Many of the features that make public cloud-computing services attractive run up against government’s traditional security models and controls, according to the National Institute of Standards and Technology’s recently-released Special Publication 800-144 (.pdf), which tallies the threats, risks and access concerns agencies should consider before entering into such contracts.
The publication stops short of recommending service arrangements, service agreements, service providers or deployment models, however. Departments and agencies should use NIST’s guide to analyze their specific requirements against public cloud services, write report authors.
Sign up for our FREE newsletter for more news like this sent to your inbox!
The publication emphasizes that in the end, the organization is responsible for security and privacy in the cloud, not the service provider. As such, SP 800-144 stresses a risk-based approach in analyzing how and what functions to move to the public cloud–organizations should extend to the cloud the same governance practices employed when deciding to outsource any other IT service.
via NIST issues security, privacy guidance for public cloud – FierceGovernmentIT.