col-xs-12
col-sm-12
col-md-12
col-lg-12
col-xs-12
col-sm-12
col-md-12
col-lg-12
videoType
dynamic-media
videoDmUrl
https://delivery-p136806-e1377785.adobeaemcloud.com/adobe/assets/urn:aaid:aem:f2b89149-a509-42b8-9727-62e9fe5ada0c/play?assetname=Cloud_Computing_Navigating_Procurement_and_Cybersecurity_Challenges.mp4
keyFrameImage
timestamp

00:03 The,

00:04 uh,

00:05 should we start at I see at.

00:08 Yes,

00:09 uh,

00:09 we can start.

00:10 Kan,

00:10 thanks.

00:11 Yeah,

00:12 so the objective of today's BBL is to demystify cloud

00:16 computing and facilitate mainstreaming of it in our client countries.

00:22 Uh,

00:22 the agenda is opening opening remarks from Ed.

00:27 They will be our main presentation.

00:30 Then deflections from our two experts followed by a question and answer session,

00:34 and then closing remarks from Tracy.

00:37 The event is open to external participation from our clients.

00:41 Uh,

00:42 now I invite Ed to please,

00:44 uh,

00:44 open the meeting

00:46 with his opening remarks.

00:48 OK,

00:49 uh,

00:49 thank you very much,

00:50 uh,

00:51 Khuram,

00:51 and,

00:52 uh,

00:52 good morning,

00:52 good afternoon,

00:53 good evening to everyone,

00:55 depending on where you are connecting from.

00:57 Uh,

00:58 I want to,

00:59 uh,

00:59 welcome all of you to,

01:01 uh,

01:01 today's BBL,

01:03 uh,

01:03 a special welcome to our guest speaker today,

01:06 Brian Conrad,

01:07 uh,

01:08 who is the acting director of Fed RAM.

01:11 And program manager for cybersecurity

01:16 GSA

01:17 in the US government.

01:19 I would also like to welcome our discussions today,

01:22 uh,

01:23 Ken,

01:24 uh,

01:25 who is lead procurement specialist,

01:27 and also

01:29 Ed Usu,

01:29 who is,

01:30 um,

01:31 the senior advisor at digital development.

01:34 Uh,

01:34 many thanks also to Khuram and the Govtech team for organizing,

01:38 uh,

01:39 this,

01:39 uh,

01:39 event,

01:40 uh,

01:40 which is focusing on a very important topic.

01:43 As many of you

01:45 know,

01:46 advanced digital economies are mainstreaming

01:49 disruptive technologies like cloud computing.

01:53 These governments are harnessing the

01:56 transformational potential of cloud computing

01:59 to reduce costs,

02:00 strengthen security,

02:02 and accelerate innovation.

02:05 COVID-19 has provided further push to

02:09 cloud computing.

02:11 Client governments can also take advantage of cloud computing.

02:17 And

02:18 they have various concerns,

02:20 but given some of their concerns about sensitivity of data and sovereign

02:25 issues,

02:26 they can adopt different options.

02:28 And for instance,

02:30 they can use public cloud for non sensitive data

02:33 while retaining the sensitive data on premises or private cloud.

02:38 But there is really no reason why our client countries cannot use

02:42 cloud computing and take advantage of the opportunities that this offers.

02:47 In FCV settings,

02:49 saving costs,

02:50 improving access,

02:51 and ensuring business continuity

02:54 uh

02:55 make

02:56 uh

02:57 even more compelling business case for cloud

03:01 adoption.

03:02 However,

03:04 as I was alluding to,

03:06 mainstreaming cloud computing in our client countries is facing challenges.

03:11 On the one hand,

03:13 most client governments cite cybersecurity and data sovereignty as key risks.

03:20 On the other hand,

03:21 our task teams and staff do not

03:24 have adequate guidance on how to navigate cybersecurity

03:28 and cloud procurement arrangements.

03:33 Our traditional procurement models,

03:35 for instance,

03:36 are focused on capital goods.

03:39 Uh,

03:40 services,

03:41 uh,

03:42 in contrast to the subscription-based cloud services model.

03:48 There is,

03:48 however,

03:50 high demand from our clients and task teams

03:53 for guidance and knowledge sharing on cloud computing.

03:58 Given its relevance to digital transformation

04:01 and the development agenda

04:04 that we are working on.

04:07 To respond to this demand.

04:09 I want to thank the Govtech team for organizing this BBL,

04:16 which is really focused on learning lessons from the US government.

04:20 The US government is a pioneer

04:23 in mainstreaming cloud computing in government.

04:27 The Gov tech team is also preparing technical guidance

04:31 on cybersecurity assessment framework for cloud computing applicable to

04:36 cloud procurement,

04:37 and that will be made available shortly.

04:40 I will encourage our task teams to support

04:44 clients in their adoption of cloud computing.

04:47 And in this regard,

04:49 the governance,

04:50 global practice and digital development

04:54 GP

04:56 recent joint work in supporting Palestinian Authority on cloud

05:02 readiness assessment is a good example

05:05 that we could adopt going forward,

05:07 so.

05:09 Uh,

05:09 to support our clients better on this agenda,

05:12 I want to emphasize three,

05:14 key

05:15 points.

05:16 One is we need to promote a whole of government approach to procurement

05:20 rather than agency-specific piecemeal approaches,

05:24 OK.

05:24 Especially when we are talking about this,

05:26 uh,

05:26 cloud computing,

05:29 uh,

05:29 promote structured

05:31 empirical cybersecurity

05:35 assessment framework.

05:37 As we learn,

05:38 I mean,

05:38 as we will learn today from uh the various uh uh speakers,

05:42 uh,

05:42 to facilitate a risk mitigation approach

05:46 rather than the current approach of risk avoidance.

05:51 We also need to collaborate,

05:53 that is

05:54 with the digital development and other GPs to support our clients

06:00 and to share knowledge and concrete examples on cloud

06:04 computing so as to promote

06:06 and facilitate the adoption and use of cloud computing.

06:11 I really look forward to a very interesting session today.

06:15 Uh,

06:15 and again I want to thank the guest speaker and uh our discussions

06:19 and also the team that organized this.

06:22 So thank you so much,

06:23 uh,

06:23 back to you,

06:23 Korra.

06:26 Thank you,

06:27 Ed.

06:27 And now I will invite our guest speaker,

06:29 Brian Conrad

06:31 to share,

06:31 uh,

06:32 his presentation,

06:34 uh,

06:34 based on US experience.

06:36 Brian,

06:36 over to you.

07:01 Hi,

07:01 this is Janelle Thels.

07:02 I support Brian at the Feder PMO.

07:04 It looks like he might have

07:06 gotten kicked off.

07:08 So if you just wait one moment,

07:09 um,

07:10 he should be.

07:10 I'm here.

07:11 We're here.

07:11 OK,

07:12 I'm here.

07:12 My apologies.

07:14 Um,

07:15 the Webex mute button was very elusive.

07:19 Uh,

07:19 however,

07:20 I was successful in finding it.

07:23 Thank you everyone for having me today.

07:26 Um,

07:27 I am very,

07:28 uh,

07:28 honored and humbled to come and present

07:31 on the US government's

07:33 Federal Risk and Authorization Management Program known as FEDRAMP.

07:38 Um,

07:38 I will have to warn you,

07:39 the US government floats on a sea of acronyms and abbreviations.

07:44 So for such a diverse audience,

07:46 if there's,

07:46 if I say something and just blow past it,

07:49 please,

07:49 uh,

07:50 raise your hand,

07:50 keep me honest,

07:51 and,

07:52 uh,

07:53 because I will,

07:54 I will consider it,

07:55 the,

07:55 I will consider that I've done my job well today,

07:58 um,

07:58 if you leave with a greater understanding of what we're doing,

08:01 OK?

08:03 So let's get started.

08:05 Next slide,

08:06 please.

08:08 This is me,

08:09 um,

08:10 next slide.

08:15 So we're gonna start out with a little Fed ramp overview and,

08:18 and that is uh gonna be with a YouTube video that we had produced.

08:23 So,

08:23 uh,

08:23 sit back and enjoy for a couple of minutes and it will give

08:26 you an overview and then I'll go into detail after the video.

08:36 The Federal Risk and Authorization Management Program,

08:39 FEDRAMP.

08:41 Promotes the adoption of secure cloud services across the US government,

08:45 providing a standardized approach to security

08:47 assessments for cloud service offerings.

08:50 FedRAM creates a partnership between the federal government and industry.

08:54 Together

08:55 we modernize IT infrastructure while protecting federal information.

09:02 Before FedRAM,

09:03 vendors had to meet different security requirements for each federal agency.

09:08 FedRAM eliminates this duplication by providing a common security framework,

09:13 making it possible for agencies and

09:15 cloud service providers to reuse authorizations.

09:18 Agencies review a standardized set of

09:20 security materials against one common baseline.

09:24 A cloud service offering is authorized once and then the

09:27 security package can be used by any federal agency.

09:31 FedRAM's guiding principle is reuse,

09:33 do once,

09:34 use many times.

09:36 This saves money,

09:37 time and effort for both agencies and cloud service providers.

09:53 All right,

09:53 next slide,

09:54 please,

09:54 to know.

09:55 Brian,

09:56 can you open your video,

09:57 please?

09:59 Oh,

09:59 I'm sorry.

10:01 My video,

10:02 video,

10:03 yes,

10:03 thank you so much.

10:05 I have that my video is on.

10:10 Can you not see me?

10:13 Can others see Brian?

10:14 No,

10:14 no,

10:15 we cannot see you.

10:16 Yeah,

10:17 we can see just the presentation.

10:19 But we can see the presentation.

10:21 Maybe you can go ahead.

10:22 Uh,

10:22 yeah,

10:22 that's fine.

10:24 The,

10:24 the.

10:24 The presentation is much more pleasant to look at than I am.

10:27 So,

10:27 um,

10:28 I'll,

10:28 I'll get into this.

10:29 Uh,

10:30 the mission of,

10:31 of the Federal Risk and Authorization Management Program

10:34 is that we promote the adoption of secure cloud

10:37 services across the federal government by the US government

10:40 by providing a standardized approach to security and risk assessment.

10:44 So,

10:45 as the video said,

10:46 you know,

10:47 the idea of behind FedRAM is that we authorize a cloud service once

10:52 and it can be reused across the federal government.

10:54 Next slide,

10:54 please.

10:57 So,

10:58 like anything,

10:58 there is a legal and policy framework uh

11:02 that is the foundation for

11:04 uh the FEDRAM program,

11:05 OK?

11:06 We have in the US the Federal Information Security Modernization Act,

11:11 uh,

11:11 which is a federal law,

11:13 and that requires our,

11:14 our,

11:14 our government agencies to protect federal information systems.

11:18 So,

11:19 uh,

11:19 through FISMA,

11:20 they require NIST,

11:22 our National Institutes of Standards and

11:24 Technology to develop standards and guidelines.

11:28 Uh,

11:28 the Office of Management and Budget,

11:30 uh,

11:31 states that when agencies implement FISMA,

11:34 they must use those standards that were developed by NIST.

11:38 And what FedRAM does is we leverage the NIS standards

11:42 and apply those to cloud services.

11:45 So,

11:46 um,

11:47 that's,

11:47 that's how we create the standardized authorization packages and,

11:51 and we use the,

11:52 the standards developed by the,

11:54 by NIST.

11:55 Um,

11:56 the standards,

11:57 uh,

11:57 that are published by NIST,

11:58 I believe,

11:59 are,

11:59 are publicly accessible,

12:01 um,

12:02 the.

12:04 OM uh Office of Management and Budget circular A 130,

12:08 that's what that A130 is referring to.

12:10 I believe that's publicly accessible as well.

12:12 So if you're interested,

12:13 you can,

12:14 you can download those and,

12:15 and read those and,

12:16 and kind of get an idea

12:17 of what the legal and policy framework for FADRAM is.

12:20 Next slide,

12:21 please.

12:24 So,

12:25 on top of the legal and policy,

12:26 we have a governance uh structure as well.

12:30 So,

12:31 as I mentioned at the top of the diagram,

12:33 the Office of Management and Management and Budget provides oversight.

12:37 Um,

12:37 we do our cross-agency coordination through

12:40 the Chief Information Officer council.

12:43 So each agency,

12:44 uh,

12:45 has a representative on that council.

12:47 And they talk through uh issues pertaining to,

12:50 uh,

12:51 cybersecurity and technology adoption,

12:53 etc.

12:54 And then we have the National Institutes of Standards and Technology,

12:58 NIST,

12:59 uh,

13:00 which,

13:00 uh,

13:01 which,

13:02 uh,

13:02 FISMA requires to,

13:03 uh,

13:05 which FISMA has,

13:07 um,

13:08 Create the standards

13:09 and,

13:09 and the technical specifications.

13:12 And then at the very bottom of the diagram,

13:14 we see our Department of Homeland Security who does the uh

13:17 cybersecurity incident response uh for across the federal government

13:22 and uh the Department of the Defense

13:23 of Defense and the General Services Administration.

13:27 So those three agencies make up the what we call the Joint Authorization Board.

13:32 Uh,

13:32 this will become important to remember,

13:34 uh,

13:35 as I get into in a couple of slides about

13:37 how cloud service providers can get authorized to,

13:40 can,

13:40 can get FEDRAA authorization.

13:42 There's two paths,

13:43 um,

13:44 and one of those is through the,

13:45 the Joint Authorization board,

13:47 and the jab,

13:47 uh,

13:48 that we refer to as the JAB

13:50 is also sort of like our,

13:52 uh,

13:53 uh,

13:53 board of directors.

13:54 They,

13:54 they sign off on policy,

13:56 uh,

13:57 which is applied across the FedRA program as well.

14:02 Next,

14:02 please.

14:06 So in talking about our stakeholders,

14:08 we have the,

14:08 uh,

14:09 starting on the left,

14:10 we have the FedRAM Program Management Office.

14:12 We provide

14:14 all the,

14:15 the unified process for agencies and cloud services to follow,

14:19 uh,

14:19 to get,

14:20 uh,

14:20 to work towards the office.

14:21 Authorization.

14:22 We work with the joint authorization board to prioritize vendors,

14:26 uh,

14:27 to achieve the authorizations.

14:28 We support the cloud service providers and agencies through the process

14:32 and we maintain a secure repository of

14:36 security artifacts.

14:37 Um,

14:38 again,

14:38 we have the,

14:39 uh,

14:39 the

14:40 federal agencies within the government who conduct quality risk assessments.

14:44 Um,

14:45 they deposit ATO documents in our secure repository.

14:49 Uh,

14:49 of course,

14:50 we have our commercial cloud server providers,

14:52 um,

14:53 which provide the documentation

14:55 and,

14:55 and,

14:56 uh,

14:56 a very important part of this process

14:58 is our third-party assessors who maintain independence,

15:02 uh,

15:02 through,

15:03 uh,

15:03 the verification and validation

15:05 that the cloud service providers are actually doing what they're,

15:08 what they say they're doing.

15:10 Um,

15:10 when I have conversations with cloud service providers and,

15:13 and our third-party assessors and,

15:15 and the agency,

15:16 so our stakeholders across the board.

15:18 Um,

15:18 I tell them that protecting,

15:20 you know,

15:21 federal information is a team sport.

15:23 Um,

15:23 we all have our specific parts of the team and we,

15:26 it best works when we do it collaboratively,

15:29 um,

15:29 where we have,

15:30 and,

15:30 and yes,

15:31 the third-party assessors have a job,

15:33 uh,

15:34 to maintain,

15:34 make sure that the cloud service providers are doing what they're doing.

15:38 The Feder PMO has,

15:39 has to make sure that policy and process are being followed,

15:42 but it's all done in concert to,

15:44 again,

15:45 with the end goal of protecting federal information.

15:48 Next slide,

15:48 please.

15:52 So,

15:52 now we're gonna talk a little bit about the impact and you got a little bit of,

15:56 of that in the,

15:57 in the brief.

15:58 So,

15:59 federal security,

16:00 US federal security policy requires all systems to be,

16:03 to be authorized based on risk,

16:05 OK?

16:06 And what FedRAM does is it standardized that process for commercial cloud.

16:11 OK,

16:11 we have a model where we,

16:13 we authorize once so it can be used many times.

16:17 You know,

16:17 doing the security authorization right the first time allows agencies

16:22 to reuse the work and eliminate duplicative efforts.

16:26 So if you Have multiple agencies,

16:28 they don't have to do the same work twice,

16:31 uh,

16:32 as,

16:32 as Ed mentioned,

16:33 as Edward mentioned in the opening,

16:35 using that whole of government approach

16:37 to leverage the work that one agency has done across the,

16:40 across the enterprise,

16:41 so to speak.

16:43 Um,

16:43 with transparency,

16:44 we have increased collaboration.

16:47 We create a community amongst the government and the commercial vendors,

16:50 um,

16:51 that did not exist

16:53 before.

16:53 Um,

16:54 we,

16:55 FedRAM validates the,

16:57 the security authorizations to ensure that.

16:59 That there's uniformity and conformity

17:02 amongst the security packages

17:04 and I mentioned a central,

17:05 centralized repository where agencies can request

17:09 access to those existing security packages

17:11 so that,

17:12 that can expedite their,

17:14 their authorizations.

17:16 Next slide,

17:16 please.

17:20 So looking at the,

17:22 looking at continuing into some of the more detail of the,

17:26 of the FedRAM landscapes,

17:28 presently,

17:29 we have 4 different security baselines

17:32 matched to,

17:32 to risk,

17:33 OK?

17:34 Uh,

17:35 mass,

17:35 uh,

17:35 matched to sensitivity of information.

17:38 When you go and categorize the types of information you want to put in a cloud,

17:42 um,

17:43 we have,

17:44 we have,

17:44 uh,

17:45 documentation for that.

17:46 We have,

17:47 uh,

17:48 federal policy and guidance on how we do that.

17:50 Um,

17:51 it's called the Federal Information Processing Standards,

17:54 and it,

17:55 it basically serves as a guideline for agencies to categorize,

17:59 uh,

18:00 the impact level of their information.

18:02 Is it

18:03 very sensitive?

18:04 Is it high?

18:04 Is it moderate?

18:05 Um,

18:06 is it low,

18:07 publicly accessible,

18:08 publicly releasable information,

18:09 that kind of thing.

18:10 Um,

18:11 I'll have you note that this is not necessarily

18:13 used for intelligence activities or the Department of Defense

18:17 because the FedRAM baseline does not send,

18:19 does not do anything,

18:21 uh,

18:21 with classified information.

18:22 This is

18:23 for,

18:24 uh,

18:25 uh,

18:25 agencies to conduct their business.

18:27 So yes,

18:28 there may be personally,

18:29 personally identifiable information.

18:31 There might be,

18:32 uh,

18:33 personal health information included in some of these

18:36 in the information categorized,

18:38 but

18:39 So agencies would have to pick the cloud service

18:41 that meets their requirements out of those four baselines.

18:45 Presently,

18:45 we have over 211 authorized cloud services in our catalog.

18:50 Uh,

18:50 the 1st 6 years of the program,

18:52 it,

18:53 uh,

18:53 we got to 100,

18:54 but in the last 2 years,

18:56 we've doubled that number.

18:57 Um,

18:58 we have over 2100 agency reuses of authorized systems.

19:02 So I,

19:03 I wanna point this out.

19:04 So

19:05 we talked before about the value of FedRAM being.

19:08 That it can be uh the,

19:09 the cloud service provider is authorized through the cloud service offering

19:13 is authorized once and it can be reused across the government.

19:17 That 21,

19:18 that over 2100,

19:19 uh,

19:20 instances of reuse is,

19:22 is indicative of that because

19:24 that shows,

19:25 uh,

19:26 in resource savings

19:28 what the FedRAM program has been able to bring to the US federal government.

19:32 We have.

19:33 72 participating federal agencies

19:36 and we have over 220 industry partners who are participating.

19:39 And again,

19:40 those industry partners are not just the cloud service providers,

19:43 but they're also the uh third-party assessment organizations as well.

19:49 Program management office is very,

19:51 very,

19:51 uh,

19:51 active.

19:52 We,

19:53 we participate in over 750 annual meetings with agencies

19:57 and vendors and speaking engagements like this one.

20:00 we have over 4400,

20:02 uh,

20:02 followers on Twitter.

20:04 Um,

20:04 we have a listser,

20:05 uh,

20:05 uh,

20:06 basically an email,

20:07 an email list of over 13,000,

20:09 uh,

20:10 stakeholders,

20:11 and we have,

20:12 uh,

20:12 through our,

20:13 our

20:14 email.

20:15 Info at Fed ramp.gov.

20:18 Uh,

20:19 our team,

20:19 uh,

20:20 fields over 33,000 questions a year.

20:23 Um,

20:25 simple things to the most complex,

20:27 and,

20:27 uh,

20:28 and,

20:28 but our team of professionals is,

20:30 is there to handle that.

20:32 Next slide,

20:32 please.

20:37 So,

20:38 when we talk about authorizing,

20:39 we

20:40 authorize the whole cloud stack,

20:42 OK?

20:42 So agencies

20:44 ultimately end up doing an authorization for,

20:47 uh,

20:48 from

20:49 the infrastructure plat platform and software,

20:52 and each of these components plays an important security role.

20:55 So agencies must acknowledge and accept the risk

20:58 associated with their federal information with these environments.

21:02 Um.

21:03 So where this is important is

21:06 if you're an agency and you're going to put your

21:10 into a platform,

21:12 you can leverage.

21:15 Package from that particular platform if it has a FedRAM authorization

21:20 for your,

21:21 for the agency's authority to operate.

21:23 OK,

21:24 as well,

21:25 if,

21:26 if there's a uh SAS provider,

21:28 software is a service provider

21:30 who is going into a FedRAM uh authorized environment,

21:33 they get the leverage.

21:34 The controls from that authorized environment for their security package as well.

21:40 So it's a building,

21:41 sort of a building block approach

21:43 where

21:43 FedRAM-authorized cloud services at the platform

21:46 and infrastructure level can be leveraged

21:49 up the stack.

21:57 As I mentioned a couple of slides ago,

21:58 we have 4 specific baselines

22:01 according to the security impact.

22:04 Agencies.

22:05 So looking from,

22:06 from tailored up to high,

22:10 um,

22:10 those are specific,

22:11 the tailored,

22:12 uh,

22:12 low impact software as a service is specific to

22:16 those software as a service which have a,

22:18 a low-risk limited use case.

22:20 Uh,

22:21 for instance,

22:21 uh,

22:22 uh,

22:22 if your agency wants to run a survey for 30 days,

22:26 um,

22:26 the low impact,

22:28 uh,

22:29 software as a service authorization may.

22:32 Tailored authorization may be suitable for that.

22:34 Uh,

22:35 for low,

22:36 it's,

22:36 uh,

22:38 uh,

22:38 uh,

22:38 125 controls,

22:41 uh,

22:41 versus again,

22:42 do not store personally identifiable information.

22:45 Um,

22:46 moving up

22:47 to moderate,

22:47 there's 325 controls,

22:50 and this is where we find the majority of

22:52 the cloud systems that we have in our catalog.

22:54 80% of those,

22:55 uh,

22:56 of those are at the moderate level,

22:58 and then,

22:59 uh,

22:59 the high impact systems,

23:01 um.

23:02 Obviously,

23:03 are,

23:03 are more sensitive information if you think about law enforcement,

23:06 uh,

23:07 data,

23:08 uh,

23:08 immigration data,

23:10 other personally identifiable information or,

23:12 or

23:13 PHI,

23:14 uh,

23:14 personal health information that you might find that in,

23:17 in a high-impact

23:19 system.

23:19 So what it means by controls on the very first bullet point,

23:23 those are the,

23:24 that's the number of uh controls from the NIST

23:27 uh standard,

23:28 the 8,

23:30 special publication 853,

23:33 uh,

23:33 currently revision 4,

23:36 that those baselines are built off of.

23:45 And a little more about

23:47 lines,

23:47 uh.

23:49 So,

23:50 there's different,

23:51 there's 7,

23:51 there's 17 uh different control family

23:55 uh within the NIST baselines and,

23:57 and so,

23:59 for example,

24:00 there are,

24:01 uh,

24:02 there's a family around encryption,

24:04 uh,

24:04 which helps ensure that only authorized parties,

24:07 uh,

24:08 uh,

24:08 can decode the information.

24:10 There's identification and and authentication.

24:14 Um,

24:14 we have controls built into the baselines

24:16 about vulnerability scanning and malicious code,

24:19 uh,

24:20 boundary protection systems and interconnections,

24:23 as well as configuration management.

24:28 Next

24:32 So we

24:34 About the base

24:35 of FedRAM,

24:36 uh,

24:36 the legal and the policy framework

24:39 associated in the,

24:40 in the,

24:41 uh,

24:41 you know,

24:42 what we use for the controls to,

24:44 uh,

24:44 adjudicate cloud service providers.

24:46 I'm gonna go into a little bit of the mechanics on how we do it,

24:49 OK?

24:50 So,

24:51 in FedRAM,

24:51 we have 3 different designations that appear on our marketplace,

24:55 and,

24:55 uh,

24:55 those digital,

24:56 I,

24:56 I believe a link to that marketplace

24:58 is included in the,

25:00 in the later part of this presentation which you can go and look at.

25:03 So we have a FedRAM ready,

25:05 FedRAM in process and FedRAM authorized.

25:08 And this,

25:08 these designations are,

25:10 are,

25:11 were designed to

25:13 allow

25:14 uh potential agency customers to see

25:17 the,

25:17 the current state of a cloud service provider in the process,

25:21 OK?

25:22 With FedRAM ready,

25:24 um,

25:24 this is sort of a pre-check that we do

25:26 to make sure that the cloud service offering can make it through authorization.

25:30 We look at things like,

25:32 um,

25:32 what external services are being.

25:35 Uh,

25:36 the,

25:36 uh,

25:37 implementation of encryption,

25:39 uh,

25:39 those sorts of things,

25:40 just kind of as a,

25:41 as a pre-check before we do the authorization,

25:43 the actual,

25:44 uh,

25:45 initial assessment.

25:46 Um,

25:47 usually,

25:48 um,

25:48 once there is a kickoff meeting either with

25:51 an agency sponsor or the joint authorization board,

25:54 um,

25:55 that's when a cloud service provider will be listed as in process.

25:58 That means they are actively going through the initial assessment.

26:01 And their security package and their,

26:03 all their artifacts are being examined by

26:06 information systems security officers

26:08 um from,

26:09 from

26:10 the agency or the joint authorization board

26:13 and that's really the deep dive into the security package to make sure

26:17 that uh the cloud service offering is.

26:19 Meeting all the requirements that we have with FedRAM

26:22 and when all that's said and done,

26:24 um,

26:25 if everything is,

26:26 is

26:27 judged to be satisfactory and,

26:29 and,

26:29 uh,

26:30 and it meets our standard,

26:32 that's when the,

26:33 the cloud service offering will have a FedRAM authorized,

26:36 uh,

26:37 entry in the,

26:38 in the marketplace

26:39 and that shows that,

26:40 uh.

26:42 It allows sort of like a one-stop shop for agencies to come

26:45 and look at all those cloud service providers that are authorized

26:49 to see if,

26:49 if there's one in the marketplace that fits,

26:52 fits their needs.

26:53 Sorry about that,

26:54 Jana.

26:54 I didn't mean to trip you up there.

26:57 Next slide,

26:58 please.

26:59 So

27:01 You've heard me mention the Joint

27:02 Authorization Board and the agency authorization.

27:05 So in FEDRAAM,

27:06 we have two discrete paths to authorization.

27:09 So,

27:09 with the Joint Authorization Board,

27:11 this,

27:12 the JAB is the primary governance and decision-making body for the FEDRAM program.

27:16 It consists of the,

27:17 uh,

27:18 Chief Information Officers from the Department of Defense,

27:21 Department of Homeland Security,

27:22 and General Services Administration.

27:24 And they strictly review the cloud service

27:26 providers packages for applic for acceptable risk posture

27:30 using our standardized baselines.

27:32 Uh,

27:33 what's unique about this is the Joint Authorization board issues a provisional

27:38 authorization to operate.

27:40 Because

27:41 the collection of those three CIOs cannot accept risk on behalf of the government,

27:46 um,

27:46 or be on behalf of any other agency.

27:49 So each agency

27:50 who wants to leverage that package,

27:53 to leverage,

27:54 use that cloud service that has a job authorization.

27:57 We have the,

27:58 we have the package,

27:59 will have a uh

28:00 a a understanding of the cybersecurity posture

28:04 and,

28:04 and

28:05 of,

28:05 of that particular

28:07 cloud service and then they have to by US federal law,

28:11 they have to uh sign off what we call an authority to operate.

28:15 Again,

28:16 the idea is

28:17 the amount of work that they have to do is

28:19 greatly reduced because the cloud service already has that FedRAM

28:24 authorization or Jab provisional authorization.

28:27 As well,

28:28 the,

28:28 uh,

28:29 a,

28:29 any federal agency within the US government

28:32 can sponsor a FedRAM authorization as well.

28:34 So,

28:35 the onus is on the agency to conduct the review along with a third-party assessor,

28:41 um,

28:42 to make sure that the package conforms to FEDRAAM standards.

28:45 And so once that is complete,

28:47 the package comes over to FedRAM,

28:49 to the PMO.

28:50 We sign off on the completeness,

28:52 we do a check on critical controls and such

28:55 to make sure they're implemented

28:57 and they get a,

28:58 they'll be posted on the,

28:59 uh,

29:00 on the marketplace as FedRAM authorized

29:02 and the agency will sign off an,

29:04 an authority to operate or an ATO

29:06 uh for that.

29:09 OK.

29:13 So I mentioned before the FedRAM Marketplace,

29:16 and this provides a

29:17 database of all cloud services with any of those three

29:21 FedRAM designations whether they're uh ready in process or authorized.

29:25 Um,

29:26 it allows uh

29:28 it.

29:29 To look for third-party assessment organizations,

29:32 we have a,

29:33 uh,

29:33 just like we have a,

29:34 uh,

29:34 a standard

29:36 policy to authorize cloud services,

29:39 we have,

29:39 uh,

29:40 a program to manage the,

29:41 the third-party assessors who do the verification and validation

29:45 of the cloud service providers.

29:47 There's certain standards they need to meet,

29:49 uh,

29:49 in order to be accepted as FedRAMP 3 PAOs,

29:52 um,

29:53 third-party assessors,

29:54 and,

29:55 um.

29:56 We maintain uh

29:58 uh visibility on their performance as well.

30:01 So if,

30:01 if,

30:02 uh,

30:02 cloud service providers have a,

30:04 uh,

30:05 are,

30:05 are having an issue addressing vulnerabilities or anything,

30:08 you know,

30:08 we have an escalation.

30:10 Make sure that they continue to meet the,

30:13 meet our standards.

30:14 The same goes for the third-party assessors as well because we realize

30:18 the importance of that third party,

30:20 uh,

30:20 assessor to

30:21 validate the,

30:23 the cybersecurity posture and,

30:24 and

30:25 validate the fact that the cloud service providers are doing

30:27 what they tell us that they're supposed to be doing.

30:30 Next slide,

30:30 please.

30:33 I,

30:34 that's all my prepared material and I am,

30:36 I'm more than,

30:37 more than happy and prepared to take on questions from this esteemed audience.

30:44 Uh,

30:44 thank you very much,

30:45 Brian.

30:45 Thank you.

30:46 This is excellent.

30:47 And now I turn to our discussions.

30:50 Uh,

30:50 first I will ask,

30:51 uh,

30:52 Ed Sue,

30:53 uh,

30:53 senior adviser digital development,

30:56 uh,

30:56 to share with us his reflections

30:59 on how we can mainstream cloud computing

31:02 in our operations and in the client governments,

31:05 uh,

31:06 learning some of the lessons from the US experience.

31:08 Ed,

31:09 over to you.

31:11 Great,

31:11 thanks so much and uh thanks for inviting us and,

31:14 and I just wanna echo the comments before that the

31:17 governance GP and digital development are working very closely together on,

31:20 on uh several initiatives in this area

31:22 and we hope to continue that

31:24 partnership,

31:24 uh,

31:25 particularly in cloud computing and,

31:26 uh,

31:26 and in cybersecurity.

31:28 Um,

31:28 just wanna make a quick,

31:29 some comments first on cybersecurity broadly and then coming down,

31:33 back down to cloud.

31:35 Um,

31:35 we have been looking at cybersecurity.

31:38 Mostly from an

31:39 ecosystem perspective,

31:41 from a national perspective,

31:42 and have been

31:43 working with countries to do assess

31:45 where did,

31:46 where does a country stand,

31:47 uh,

31:47 in terms of their cybersecurity maturity,

31:50 um,

31:50 and now we're actually working on tools to bring that down

31:53 to a sectoral and project level and start to assess cybersecurity,

31:56 um,

31:57 from a sectoral level,

31:58 but again,

31:58 it's,

31:58 it's also looking at a network.

32:00 And looking at uh where is the data coming from,

32:03 who is using it,

32:04 who is producing it,

32:05 and where are all the cybersecurity vulnerabilities

32:07 as the data is being produced or consumed

32:09 along many different nodes or uh along the network.

32:13 Um,

32:13 so that being said,

32:14 I think that this is obviously a very important aspect of

32:19 improving cybersecurity in general,

32:21 you know,

32:21 I think that

32:22 it's,

32:23 it's almost a,

32:24 a,

32:25 a no-brainer that,

32:26 you know,

32:27 as,

32:27 as our clients can leverage

32:29 cloud and,

32:30 and

32:31 the commercial data,

32:32 data providers,

32:33 data storage providers much better,

32:35 this is going to improve cybersecurity

32:37 of the data that they store given the options that they have.

32:41 So I think this is uh

32:42 something that,

32:43 you know,

32:43 we'd be very,

32:44 you know,

32:45 we,

32:45 we need to do,

32:46 uh,

32:46 much more of,

32:47 we'd be interested to hear a bit more around,

32:49 you know,

32:49 how do you think about,

32:50 you know,

32:51 from,

32:51 from Brian,

32:51 how do you think about cybersecurity outside of,

32:54 outside of just,

32:55 you know,

32:55 just putting data on the cloud,

32:57 but of,

32:57 of as data's moving in and out,

32:59 and,

32:59 you know,

33:00 how can we also look at it from an ecosystem perspective.

33:03 Coming down to the cloud,

33:04 uh,

33:04 you know,

33:05 DD,

33:05 we're also working on a global data and cloud infrastructure study

33:08 that looks at broadly first enabling environment around how,

33:12 you know,

33:12 how does private sector

33:14 look at data infrastructure within our client countries,

33:16 how can we catalyze more investment,

33:17 and then looking very specifically at this issue like you were saying,

33:20 Karam,

33:20 how can we mobilize and mainstream more

33:23 use of.

33:24 Cloud among our,

33:25 uh,

33:25 among our projects,

33:27 a couple of things we're gonna do within this,

33:29 uh,

33:29 you know,

33:30 this study is look at,

33:31 you know,

33:31 what are we doing within World Bank projects today,

33:34 and I think that

33:35 trying to benchmark what what is happening and

33:37 the little that we've done so far we've seen there's many,

33:40 many obstacles,

33:41 uh,

33:42 that,

33:42 that our clients are facing.

33:44 Um,

33:45 and cybersecurity is just,

33:47 is one of them is not being able to accurately assess,

33:49 so I think this tool is very helpful.

33:51 We,

33:51 we definitely need to extend this tool to other areas

33:54 of other barriers of why our clients are not using cloud.

33:57 Um,

33:58 so one thing we want to do is look at sort of uh,

34:00 uh,

34:00 take a holistic cost benefit analysis of cloud,

34:03 looking at the financial benefits,

34:04 um,

34:05 uh,

34:06 comparing one-time cost versus recurring costs and maintenance costs,

34:09 looking at the economic benefits of which cybersecurity is one of them.

34:12 But there's also a lot of benefits around data modernization,

34:16 forms of IT operations,

34:17 looking at other indirect impacts when the government adopts cloud.

34:20 How does that catalyze other adoption of cloud,

34:23 and also the social aspects of how does cloud enable

34:26 improved government services.

34:28 So it would be great to kind of

34:29 Understand this model and,

34:30 and I,

34:31 you know,

34:31 like,

34:32 like I think was mentioned earlier,

34:33 a whole government approach,

34:35 we need to do this for cybersecurity,

34:36 but the government needs to also

34:38 kind of give guidance on all these other financial,

34:41 economic,

34:42 social benefits

34:43 and help agencies also,

34:44 uh,

34:44 also across that.

34:46 Um,

34:46 and

34:47 perhaps a reflection back that,

34:49 you know,

34:49 from our standpoint,

34:50 we see this as incredibly important,

34:52 as incredibly

34:53 uh useful way,

34:55 um.

34:56 Uh,

34:56 to,

34:57 um,

34:58 to,

34:58 to manage some of the cybersecurity risks,

35:00 um,

35:00 but you know,

35:01 one thing that you,

35:01 you had in your presentation was,

35:03 you know,

35:03 when you,

35:04 when you looked at

35:05 the,

35:06 uh,

35:06 the number of cloud providers you managed to authorize 211

35:10 within the US,

35:11 that,

35:11 that's quite a large number of,

35:13 of,

35:13 of providers who are able to meet your standards.

35:16 And you know,

35:17 within our client countries,

35:18 if we went through,

35:19 if our clients went through this exercise,

35:21 how many would they actually be able to

35:22 identify that meet these standards other than the top

35:26 5 or 6 global providers that we're all aware of?

35:28 Is that,

35:29 you know,

35:29 will this simply push our clients towards really

35:32 using the,

35:33 the,

35:33 the,

35:33 the hyper scales.

35:35 And,

35:35 and,

35:36 you know,

35:36 um,

35:36 so I kinda wanna,

35:37 we'd love to have some reflection on,

35:39 on,

35:39 on that from you as well,

35:40 Brian.

35:40 But again,

35:41 thank you so much.

35:41 I think this is a model for our clients,

35:44 not just for cybersecurity,

35:45 but we wanna use this model and look at all the other aspects of cloud adoption

35:49 that,

35:49 that we can standardize and,

35:50 and,

35:50 and help,

35:51 uh,

35:51 and help mainstream this across our operations.

35:53 So,

35:53 thank you so much.

35:55 Thank you.

35:55 Uh,

35:56 you know,

35:56 one of,

35:56 one of the things that I noticed that was,

35:58 uh,

35:58 that I didn't cover in,

35:59 in my presentation was,

36:01 you know,

36:02 we talked all about the initial assessment,

36:04 but,

36:05 uh,

36:05 in,

36:05 in our FedRAM requirements,

36:07 we have a very,

36:08 very strict,

36:09 uh,

36:09 continuous monitoring program

36:11 and

36:13 Requirements we have,

36:15 we,

36:15 we,

36:16 we make sure that the cloud service providers on a monthly

36:19 basis are maintaining that cloud ser that the cybersecurity posture,

36:22 that cloud service,

36:23 OK?

36:24 So we,

36:24 we,

36:25 uh,

36:25 we get uh

36:26 monthly scans from the cloud service providers and,

36:28 and,

36:29 and.

36:29 As you can imagine,

36:30 the amount of data coming from some of the hyperscale providers

36:33 is,

36:33 uh,

36:34 is,

36:34 is pretty large,

36:36 uh,

36:36 to say the least,

36:37 but,

36:37 um,

36:38 we work very closely with the cloud server providers

36:40 to make sure that they address all the,

36:42 all the vulnerabilities that are identified in their scans

36:46 and so it's an ongoing process.

36:47 The,

36:48 the initial authorization is just the first piece.

36:50 It's,

36:51 it's the continuous monitoring that happens up until,

36:54 you know,

36:54 the cloud service goes away.

36:56 Uh,

36:56 that's,

36:57 that's important as well.

36:58 And on top of the continuous monitoring,

36:59 we also do annual assessments.

37:01 So we look at a,

37:02 uh,

37:02 a subset of the,

37:03 uh,

37:04 of what,

37:04 what are considered critical controls,

37:07 um,

37:07 every,

37:08 you know,

37:09 roughly,

37:09 uh,

37:09 33% of the,

37:11 of the controls every year.

37:12 So,

37:13 uh,

37:13 ostensibly every 3 years,

37:15 they're getting a full look,

37:17 uh,

37:17 uh,

37:17 a full reassessment again,

37:19 just based on,

37:20 on the annual assessment and the continuous monitoring process.

37:22 So,

37:23 Again,

37:23 that was a little piece that I,

37:24 that I didn't mention in,

37:26 in my brief,

37:26 but I think it's very important to understand

37:29 that we just don't authorize a cloud and forget it and you know,

37:31 we don't authorize a cloud and then send it out into the wild

37:34 to be used by the federal government.

37:36 We,

37:36 we,

37:36 we have a very robust

37:38 uh

37:39 method to,

37:40 to maintain,

37:41 to ensure that the cloud service

37:42 providers are maintaining their cybersecurity posture.

37:47 Thank you Ed and thank you Brian for this clarification.

37:50 This is very helpful.

37:52 Now I return to uh Canutt Lipo.

37:56 Canutt is our lead,

37:57 uh,

37:57 procurement specialist and,

37:59 uh,

37:59 with extensive,

38:00 uh,

38:01 multi-regional experience of IT ICT procurement.

38:05 So Kut,

38:05 uh,

38:06 uh,

38:07 since,

38:07 uh,

38:08 in addition to the cybersecurity,

38:09 there's a procurement angle to the cloud service,

38:12 uh,

38:12 provision

38:13 as we learned from Brian,

38:16 how,

38:16 uh,

38:17 our,

38:17 uh,

38:17 new procurement framework,

38:19 uh,

38:19 could accommodate,

38:20 uh,

38:21 similar procurement approaches for our,

38:22 for our cloud-based services.

38:27 Yeah,

38:27 thank you.

38:28 Thank you very much,

38:29 from,

38:29 um,

38:30 and thank you very much to Ed for having me in this meeting.

38:33 And here we go again with procurement.

38:35 So

38:36 we have seen a lot of issues with ICT procurement,

38:39 not only in bank projects,

38:40 but,

38:40 uh,

38:41 even beyond.

38:42 Uh,

38:42 thanks also to Brian for a very interesting presentation,

38:46 uh,

38:46 and to Ed for his comments and contributions.

38:49 As I understand it,

38:50 FedRAM is a sort of a Framework agreement

38:53 or a standing list,

38:55 which is open to,

38:56 uh,

38:56 US companies,

38:57 to US cloud service providers,

39:00 uh,

39:00 which are validated against certain,

39:02 uh,

39:03 standards and become part of a catalog that then,

39:06 uh,

39:07 agencies,

39:07 public agencies can be,

39:09 uh,

39:09 benefit from.

39:11 Um,

39:12 what I would like to try is really to link the procurement angle

39:16 of cloud computing maybe to three major procurement principles.

39:19 One is integrity.

39:21 The other one is value for money,

39:23 and the third one is sustainability.

39:25 Uh,

39:25 quickly,

39:26 let me start with integrity.

39:28 Um,

39:28 Public procurement is about following legislation,

39:30 compliance with legislation,

39:33 and we all know that,

39:34 uh,

39:34 change in legislation is a very slow undertaking.

39:39 On the other hand,

39:40 uh,

39:40 ICT is developing at very high speed with short innovation cycles,

39:45 and a change in legislation cannot keep up with that speed,

39:48 not at all.

39:49 So I think therefore it's very important

39:51 that the procurement legislation is technology

39:55 neutral

39:56 and also provides the flexibility

39:59 to accommodate

40:00 the public acquisition of new technologies such as cloud computing.

40:04 And this is very important.

40:05 The good news is that we see this

40:07 in most of the countries in the world,

40:09 across the world,

40:10 and we also see it

40:12 in our own procurement regulations,

40:15 uh,

40:15 which is technology neutral

40:17 and also provides a lot of flexibility

40:19 to accommodate.

40:20 The purchase of innovative

40:22 technologies.

40:23 So that's not really an issue,

40:25 um,

40:26 as I would say.

40:27 And,

40:27 uh,

40:28 we have seen examples,

40:29 for example,

40:30 um,

40:31 non-consulting services.

40:32 I would categorize a cloud computing as a non-consulting service.

40:38 And in the past,

40:39 we have seen,

40:40 for example,

40:40 as part of uh capital investments,

40:42 ICT capital investments,

40:44 we have seen recurrent costs during the warranty

40:47 and post-warranty period up to 6 years or even longer.

40:51 And this was also based on a sort of service level agreement

40:54 uh for a defined number of years.

40:57 So,

40:57 uh,

40:58 the World Bank framework

40:59 is Available to accommodate procurement of cloud

41:04 computing.

41:04 And it also provides adequate,

41:06 uh,

41:07 procurement approaches,

41:09 everything from,

41:09 let's say,

41:10 framework agreement to competitive dialogue for complex projects

41:14 or contracts.

41:15 Now,

41:15 the framework agreement is very interesting.

41:19 Um,

41:20 cloud computing as a new technology.

41:22 I think that what we have seen from FedRAM,

41:24 um,

41:25 a framework agreement would,

41:27 would be maybe a good fit for purpose

41:29 in this instance to do a procurement,

41:31 uh,

41:32 for cloud computing

41:33 at a national level.

41:35 But I will talk a little bit about

41:36 the implication when we talk about open international procurement

41:40 which,

41:41 uh,

41:41 the bank,

41:41 uh,

41:42 is in favor of.

41:43 Um,

41:44 what is perhaps missing from the World Bank right now,

41:47 and this is acknowledged as part of

41:50 the procurement framework is specific guidance,

41:52 templates,

41:53 and also examples

41:55 where

41:56 cloud computing solutions have been procured

41:59 successfully.

42:00 Now,

42:00 public procurement is also about value for money,

42:02 and I I think without any doubt,

42:04 one of the

42:05 best benefit of cloud computing is cost savings.

42:09 Um,

42:10 it's just a matter of calculation to find out the break-even

42:13 if you go for cloud computing versus,

42:15 uh,

42:15 capital

42:16 ICT investments

42:18 into data centers.

42:19 Um,

42:20 there are other benefits of cloud computing.

42:23 If we talk about value for money,

42:25 and this is scalability,

42:26 flexibility,

42:27 service quality,

42:28 and so on and so forth.

42:29 And what I learned recently,

42:31 and this is a very interesting point,

42:33 security.

42:35 So there is an opinion out there and,

42:37 and maybe we can hear a little bit more on that from

42:40 Brian and also from Ed,

42:41 um,

42:42 that argues that uh cloud computing offers better security,

42:46 data security

42:48 than as if you're hosted on-premise in your own data center.

42:52 Because

42:52 this is exactly the point.

42:54 Security concerns,

42:55 in addition to data sovereignty and privacy issues,

42:59 are

43:00 considered among the highest risks

43:01 by governments when they

43:04 embark on moving data into the cloud.

43:07 Data are very sensitive,

43:08 as we could hear,

43:10 and so there is a certain resistance of.

43:12 Countries

43:13 to open up even to international cloud providers

43:18 and we have seen examples like in Estonia who

43:20 keep the cloud computing all on their own territory

43:24 and I know also about the existence of a discussion in the world right now

43:30 of a large contract,

43:31 multi-million contract for cloud computing.

43:33 Uh,

43:34 where the borrower would like to keep the data

43:38 on national territory,

43:40 mainly for security reasons and data sovereignty and privacy issues.

43:44 So we,

43:44 we are faced with that

43:46 and um

43:48 If,

43:48 if,

43:48 if that means that they don't want to hire

43:50 international cloud providers and there are big cloud providers,

43:54 in particular when there are no cloud providers in a,

43:57 in a smaller country,

43:58 um,

43:59 on the one hand,

44:00 you can understand

44:01 if it comes to data security,

44:03 sovereignty,

44:03 and privacy issues.

44:05 On the other hand,

44:06 you

44:07 consider this as a limited competition.

44:09 So you limit the competition

44:10 to national.

44:12 Territory keeping the data in national territory,

44:16 not benefiting from the best value

44:18 that maybe an international cloud service provider

44:20 could offer to you.

44:22 And there are maybe additional reasons besides security and data

44:26 privacy and sovereignty

44:28 which may contribute to the motivation to keep data hosting in the country

44:32 which is related to the promotion of the local industry.

44:36 And this links to the sustainability,

44:38 where the sustainability aspect comes in,

44:40 uh,

44:41 as part of the value for money concept as a,

44:43 as a measure.

44:46 principle of public procurement today.

44:48 So I think

44:50 as you can see there are several aspects which can play a role,

44:53 and

44:54 I think that

44:55 any requirements

44:57 that may point towards a limited competition,

45:00 for example,

45:02 you have to meet national security certifications,

45:05 you have to keep data

45:07 on national territory,

45:09 or you would like to promote local providers.

45:12 I don't think we,

45:13 we have a black and white approach here.

45:15 I think we have to assess this on a case by case basis

45:18 as part of the procurement strategy in our projects,

45:21 and we have to take into consideration several aspects like

45:24 doing a market analysis of available local cloud service providers,

45:29 um,

45:30 doing,

45:30 uh,

45:31 an analysis of existing.

45:33 strategies in the government.

45:34 We could hear,

45:35 uh,

45:36 from Ed at the beginning and the introduction,

45:39 a whole of government approach to cloud computing.

45:42 We have accepted previously in large ICT contracts,

45:45 the fact that,

45:46 for example,

45:47 certain brands have to be purchased as part of the contract for a database

45:51 when there was an existing.

45:53 In the national strategy which promoted exactly,

45:57 uh,

45:57 uh,

45:58 this,

45:58 uh,

45:58 brand.

45:59 So if there is in a country an existing

46:02 cloud computing strategy,

46:04 um,

46:04 certification program and things similar to FedRAM in the US,

46:08 this also should be taken into consideration when we make

46:11 a decision whether we can fund this or not.

46:13 Um,

46:14 existing standards,

46:15 security standards,

46:17 and also the sustainability of policies play a role.

46:20 In summary,

46:22 I think the procurement of cloud solutions can be accommodated

46:26 in bank-funded projects.

46:28 That's not an issue really.

46:30 We haven't seen too many examples,

46:31 but glad to be part of this discussion and to see how this develops

46:35 and to contribute to moving this agenda forward.

46:39 Um,

46:40 what I can say is that typically,

46:42 uh,

46:43 the procurement family in the bank would put the preference on open competition.

46:48 Uh,

46:48 open international competition approaches,

46:51 um,

46:52 and that should be based on relevant international standards,

46:54 and the question would be,

46:55 are there any

46:57 international standards in the context of cloud computing

47:00 that could be

47:01 part of,

47:02 uh,

47:02 the bidding document if you go out to the market

47:05 as a requirement.

47:06 Um,

47:07 if it comes to limitation of the competition,

47:10 keeping,

47:10 uh,

47:11 the list of data providers of,

47:13 of,

47:13 um,

47:14 of cloud,

47:15 uh,

47:15 uh,

47:15 solution providers within the country,

47:18 or at least allowing international companies,

47:21 but then making it a requirement

47:23 to keep the data

47:25 within

47:25 national territory,

47:27 uh,

47:27 this,

47:28 this has to be carefully assessed.

47:29 As I said before,

47:30 against this criteria,

47:32 um,

47:33 before making a decision in favor

47:34 or against it.

47:36 Um,

47:36 I know that further guidance will be developed with

47:39 our procurement colleagues in OPCS and in the global

47:42 procurement unit,

47:43 and,

47:44 uh,

47:44 I also know that there are more learning sessions,

47:47 uh,

47:47 almost every week on the subject matter.

47:50 This is a very good dialogue

47:51 and,

47:52 um,

47:53 And I think this is a great agenda.

47:55 So

47:56 from the procurement point of view,

47:57 I'm happy to answer any more questions that might come up

48:00 and perhaps from Brian to hear

48:04 whether this has been an issue

48:06 or whether

48:08 there is certain comfort,

48:09 you know,

48:10 to

48:11 keep

48:11 the.

48:12 A certified list of cloud providers within the US

48:16 or maybe there are international providers as well,

48:18 but given the fact that most of the cloud providers,

48:20 the large ones,

48:21 they are from the US anyway,

48:23 that might not be really a problem.

48:24 So thank you very much for the opportunity,

48:27 and we'll stay tuned and be available for questions.

48:29 Thanks.

48:31 So,

48:31 I'd,

48:31 I'd like to interject about the data sovereignty in the geolocation of,

48:35 of,

48:35 of data.

48:36 I can understand where that's an issue and,

48:37 and obviously that's the top of mind for

48:40 the US government as well.

48:41 And

48:42 through those uh NIS standards,

48:44 um,

48:44 we have,

48:46 um,

48:47 we,

48:47 there are parameters that,

48:49 that our joint authorization board has prescribed to keep,

48:52 uh,

48:53 certain types of data within the US,

48:55 US territories or geo geolocations that have US jurisdictions.

48:59 So it's possible to do with the creation of

49:02 uh parameters uh on how those security controls,

49:06 those new security controls are implemented,

49:08 um,

49:08 to,

49:09 to maintain that.

49:10 Um,

49:11 there are also other ways to do it,

49:13 um,

49:14 uh,

49:14 you know,

49:14 the,

49:15 the,

49:15 the contract is a very powerful tool,

49:17 um,

49:18 with a cloud service provider and to say,

49:21 OK,

49:21 show me how you're meeting the standard,

49:23 show me that you're keeping,

49:24 how you're keeping.

49:26 My data in within my borders,

49:28 um,

49:29 you know,

49:29 show me how

49:30 you have,

49:31 you're giving either logical or physical separation,

49:34 uh,

49:35 if it's in a community cloud,

49:36 a public cloud,

49:37 um,

49:38 you know,

49:38 how you're,

49:39 how you're maintaining that logical or physical

49:40 separation between my data and their data.

49:43 So,

49:44 uh,

49:44 you know,

49:44 what,

49:45 what you mentioned nude is a very valuable tool and that contract can be used

49:49 and formulated to,

49:50 you know,

49:50 to kind of push.

49:52 You know,

49:52 to get that last mile in and,

49:54 and have the,

49:55 have the provider meet the standards that you want to meet

49:58 without having it necessarily written within the,

50:00 within the cybersecurity standards.

50:07 Thank you Brian.

50:08 I think this is a question that is coming

50:09 from the audience as well about the data sovereignty.

50:12 There are a lot of comments on data sovereignty.

50:15 So you mentioned that within the US government data sovereignty,

50:18 uh,

50:19 you can,

50:19 uh,

50:19 you can have cloud service providers offshore,

50:22 right?

50:28 Most of,

50:29 most of the companies are US based.

50:32 Um,

50:32 however,

50:33 we understand that,

50:34 you know,

50:35 the way the internet works

50:37 is that data is going to travel,

50:39 you know,

50:40 uh,

50:41 trans,

50:41 uh,

50:41 across the globe.

50:43 Um,

50:43 however,

50:44 uh,

50:45 the focus is mostly on where the data resides.

50:49 And so we understand that for,

50:51 to get from point A to point B,

50:53 um,

50:54 it,

50:54 it will have to traverse outside US territory,

50:57 but

50:57 if the,

50:58 if the data is being held in a data center,

51:00 um,

51:01 that data center needs to be in the US,

51:04 uh,

51:04 on US territory

51:06 or in geolocations where there's US jurisdiction,

51:08 and that,

51:09 and that is strictly for,

51:11 uh,

51:11 our high-impact data.

51:14 OK.

51:15 Um,

51:16 the,

51:16 the joint authorization board has been more lenient with regards to that,

51:20 uh,

51:20 with moderate and low,

51:22 um,

51:22 because we consider low data is publicly accessible,

51:25 publicly releasable,

51:26 um,

51:27 You know,

51:28 we're not so concerned about that,

51:29 but for the high impact data,

51:31 uh,

51:31 the,

51:31 the Joint Authorization Board has,

51:33 has wanted to look at that a little more

51:35 closely and make sure that controls are in place,

51:37 uh,

51:38 to,

51:38 to make sure that that data stays within,

51:40 within,

51:41 you know,

51:41 the US ostensibly.

51:44 And,

51:45 but

51:45 also we have,

51:46 we have

51:47 encryption requirements too for data in transit.

51:49 So,

51:50 it's not just out there blowing in the wind,

51:52 uh,

51:53 so to speak,

51:53 or just live on the wire,

51:55 it's,

51:55 uh,

51:56 there,

51:56 there are encryption standards for,

51:58 for data in transit that,

51:59 that cloud service providers have to meet as well.

52:03 Thank you.

52:04 I hope Luda,

52:05 Luda had this question actually in the chat box,

52:07 so I hope that question is answered from,

52:09 uh,

52:09 uh,

52:10 on the data sovereignty.

52:11 Uh,

52:12 yes,

52:12 thank you very much,

52:13 very,

52:13 very useful,

52:15 very much appreciated.

52:17 Yeah,

52:17 thank you.

52:18 So,

52:18 given I think there are so many questions,

52:20 uh,

52:20 I will ask Nathanny to extend the session by 10 minutes.

52:24 So the next question is from Tracy.

52:27 Uh,

52:28 do you want to come in or?

52:31 Thanks

52:32 I'll ask you very quickly.

52:34 I just wanted to know what life looked like before FedRAM was set up.

52:38 So how did you reach that point?

52:40 Uh,

52:40 what was needed in terms of coordination or leadership,

52:43 uh,

52:44 to get to this kind of whole of government approach?

52:46 Thanks.

52:48 No problem.

52:48 That's a great question.

52:49 Uh,

52:49 unfortunately,

52:50 that sort of predates me,

52:51 but,

52:52 um,

52:53 having some of the history on the program,

52:55 again,

52:55 as is explained in the video previously,

52:58 um,

52:58 you know,

52:58 we saw the advent of cloud computing.

53:01 Um,

53:01 and so we,

53:03 there,

53:03 there was,

53:04 uh,

53:04 an observation that across the government that,

53:07 you know,

53:07 with 10 different federal agencies,

53:09 each agency would have,

53:11 had its own standard

53:12 to basically uh assess the same product over and over and over again.

53:17 And so,

53:18 Uh,

53:19 you know,

53:19 not only,

53:20 not only does the Fed,

53:21 so

53:22 there's resource constraints or resource costs per agency of having to do that,

53:26 but it's also a burden on the cloud service provider.

53:29 So

53:30 if you think about it from an economic model,

53:32 the more things,

53:33 if,

53:33 if the cloud service provider has to spend money

53:35 to do something over and over and over again,

53:37 that cost is not.

53:38 They're not gonna

53:39 absorb that cost that's gonna get passed back to the customer

53:42 and then this customer is the,

53:44 uh,

53:44 is the federal government.

53:45 So,

53:46 um,

53:46 part of the motivation is,

53:48 you know,

53:48 ensuring that we have a,

53:50 uh,

53:50 uh,

53:51 uh,

53:51 you know,

53:52 a,

53:52 a common framework,

53:53 a common,

53:54 uh,

53:54 standard for cloud service providers to meet with regards to cybersecurity,

53:58 but also that that's acceptable across the agencies and again,

54:01 the cloud service providers are happy about that

54:03 because they only have to do it once,

54:05 um.

54:06 You know,

54:07 OK,

54:07 so it's a little bit of a shock to them because they

54:09 don't get to charge 10 different agencies to do the same thing.

54:13 But,

54:13 you know,

54:14 looking at it from a government perspective,

54:16 we've,

54:16 we've eliminated a lot of the,

54:18 uh,

54:19 duplicative effort uh

54:21 by

54:22 agency to agency to agency to,

54:24 to basically assess the same,

54:26 same product.

54:27 Uh,

54:27 did,

54:27 did that answer your question or do you need me to go into a little more depth?

54:32 No,

54:32 that's good.

54:33 I,

54:33 I mean I think that the efficiency argument is

54:35 very well made by your presentation and the follow-up,

54:38 um I guess from our client's point of view,

54:41 That's often not enough of a driver and that there's institutional

54:46 challenges for getting to collaboration with a

54:49 different agency which requires leadership from somebody

54:52 sort of rising above that.

54:54 So I'm just wondering

54:55 with the Department of Defense in the lead here or Homeland Security or the,

55:00 you know,

55:00 something,

55:01 something from the presidency.

55:04 So that

55:07 Sorry,

55:07 I went the wrong way.

55:08 So that,

55:09 that kind of,

55:10 that still exists as a,

55:11 as an issue,

55:12 is a challenge we have in the federal government because

55:15 as I mentioned,

55:15 our federal law requires agencies to,

55:18 each agency to authorize the cloud product.

55:21 Um,

55:22 so,

55:23 depending on the difference of risk appetite of an authorizing official,

55:27 we have,

55:28 we have an individual in the agencies who work,

55:30 who

55:31 function as an authorizing official.

55:32 So they're the one who signs the paper that says

55:35 we're giving,

55:36 we're,

55:36 we're,

55:36 we're giving,

55:37 granting the authority to operate

55:39 for this particular system,

55:40 OK?

55:41 It has a FedRAM authorization.

55:43 We've looked at the package and,

55:44 and we're,

55:45 you know,

55:46 they're the ones who are accepting risk on behalf of their agency and so the issue is.

55:51 The risk appetite

55:53 is different

55:54 across the agencies and,

55:56 you know,

55:56 it's,

55:57 it's a three-fold thing.

55:58 It's,

55:58 it's personality-driven,

55:59 it's,

56:00 um,

56:01 you know,

56:01 my data,

56:02 my,

56:02 I think my data or my,

56:03 my data may be a little more sensitive,

56:06 so I'm gonna require,

56:08 um,

56:08 one of the things that we see frequently

56:10 is additional controls that,

56:12 that cloud service providers are asked to do uh is about having US personnel,

56:17 um,

56:17 access,

56:18 being able to access the environment.

56:20 Um.

56:22 At all

56:23 on the data that the agency is putting into the cloud

56:26 and

56:26 and the risk appetite of the organization,

56:29 so we haven't been able to necessarily

56:31 standardize that across the federal government,

56:33 but the starting point is

56:35 that when you look at the FedRAM package,

56:37 we know up to a certain point

56:39 that that,

56:40 that has addressed the majority of the issues.

56:45 Thanks,

56:45 bye.

56:48 Uh,

56:48 OK.

56:48 Our next question is from Hain Von Lee.

56:51 Uh,

56:52 this is regarding interoperability.

56:53 Hain,

56:54 you are around to ask the question,

56:55 or you want me to?

56:58 Uh,

56:58 hi,

56:58 Crown.

56:59 Can you hear me?

57:01 Um,

57:02 thanks,

57:02 Brian and thanks foram.

57:03 Um,

57:04 so my question was more,

57:05 um,

57:06 on interoperability of the system and,

57:09 um,

57:09 if,

57:10 um,

57:11 if

57:12 there's a service that needs to pull,

57:14 uh,

57:14 multiple sources of data across different agencies,

57:18 um,

57:20 what were some of the measures that you had to introduce to make sure,

57:24 um,

57:25 the interoperability between data sharing and the system,

57:28 um,

57:28 is guaranteed,

57:30 um.

57:31 Yeah,

57:31 thank you.

57:38 My apologies,

57:39 I.

57:40 Can you hear me?

57:42 Yeah,

57:42 yeah,

57:43 OK,

57:43 so

57:44 that the,

57:44 the data interoperability is not really

57:48 a responsibility of FedRAM.

57:49 That is something that the agencies need to work out on the agency level.

57:54 We are making sure that the environment in which they're put,

57:57 in which they put their data is secure.

58:01 Yeah.

58:03 OK,

58:04 the next question is from Fasil.

58:06 Uh,

58:07 and this is regarding uh institutional readiness.

58:11 Vessel.

58:17 So I can ask a question.

58:19 Sure,

58:19 uh,

58:20 OK,

58:20 please,

58:21 uh,

58:21 so that,

58:22 uh,

58:23 how did you,

58:24 uh,

58:24 promote the institutional readiness

58:27 for cloud adoption?

58:29 Again,

58:30 that,

58:30 you know,

58:31 providing an environment that,

58:33 that meets a specific standard with regards to cybersecurity,

58:36 uh,

58:37 sort of allays a lot of fears,

58:39 um,

58:39 that once,

58:41 once agencies see exactly the standard that,

58:43 that cloud,

58:44 that cloud service offerings that have FedRAM authorizations meet,

58:48 um,

58:48 they understand that it's not just,

58:50 uh,

58:51 the initialment but it's the continuous monitoring,

58:54 um.

58:54 And also our continuous monitoring data is

58:57 available to the agency customers and anybody who

58:59 is thinking about a uh uh a US federal agency who's thinking about using that cloud

59:04 can,

59:04 can request that data,

59:06 so they can see

59:07 the,

59:08 the,

59:08 the,

59:08 the performance record of the cloud service and so,

59:12 Knowing the standard and being able to see their performance

59:16 has allayed a lot of fears on,

59:18 uh,

59:19 you know,

59:19 just walking in,

59:20 just throwing their data into a cloud,

59:22 um,

59:23 you know,

59:23 they,

59:23 they have to be very judicious with what they're doing,

59:26 uh,

59:26 with their resources,

59:27 obviously,

59:28 and,

59:28 and they want to make sure that their data is protected.

59:31 And so again,

59:31 it's that FedRAM authorization and understanding their,

59:34 their track record which,

59:36 uh,

59:36 provides a level of confidence to agencies that,

59:38 that allows them to do that.

59:42 Thank you.

59:43 And now

59:44 Rajendra Singh,

59:45 you wanted to ask a question directly.

59:50 Thank you very much.

59:50 Uh,

59:51 thank you,

59:51 Koram.

59:52 Uh,

59:52 my point was,

59:53 uh,

59:54 and thank you,

59:54 Brian,

59:55 for this excellent presentation.

59:57 This is in continuation of the questions asked by,

1:00:00 by my previous colleagues.

1:00:03 See,

1:00:04 when we look at it from our client country's point of view,

1:00:07 I mean,

1:00:08 look,

1:00:08 in the United States,

1:00:10 you have NITA,

1:00:11 you have excellent partnership within the government and

1:00:15 outside government.

1:00:17 What I'm wondering is,

1:00:18 uh,

1:00:19 like,

1:00:19 uh,

1:00:20 in our client countries,

1:00:21 where to pick up the threat.

1:00:25 You know,

1:00:26 everything is in a complete mess,

1:00:28 and they are investing a lot of money

1:00:31 on creating their own data centers.

1:00:33 Sometimes different ministries,

1:00:35 they have their own

1:00:36 data centers.

1:00:37 So

1:00:38 where exactly we as an institution,

1:00:41 we should make the intervention.

1:00:43 And say that,

1:00:44 uh,

1:00:44 you know,

1:00:45 this is like uh

1:00:46 our procurement colleague,

1:00:47 he mentioned about,

1:00:49 uh,

1:00:49 you know,

1:00:50 value for money and all those things.

1:00:52 Uh,

1:00:53 so,

1:00:53 how do we start it in our project?

1:00:56 Uh,

1:00:56 what is your suggestion?

1:00:57 Thank you.

1:01:00 So,

1:01:02 uh,

1:01:02 I,

1:01:02 I,

1:01:03 I'll take a swing at this.

1:01:04 This is kind of outside my wheelhouse,

1:01:05 but we had a,

1:01:06 a concerted effort,

1:01:08 uh,

1:01:08 in the US government to,

1:01:10 um,

1:01:10 move to cloud.

1:01:12 Um,

1:01:13 there was,

1:01:14 uh,

1:01:14 executive leadership at the department,

1:01:16 at,

1:01:17 at the agency heads,

1:01:18 at the agency leadership level,

1:01:20 um,

1:01:21 to move to cloud,

1:01:22 um.

1:01:24 And recognizing that the inefficiencies of each

1:01:29 agency having their own data centers,

1:01:31 you know,

1:01:32 we understand that that's appropriate because there are some,

1:01:34 there,

1:01:35 there may be some instances and some use cases where

1:01:38 an agency having their own data centers completely appropriate,

1:01:41 um.

1:01:43 But also on those,

1:01:45 on those things that can be leveraged,

1:01:47 um,

1:01:47 because there are a lot of capital expenses,

1:01:49 uh,

1:01:50 dealing with,

1:01:50 with data centers,

1:01:52 um,

1:01:52 and,

1:01:53 and the management of the,

1:01:54 of the systems inside,

1:01:56 um.

1:01:57 You know,

1:01:57 it,

1:01:58 there was a push

1:01:59 to,

1:02:00 uh,

1:02:00 to cloud from uh executive leadership in,

1:02:04 in the US,

1:02:05 uh,

1:02:06 from the agency level and,

1:02:07 and on down.

1:02:08 I believe President Obama was,

1:02:10 uh,

1:02:10 pushed,

1:02:11 uh,

1:02:11 cloud computing quite a bit during his administration as well.

1:02:15 So it's,

1:02:15 it's,

1:02:17 it's

1:02:18 moving towards,

1:02:18 and,

1:02:19 and it's understanding too

1:02:20 that the cloud provides capabilities that are,

1:02:25 that are expensive to build and maintain.

1:02:27 Um,

1:02:27 and there,

1:02:28 the elasticity and the availability of the cloud is there when you need it and,

1:02:33 and it can go away when you don't.

1:02:35 Um,

1:02:35 I think that is a,

1:02:36 that is huge,

1:02:37 is a huge selling point for the cloud.

1:02:39 Um,

1:02:40 it allows,

1:02:41 uh,

1:02:41 it allows,

1:02:42 uh,

1:02:43 it has allowed our government agencies to innovate

1:02:46 because of the computing power that,

1:02:48 uh,

1:02:48 that it,

1:02:49 that the cloud brings,

1:02:50 um,

1:02:51 that they would,

1:02:51 it would,

1:02:52 it would just be again too very expensive to replicate.

1:02:55 Uh,

1:02:55 in their own data center,

1:02:56 but,

1:02:57 you know,

1:02:57 there's,

1:02:58 uh,

1:02:59 and,

1:02:59 and we saw it with,

1:03:00 uh,

1:03:00 with the advent,

1:03:02 not the advent,

1:03:02 that's a poor word,

1:03:03 but with the,

1:03:04 with the onset of COVID,

1:03:06 um,

1:03:07 we saw that the,

1:03:08 uh,

1:03:09 the cloud computing capability is critical

1:03:12 for supporting a,

1:03:13 a,

1:03:13 a,

1:03:14 uh,

1:03:14 dispersed workforce,

1:03:16 um,

1:03:17 not just in the,

1:03:18 on the commercial side,

1:03:19 but on the,

1:03:20 uh,

1:03:20 on the government side as well.

1:03:22 Uh,

1:03:22 we've,

1:03:23 and,

1:03:23 and we've seen our numbers of reuse of authorized cloud services,

1:03:27 uh,

1:03:28 basically take off exponentially,

1:03:30 uh,

1:03:30 since April of last year,

1:03:32 as you can imagine,

1:03:33 because,

1:03:34 you know,

1:03:34 all the

1:03:35 cloud systems that were required are,

1:03:37 are being used or wanting to be used by,

1:03:40 uh,

1:03:40 federal agencies to support,

1:03:42 uh,

1:03:42 uh,

1:03:42 a new work paradigm that they weren't necessarily used to doing.

1:03:48 Uh,

1:03:49 a similar question to Rajendra is my question.

1:03:51 Uh,

1:03:52 sorry,

1:03:52 I'm jumping the queue because this is relevant to Rajendra's question.

1:03:55 This is regarding enforcement.

1:03:57 Uh,

1:03:58 is there any agency in the US government,

1:04:00 uh,

1:04:01 they can use their own budget to build their own

1:04:02 data center or continue using their own data center,

1:04:05 or there is some enforcement mechanism for Fed ramp.

1:04:09 So,

1:04:10 yeah,

1:04:10 I,

1:04:11 I,

1:04:11 you know,

1:04:12 depending on agency policy

1:04:14 and depending on what they're doing with their data

1:04:17 and what type of data it is,

1:04:18 I'm sure they could.

1:04:19 Um,

1:04:20 we,

1:04:20 we do again have enforcement,

1:04:22 we have,

1:04:23 uh,

1:04:24 Enforcement mechanisms within FedRAM.

1:04:26 So if the I,

1:04:27 I mentioned continuous monitoring and the

1:04:29 vulnerability addressing the vulnerabilities that,

1:04:31 that are,

1:04:32 that are reported each month,

1:04:33 if a cloud service provider isn't doing what they're doing

1:04:36 or what they're supposed to be doing,

1:04:37 we can,

1:04:38 we can remove them from the marketplace.

1:04:40 We can,

1:04:41 the joint authorization board has the,

1:04:43 has the power basically to revoke their authorization

1:04:46 and,

1:04:47 and that's not a good look for a commercial cloud service

1:04:49 who wants to keep doing business with the federal government,

1:04:52 um.

1:04:54 So there's other methods

1:04:55 um that can be done.

1:04:57 Newt mentioned the,

1:04:57 uh,

1:04:58 the contracting if,

1:04:59 if there,

1:05:00 if there are clauses put in the contract about performance SLAs

1:05:04 and the like,

1:05:05 um,

1:05:05 those are,

1:05:06 those are methods of enforcement as well.

1:05:08 Um,

1:05:09 so there's something built in,

1:05:10 but we don't have a central agency who says,

1:05:13 you know,

1:05:13 you're going to do this.

1:05:15 I,

1:05:15 it's,

1:05:16 we,

1:05:16 we manage that for commercial cloud services

1:05:19 with FedRAM authorizations at the PMO.

1:05:23 The next question is from Atul.

1:05:25 This is regarding,

1:05:25 uh,

1:05:26 given the data breaches of the federal systems,

1:05:28 are there specific advantages of using cloud,

1:05:32 uh,

1:05:32 compared to the traditional data centers?

1:05:34 I think you have answered this question,

1:05:35 but just briefly recap.

1:05:40 Yeah,

1:05:40 um,

1:05:43 Uh,

1:05:44 Kuram,

1:05:44 if I may,

1:05:45 uh,

1:05:45 yeah,

1:05:46 uh,

1:05:46 Brian,

1:05:47 Brian,

1:05:47 uh,

1:05:47 thank you for a very informative presentation.

1:05:49 I mean,

1:05:49 uh,

1:05:50 my question basically was,

1:05:51 you know,

1:05:51 one has heard about,

1:05:52 uh,

1:05:53 data breaches of federal systems,

1:05:55 uh,

1:05:55 in the last few years,

1:05:57 more often than earlier.

1:05:58 I mean,

1:05:58 uh,

1:05:59 just before the elections,

1:06:00 around the 2016 elections.

1:06:02 Uh,

1:06:03 so I was wondering,

1:06:03 I mean,

1:06:03 uh,

1:06:04 one,

1:06:04 has it,

1:06:05 has this,

1:06:05 uh,

1:06:06 more regular breach.

1:06:07 of,

1:06:08 uh,

1:06:08 uh,

1:06:09 you know,

1:06:09 data,

1:06:10 federal data systems got anything to do with the

1:06:12 move from,

1:06:13 uh,

1:06:14 using traditional data centers to using cloud service providers

1:06:18 and from a data protection perspective,

1:06:20 um,

1:06:21 are there specific advantages of using,

1:06:23 uh,

1:06:24 CSPs,

1:06:24 uh,

1:06:25 vis a vis the traditional data centers?

1:06:26 I mean,

1:06:27 are they related,

1:06:27 uh,

1:06:28 in a way,

1:06:29 uh,

1:06:30 in terms of security systems?

1:06:31 Thanks.

1:06:38 So I'm not sure.

1:06:40 I,

1:06:40 I,

1:06:41 I don't have any statistics or data on,

1:06:44 you know,

1:06:44 which,

1:06:45 which one is safer.

1:06:46 I know

1:06:48 that um,

1:06:51 Basically the standard in which we,

1:06:53 we,

1:06:53 we

1:06:54 hold the commercial cloud service providers to,

1:06:57 um,

1:06:58 there's they have reporting requirements to us,

1:07:01 um.

1:07:03 Yeah,

1:07:03 that's,

1:07:03 that's a hard question to answer.

1:07:05 Um,

1:07:06 again,

1:07:06 not having any side by side comparison between,

1:07:09 you know,

1:07:09 on-prem,

1:07:10 you know,

1:07:10 agency data centers and,

1:07:12 and the cloud,

1:07:13 um,

1:07:14 you know,

1:07:14 the.

1:07:16 Each agency though,

1:07:17 it,

1:07:17 it,

1:07:18 the security in the cloud,

1:07:19 especially with commercial cloud,

1:07:20 it's a shared responsibility model.

1:07:22 OK.

1:07:23 And so,

1:07:25 you know,

1:07:25 we're,

1:07:25 we're very,

1:07:26 the cloud service providers are,

1:07:28 are very adamant about,

1:07:29 and,

1:07:29 and they're very good about meeting the standard that we,

1:07:32 that we prescribe,

1:07:34 um,

1:07:35 but again,

1:07:35 it's a,

1:07:36 it's a shared,

1:07:36 it's a shared system.

1:07:38 So,

1:07:38 you know,

1:07:39 each agency who uses that cloud,

1:07:40 each customer

1:07:42 has to make sure that they're doing the right thing,

1:07:44 that,

1:07:44 that

1:07:45 they're configuring their instance properly.

1:07:46 Properly and things of that nature.

1:07:48 Um,

1:07:49 and so it's a,

1:07:50 it,

1:07:51 it's a more holistic effort with regards to security

1:07:54 in,

1:07:54 in,

1:07:54 in,

1:07:55 you know,

1:07:55 creating that defense in depth because the agencies

1:07:58 are doing what they're supposed to be doing.

1:07:59 The,

1:08:00 uh,

1:08:00 the cloud service providers are doing what they're supposed to be doing,

1:08:03 and,

1:08:03 and there's,

1:08:04 and,

1:08:04 and there's validation along that,

1:08:05 you know,

1:08:06 we have,

1:08:06 we do that with our continuous monitoring and

1:08:08 the agencies do that internally as well.

1:08:11 So again,

1:08:11 I'm not sure if I can,

1:08:13 if that really answered your question or if I've provided the right.

1:08:16 You know,

1:08:16 insight to that,

1:08:17 but,

1:08:18 um,

1:08:19 you know,

1:08:19 maybe I can take another stab at it if,

1:08:21 if,

1:08:21 if that didn't work.

1:08:24 No,

1:08:24 it's fine.

1:08:24 I mean,

1:08:24 I was just wondering whether accountability gets diffused then.

1:08:27 I mean,

1:08:27 uh,

1:08:28 rather than having a single point of

1:08:30 accountability onto like a departmental data center,

1:08:33 whether this cloud thing kind of dilutes accountability and responsibility.

1:08:36 But thank you.

1:08:37 I think that was helpful.

1:08:39 Mhm.

1:08:40 Next question is from Anat Levin.

1:08:42 Uh,

1:08:42 this is regarding matrix.

1:08:43 Anat.

1:08:44 Yes,

1:08:45 thanks very much.

1:08:46 Um,

1:08:46 my question is,

1:08:47 is whether there are metrics that measure the effectiveness of this,

1:08:50 uh,

1:08:51 FedRAM framework,

1:08:52 um,

1:08:52 in preventing the hacks,

1:08:54 breaches,

1:08:54 and attacks that we see so often in the news right now.

1:08:57 So,

1:08:57 where my question is coming from is,

1:08:59 of course,

1:08:59 we see

1:09:00 cybersecurity attacks.

1:09:01 and breaches even against cybersecurity firms and even against

1:09:05 major cybersecurity agencies,

1:09:07 uh,

1:09:08 so obviously the attacks are increasing in terms of their,

1:09:11 um,

1:09:13 um,

1:09:13 and at the same time we see that in our client countries,

1:09:16 uh,

1:09:16 you know,

1:09:17 they wouldn't,

1:09:17 uh,

1:09:17 they wouldn't be prepared at this stage to sort of take on

1:09:21 something to the level of depth and intricacy.

1:09:22 As,

1:09:23 as you're proposing with FedRAM,

1:09:24 but it would be interesting to see how effective is the Fed,

1:09:27 the FedRAM governance framework right now

1:09:30 in preventing hacks,

1:09:32 um,

1:09:33 and is there a way for,

1:09:34 for us at the World Bank to look at maybe a FedRAM light

1:09:38 or sort of a FedRAM phase one,

1:09:41 that might be appropriate for some of our client countries.

1:09:43 Thank you.

1:09:44 No,

1:09:44 that's a great question.

1:09:45 Uh,

1:09:45 we don't have any specific metrics on how effective it is for,

1:09:50 um.

1:09:52 Preventing hacks,

1:09:53 um,

1:09:54 again,

1:09:55 it,

1:09:55 it's,

1:09:56 we have,

1:09:56 because of the shared security model,

1:09:58 we have

1:09:59 different sets of eyes looking at it.

1:10:00 So when we,

1:10:01 when,

1:10:02 when there's anomalous activity that's noted,

1:10:04 um,

1:10:05 or that's discovered within the,

1:10:07 within the boundary,

1:10:08 so when,

1:10:08 when a cloud service.

1:10:09 Uh,

1:10:11 when a cloud service provider comes to FedRAM,

1:10:13 they bring a specific cloud service offering,

1:10:15 and

1:10:16 the way we authorize it is we look

1:10:18 at the specific security boundary in which they're,

1:10:21 which they're proposing,

1:10:22 and then we do all the assessment and the testing,

1:10:25 uh,

1:10:26 against that proposed boundary,

1:10:28 um,

1:10:28 but

1:10:29 we don't have any statistics on how effective it is in preventing hacks.

1:10:33 It's a

1:10:35 Uh,

1:10:35 the analogy I've heard before with regard to,

1:10:38 uh,

1:10:39 uh,

1:10:39 football is being a goalie.

1:10:42 Um,

1:10:42 it's,

1:10:42 it's trying to make sure that they don't get in,

1:10:45 um,

1:10:46 and then mitigating as soon as possible,

1:10:48 uh,

1:10:48 with as less,

1:10:49 with as little impact,

1:10:51 um,

1:10:52 should they get in.

1:10:53 Um,

1:10:54 we know that there are advanced persistent threats and

1:10:57 we try and tailor controls to address those,

1:11:00 um,

1:11:00 but

1:11:01 in terms of metrics,

1:11:02 we don't have anything specific.

1:11:04 Um,

1:11:04 with regards to adoption,

1:11:06 we've had

1:11:07 Other governments

1:11:09 um

1:11:10 that have uh been interested in the FEDRAM program.

1:11:14 Also,

1:11:15 um,

1:11:15 there is,

1:11:16 uh,

1:11:17 amongst the 50 states,

1:11:18 uh,

1:11:18 within the US

1:11:20 there's a,

1:11:20 a consortium of chief information officers

1:11:23 who are looking at the FedRAMP standard to

1:11:26 apply towards cloud services that are being used by state governments as well.

1:11:32 Thank you.

1:11:33 And last question to Brian before I turn to Canutt.

1:11:37 Cute,

1:11:37 you have two questions,

1:11:38 but,

1:11:38 uh,

1:11:39 uh,

1:11:39 that will be the last.

1:11:40 Uh,

1:11:41 so last question is on international standards on cloud security.

1:11:45 Uh,

1:11:45 are there any international regulations requirements?

1:11:47 This is from Sadiq Assad.

1:11:49 Uh,

1:11:49 requirements that could be used during procurement.

1:11:53 Any international standards or regulations?

1:11:59 Uh,

1:11:59 from our perspective,

1:12:00 uh,

1:12:01 you know,

1:12:01 we,

1:12:02 we adhere to the

1:12:03 NIST 853 standards,

1:12:05 uh,

1:12:06 that are published by the US government,

1:12:07 and,

1:12:08 um,

1:12:10 Because

1:12:10 our,

1:12:11 our work is strictly across,

1:12:13 uh,

1:12:13 the US federal agencies,

1:12:15 um,

1:12:15 we haven't had to address international standards.

1:12:18 Um,

1:12:19 we know that cloud service providers though,

1:12:21 they have,

1:12:22 uh,

1:12:22 multiple,

1:12:23 uh,

1:12:24 multiple regimes in which they have to comply with

1:12:27 because they do business transnationally.

1:12:30 Um,

1:12:30 but with regards to what the US government is looking for,

1:12:33 we,

1:12:33 we,

1:12:34 uh,

1:12:34 hang our,

1:12:35 our proverbial hat on those NIST,

1:12:37 uh,

1:12:37 security controls.

1:12:39 Yeah,

1:12:40 I can answer this question.

1:12:41 There is ISO 27,017

1:12:45 international standard,

1:12:46 uh,

1:12:46 applicable together with the Security international standard 27,001 and 2.

1:12:52 So together these three standards are the international standard that can be used.

1:12:57 So,

1:12:57 uh,

1:12:58 Kut,

1:12:58 uh,

1:12:59 uh,

1:12:59 Tracy had a question regarding,

1:13:01 uh,

1:13:01 procurement,

1:13:02 and Tracy,

1:13:03 maybe you can ask

1:13:04 directly.

1:13:11 I think it has answered the question actually so it seems

1:13:13 that this has not been taken up widely in our projects.

1:13:17 Thanks.

1:13:18 OK.

1:13:19 Yeah,

1:13:19 uh,

1:13:19 Kuram,

1:13:19 I try to,

1:13:21 I answered in,

1:13:22 in the chat function to everyone,

1:13:26 but maybe,

1:13:27 maybe I can,

1:13:28 I can say a few words on what Brian just mentioned and,

1:13:30 and you as well on the availability of standards.

1:13:33 Uh,

1:13:33 this,

1:13:34 this has been always the discussion,

1:13:35 and it will be,

1:13:36 of course,

1:13:37 in the future if it comes to procurement under bank funded projects,

1:13:40 um.

1:13:41 The preferred option is if there were international standards like you mentioned,

1:13:45 the ISO 27,000,

1:13:47 I think 17 for security in combination with one and two.

1:13:52 So if this is given and sufficient,

1:13:54 and this depends also from the technical team of course in a project to assess this,

1:14:01 this is the preferred option.

1:14:02 If it comes to national standards,

1:14:04 we always have been struggling with the fact.

1:14:06 Does it exclude providers or not?

1:14:09 And this goes back to the need of doing a market analysis.

1:14:13 Is there a sufficient market available in the country to do that,

1:14:17 so which would maybe

1:14:20 not so interested for international.

1:14:22 Providers,

1:14:23 so this really has been an issue,

1:14:24 will be an issue,

1:14:25 but always I point out

1:14:28 during the project procurement strategy for

1:14:31 development in the preparation phase,

1:14:33 those are the areas that have to be addressed

1:14:36 and solutions have to be found.

1:14:38 Thanks.

1:14:40 Uh,

1:14:40 thank you very much for a very rich conversation.

1:14:43 And now I will request Tracy Lane,

1:14:45 our practice manager,

1:14:46 for her closing remarks.

1:14:48 Thank you,

1:14:49 Karam.

1:14:49 And let me also just start by thanking our presenter,

1:14:52 Brian and colleague Janelle,

1:14:54 uh,

1:14:54 for this,

1:14:55 uh,

1:14:55 fantastic presentation and,

1:14:57 uh,

1:14:58 really very clear and informative for us.

1:15:01 Thanks to to Ed and Not because they,

1:15:04 their comments really stimulated a great debate and discussion this morning.

1:15:08 For me,

1:15:08 it's clear that cloud computing has great opportunities.

1:15:13 As an economist,

1:15:14 you had me at

1:15:16 your efficiency gains for private sector and federal savings.

1:15:19 So

1:15:20 this,

1:15:21 this US model really is something I think we can all

1:15:24 learn from.

1:15:25 But it's also clear from our discussion and debate that our clients still have some

1:15:29 way to go before they're ready to take on board these kind of opportunities.

1:15:34 Um,

1:15:34 I really think the fact that the bank is,

1:15:36 is thinking about this,

1:15:38 that we're looking at the technical issues,

1:15:40 institutional issues,

1:15:41 and procurement issues

1:15:43 is going to prove to be of,

1:15:45 uh,

1:15:45 help and support to clients on the,

1:15:48 to our clients

1:15:49 directly,

1:15:49 but also to our child's teams on the ground,

1:15:51 and maybe I can just take this opportunity to flag

1:15:54 upcoming work.

1:15:56 That Kara is going to lead

1:15:58 in partnership with uh with Ed and DD and in procurement to provide that guidance in a

1:16:04 in a way that uh builds off this this

1:16:07 BBL today and you should expect to see that

1:16:10 by the end of the fiscal year.

1:16:11 I hope I'm not raising too many eyebrows from the team by saying that.

1:16:14 So really,

1:16:15 um,

1:16:16 this,

1:16:16 uh,

1:16:16 is a new area.

1:16:17 For us,

1:16:18 great opportunities but also risks and clearly our

1:16:21 clients are not yet where the US is.

1:16:24 So it's good for us to explore both the US but other examples of how this is being taken

1:16:29 forward to look at what might be some of the

1:16:32 steps and the map towards this kind of institutional setup

1:16:36 that we've we've had explained to us today.

1:16:39 Um,

1:16:40 really want to thank everybody,

1:16:41 but also acknowledge,

1:16:42 um,

1:16:43 Ed and his time that he spent with us today

1:16:45 and the fact that we had,

1:16:47 um,

1:16:47 more than 50 of you,

1:16:49 um,

1:16:49 here this morning.

1:16:50 So really thanks to all of you for,

1:16:51 for giving us your time and attention to this topic.

1:16:54 Thanks a lot everybody and enjoy the rest of your day.

1:17:02 Very much.

1:17:04 Thank you.

showAllTimestamps
no
transcript
The, uh, should we start at I see at. Yes, uh, we can start. Kan, thanks. Yeah, so the objective of today's BBL is to demystify cloud computing and facilitate mainstreaming of it in our client countries. Uh, the agenda is opening opening remarks from Ed. They will be our main presentation. Then deflections from our two experts followed by a question and answer session, and then closing remarks from Tracy. The event is open to external participation from our clients. Uh, now I invite Ed to please, uh, open the meeting with his opening remarks. OK, uh, thank you very much, uh, Khuram, and, uh, good morning, good afternoon, good evening to everyone, depending on where you are connecting from. Uh, I want to, uh, welcome all of you to, uh, today's BBL, uh, a special welcome to our guest speaker today, Brian Conrad, uh, who is the acting director of Fed RAM. And program manager for cybersecurity GSA in the US government. I would also like to welcome our discussions today, uh, Ken, uh, who is lead procurement specialist, and also Ed Usu, who is, um, the senior advisor at digital development. Uh, many thanks also to Khuram and the Govtech team for organizing, uh, this, uh, event, uh, which is focusing on a very important topic. As many of you know, advanced digital economies are mainstreaming disruptive technologies like cloud computing. These governments are harnessing the transformational potential of cloud computing to reduce costs, strengthen security, and accelerate innovation. COVID-19 has provided further push to cloud computing. Client governments can also take advantage of cloud computing. And they have various concerns, but given some of their concerns about sensitivity of data and sovereign issues, they can adopt different options. And for instance, they can use public cloud for non sensitive data while retaining the sensitive data on premises or private cloud. But there is really no reason why our client countries cannot use cloud computing and take advantage of the opportunities that this offers. In FCV settings, saving costs, improving access, and ensuring business continuity uh make uh even more compelling business case for cloud adoption. However, as I was alluding to, mainstreaming cloud computing in our client countries is facing challenges. On the one hand, most client governments cite cybersecurity and data sovereignty as key risks. On the other hand, our task teams and staff do not have adequate guidance on how to navigate cybersecurity and cloud procurement arrangements. Our traditional procurement models, for instance, are focused on capital goods. Uh, services, uh, in contrast to the subscription-based cloud services model. There is, however, high demand from our clients and task teams for guidance and knowledge sharing on cloud computing. Given its relevance to digital transformation and the development agenda that we are working on. To respond to this demand. I want to thank the Govtech team for organizing this BBL, which is really focused on learning lessons from the US government. The US government is a pioneer in mainstreaming cloud computing in government. The Gov tech team is also preparing technical guidance on cybersecurity assessment framework for cloud computing applicable to cloud procurement, and that will be made available shortly. I will encourage our task teams to support clients in their adoption of cloud computing. And in this regard, the governance, global practice and digital development GP recent joint work in supporting Palestinian Authority on cloud readiness assessment is a good example that we could adopt going forward, so. Uh, to support our clients better on this agenda, I want to emphasize three, key points. One is we need to promote a whole of government approach to procurement rather than agency-specific piecemeal approaches, OK. Especially when we are talking about this, uh, cloud computing, uh, promote structured empirical cybersecurity assessment framework. As we learn, I mean, as we will learn today from uh the various uh uh speakers, uh, to facilitate a risk mitigation approach rather than the current approach of risk avoidance. We also need to collaborate, that is with the digital development and other GPs to support our clients and to share knowledge and concrete examples on cloud computing so as to promote and facilitate the adoption and use of cloud computing. I really look forward to a very interesting session today. Uh, and again I want to thank the guest speaker and uh our discussions and also the team that organized this. So thank you so much, uh, back to you, Korra. Thank you, Ed. And now I will invite our guest speaker, Brian Conrad to share, uh, his presentation, uh, based on US experience. Brian, over to you. Hi, this is Janelle Thels. I support Brian at the Feder PMO. It looks like he might have gotten kicked off. So if you just wait one moment, um, he should be. I'm here. We're here. OK, I'm here. My apologies. Um, the Webex mute button was very elusive. Uh, however, I was successful in finding it. Thank you everyone for having me today. Um, I am very, uh, honored and humbled to come and present on the US government's Federal Risk and Authorization Management Program known as FEDRAMP. Um, I will have to warn you, the US government floats on a sea of acronyms and abbreviations. So for such a diverse audience, if there's, if I say something and just blow past it, please, uh, raise your hand, keep me honest, and, uh, because I will, I will consider it, the, I will consider that I've done my job well today, um, if you leave with a greater understanding of what we're doing, OK? So let's get started. Next slide, please. This is me, um, next slide. So we're gonna start out with a little Fed ramp overview and, and that is uh gonna be with a YouTube video that we had produced. So, uh, sit back and enjoy for a couple of minutes and it will give you an overview and then I'll go into detail after the video. The Federal Risk and Authorization Management Program, FEDRAMP. Promotes the adoption of secure cloud services across the US government, providing a standardized approach to security assessments for cloud service offerings. FedRAM creates a partnership between the federal government and industry. Together we modernize IT infrastructure while protecting federal information. Before FedRAM, vendors had to meet different security requirements for each federal agency. FedRAM eliminates this duplication by providing a common security framework, making it possible for agencies and cloud service providers to reuse authorizations. Agencies review a standardized set of security materials against one common baseline. A cloud service offering is authorized once and then the security package can be used by any federal agency. FedRAM's guiding principle is reuse, do once, use many times. This saves money, time and effort for both agencies and cloud service providers. All right, next slide, please, to know. Brian, can you open your video, please? Oh, I'm sorry. My video, video, yes, thank you so much. I have that my video is on. Can you not see me? Can others see Brian? No, no, we cannot see you. Yeah, we can see just the presentation. But we can see the presentation. Maybe you can go ahead. Uh, yeah, that's fine. The, the. The presentation is much more pleasant to look at than I am. So, um, I'll, I'll get into this. Uh, the mission of, of the Federal Risk and Authorization Management Program is that we promote the adoption of secure cloud services across the federal government by the US government by providing a standardized approach to security and risk assessment. So, as the video said, you know, the idea of behind FedRAM is that we authorize a cloud service once and it can be reused across the federal government. Next slide, please. So, like anything, there is a legal and policy framework uh that is the foundation for uh the FEDRAM program, OK? We have in the US the Federal Information Security Modernization Act, uh, which is a federal law, and that requires our, our, our government agencies to protect federal information systems. So, uh, through FISMA, they require NIST, our National Institutes of Standards and Technology to develop standards and guidelines. Uh, the Office of Management and Budget, uh, states that when agencies implement FISMA, they must use those standards that were developed by NIST. And what FedRAM does is we leverage the NIS standards and apply those to cloud services. So, um, that's, that's how we create the standardized authorization packages and, and we use the, the standards developed by the, by NIST. Um, the standards, uh, that are published by NIST, I believe, are, are publicly accessible, um, the. OM uh Office of Management and Budget circular A 130, that's what that A130 is referring to. I believe that's publicly accessible as well. So if you're interested, you can, you can download those and, and read those and, and kind of get an idea of what the legal and policy framework for FADRAM is. Next slide, please. So, on top of the legal and policy, we have a governance uh structure as well. So, as I mentioned at the top of the diagram, the Office of Management and Management and Budget provides oversight. Um, we do our cross-agency coordination through the Chief Information Officer council. So each agency, uh, has a representative on that council. And they talk through uh issues pertaining to, uh, cybersecurity and technology adoption, etc. And then we have the National Institutes of Standards and Technology, NIST, uh, which, uh, which, uh, FISMA requires to, uh, which FISMA has, um, Create the standards and, and the technical specifications. And then at the very bottom of the diagram, we see our Department of Homeland Security who does the uh cybersecurity incident response uh for across the federal government and uh the Department of the Defense of Defense and the General Services Administration. So those three agencies make up the what we call the Joint Authorization Board. Uh, this will become important to remember, uh, as I get into in a couple of slides about how cloud service providers can get authorized to, can, can get FEDRAA authorization. There's two paths, um, and one of those is through the, the Joint Authorization board, and the jab, uh, that we refer to as the JAB is also sort of like our, uh, uh, board of directors. They, they sign off on policy, uh, which is applied across the FedRA program as well. Next, please. So in talking about our stakeholders, we have the, uh, starting on the left, we have the FedRAM Program Management Office. We provide all the, the unified process for agencies and cloud services to follow, uh, to get, uh, to work towards the office. Authorization. We work with the joint authorization board to prioritize vendors, uh, to achieve the authorizations. We support the cloud service providers and agencies through the process and we maintain a secure repository of security artifacts. Um, again, we have the, uh, the federal agencies within the government who conduct quality risk assessments. Um, they deposit ATO documents in our secure repository. Uh, of course, we have our commercial cloud server providers, um, which provide the documentation and, and, uh, a very important part of this process is our third-party assessors who maintain independence, uh, through, uh, the verification and validation that the cloud service providers are actually doing what they're, what they say they're doing. Um, when I have conversations with cloud service providers and, and our third-party assessors and, and the agency, so our stakeholders across the board. Um, I tell them that protecting, you know, federal information is a team sport. Um, we all have our specific parts of the team and we, it best works when we do it collaboratively, um, where we have, and, and yes, the third-party assessors have a job, uh, to maintain, make sure that the cloud service providers are doing what they're doing. The Feder PMO has, has to make sure that policy and process are being followed, but it's all done in concert to, again, with the end goal of protecting federal information. Next slide, please. So, now we're gonna talk a little bit about the impact and you got a little bit of, of that in the, in the brief. So, federal security, US federal security policy requires all systems to be, to be authorized based on risk, OK? And what FedRAM does is it standardized that process for commercial cloud. OK, we have a model where we, we authorize once so it can be used many times. You know, doing the security authorization right the first time allows agencies to reuse the work and eliminate duplicative efforts. So if you Have multiple agencies, they don't have to do the same work twice, uh, as, as Ed mentioned, as Edward mentioned in the opening, using that whole of government approach to leverage the work that one agency has done across the, across the enterprise, so to speak. Um, with transparency, we have increased collaboration. We create a community amongst the government and the commercial vendors, um, that did not exist before. Um, we, FedRAM validates the, the security authorizations to ensure that. That there's uniformity and conformity amongst the security packages and I mentioned a central, centralized repository where agencies can request access to those existing security packages so that, that can expedite their, their authorizations. Next slide, please. So looking at the, looking at continuing into some of the more detail of the, of the FedRAM landscapes, presently, we have 4 different security baselines matched to, to risk, OK? Uh, mass, uh, matched to sensitivity of information. When you go and categorize the types of information you want to put in a cloud, um, we have, we have, uh, documentation for that. We have, uh, federal policy and guidance on how we do that. Um, it's called the Federal Information Processing Standards, and it, it basically serves as a guideline for agencies to categorize, uh, the impact level of their information. Is it very sensitive? Is it high? Is it moderate? Um, is it low, publicly accessible, publicly releasable information, that kind of thing. Um, I'll have you note that this is not necessarily used for intelligence activities or the Department of Defense because the FedRAM baseline does not send, does not do anything, uh, with classified information. This is for, uh, uh, agencies to conduct their business. So yes, there may be personally, personally identifiable information. There might be, uh, personal health information included in some of these in the information categorized, but So agencies would have to pick the cloud service that meets their requirements out of those four baselines. Presently, we have over 211 authorized cloud services in our catalog. Uh, the 1st 6 years of the program, it, uh, we got to 100, but in the last 2 years, we've doubled that number. Um, we have over 2100 agency reuses of authorized systems. So I, I wanna point this out. So we talked before about the value of FedRAM being. That it can be uh the, the cloud service provider is authorized through the cloud service offering is authorized once and it can be reused across the government. That 21, that over 2100, uh, instances of reuse is, is indicative of that because that shows, uh, in resource savings what the FedRAM program has been able to bring to the US federal government. We have. 72 participating federal agencies and we have over 220 industry partners who are participating. And again, those industry partners are not just the cloud service providers, but they're also the uh third-party assessment organizations as well. Program management office is very, very, uh, active. We, we participate in over 750 annual meetings with agencies and vendors and speaking engagements like this one. we have over 4400, uh, followers on Twitter. Um, we have a listser, uh, uh, basically an email, an email list of over 13,000, uh, stakeholders, and we have, uh, through our, our email. Info at Fed ramp.gov. Uh, our team, uh, fields over 33,000 questions a year. Um, simple things to the most complex, and, uh, and, but our team of professionals is, is there to handle that. Next slide, please. So, when we talk about authorizing, we authorize the whole cloud stack, OK? So agencies ultimately end up doing an authorization for, uh, from the infrastructure plat platform and software, and each of these components plays an important security role. So agencies must acknowledge and accept the risk associated with their federal information with these environments. Um. So where this is important is if you're an agency and you're going to put your into a platform, you can leverage. Package from that particular platform if it has a FedRAM authorization for your, for the agency's authority to operate. OK, as well, if, if there's a uh SAS provider, software is a service provider who is going into a FedRAM uh authorized environment, they get the leverage. The controls from that authorized environment for their security package as well. So it's a building, sort of a building block approach where FedRAM-authorized cloud services at the platform and infrastructure level can be leveraged up the stack. As I mentioned a couple of slides ago, we have 4 specific baselines according to the security impact. Agencies. So looking from, from tailored up to high, um, those are specific, the tailored, uh, low impact software as a service is specific to those software as a service which have a, a low-risk limited use case. Uh, for instance, uh, uh, if your agency wants to run a survey for 30 days, um, the low impact, uh, software as a service authorization may. Tailored authorization may be suitable for that. Uh, for low, it's, uh, uh, uh, 125 controls, uh, versus again, do not store personally identifiable information. Um, moving up to moderate, there's 325 controls, and this is where we find the majority of the cloud systems that we have in our catalog. 80% of those, uh, of those are at the moderate level, and then, uh, the high impact systems, um. Obviously, are, are more sensitive information if you think about law enforcement, uh, data, uh, immigration data, other personally identifiable information or, or PHI, uh, personal health information that you might find that in, in a high-impact system. So what it means by controls on the very first bullet point, those are the, that's the number of uh controls from the NIST uh standard, the 8, special publication 853, uh, currently revision 4, that those baselines are built off of. And a little more about lines, uh. So, there's different, there's 7, there's 17 uh different control family uh within the NIST baselines and, and so, for example, there are, uh, there's a family around encryption, uh, which helps ensure that only authorized parties, uh, uh, can decode the information. There's identification and and authentication. Um, we have controls built into the baselines about vulnerability scanning and malicious code, uh, boundary protection systems and interconnections, as well as configuration management. Next So we About the base of FedRAM, uh, the legal and the policy framework associated in the, in the, uh, you know, what we use for the controls to, uh, adjudicate cloud service providers. I'm gonna go into a little bit of the mechanics on how we do it, OK? So, in FedRAM, we have 3 different designations that appear on our marketplace, and, uh, those digital, I, I believe a link to that marketplace is included in the, in the later part of this presentation which you can go and look at. So we have a FedRAM ready, FedRAM in process and FedRAM authorized. And this, these designations are, are, were designed to allow uh potential agency customers to see the, the current state of a cloud service provider in the process, OK? With FedRAM ready, um, this is sort of a pre-check that we do to make sure that the cloud service offering can make it through authorization. We look at things like, um, what external services are being. Uh, the, uh, implementation of encryption, uh, those sorts of things, just kind of as a, as a pre-check before we do the authorization, the actual, uh, initial assessment. Um, usually, um, once there is a kickoff meeting either with an agency sponsor or the joint authorization board, um, that's when a cloud service provider will be listed as in process. That means they are actively going through the initial assessment. And their security package and their, all their artifacts are being examined by information systems security officers um from, from the agency or the joint authorization board and that's really the deep dive into the security package to make sure that uh the cloud service offering is. Meeting all the requirements that we have with FedRAM and when all that's said and done, um, if everything is, is judged to be satisfactory and, and, uh, and it meets our standard, that's when the, the cloud service offering will have a FedRAM authorized, uh, entry in the, in the marketplace and that shows that, uh. It allows sort of like a one-stop shop for agencies to come and look at all those cloud service providers that are authorized to see if, if there's one in the marketplace that fits, fits their needs. Sorry about that, Jana. I didn't mean to trip you up there. Next slide, please. So You've heard me mention the Joint Authorization Board and the agency authorization. So in FEDRAAM, we have two discrete paths to authorization. So, with the Joint Authorization Board, this, the JAB is the primary governance and decision-making body for the FEDRAM program. It consists of the, uh, Chief Information Officers from the Department of Defense, Department of Homeland Security, and General Services Administration. And they strictly review the cloud service providers packages for applic for acceptable risk posture using our standardized baselines. Uh, what's unique about this is the Joint Authorization board issues a provisional authorization to operate. Because the collection of those three CIOs cannot accept risk on behalf of the government, um, or be on behalf of any other agency. So each agency who wants to leverage that package, to leverage, use that cloud service that has a job authorization. We have the, we have the package, will have a uh a a understanding of the cybersecurity posture and, and of, of that particular cloud service and then they have to by US federal law, they have to uh sign off what we call an authority to operate. Again, the idea is the amount of work that they have to do is greatly reduced because the cloud service already has that FedRAM authorization or Jab provisional authorization. As well, the, uh, a, any federal agency within the US government can sponsor a FedRAM authorization as well. So, the onus is on the agency to conduct the review along with a third-party assessor, um, to make sure that the package conforms to FEDRAAM standards. And so once that is complete, the package comes over to FedRAM, to the PMO. We sign off on the completeness, we do a check on critical controls and such to make sure they're implemented and they get a, they'll be posted on the, uh, on the marketplace as FedRAM authorized and the agency will sign off an, an authority to operate or an ATO uh for that. OK. So I mentioned before the FedRAM Marketplace, and this provides a database of all cloud services with any of those three FedRAM designations whether they're uh ready in process or authorized. Um, it allows uh it. To look for third-party assessment organizations, we have a, uh, just like we have a, uh, a standard policy to authorize cloud services, we have, uh, a program to manage the, the third-party assessors who do the verification and validation of the cloud service providers. There's certain standards they need to meet, uh, in order to be accepted as FedRAMP 3 PAOs, um, third-party assessors, and, um. We maintain uh uh visibility on their performance as well. So if, if, uh, cloud service providers have a, uh, are, are having an issue addressing vulnerabilities or anything, you know, we have an escalation. Make sure that they continue to meet the, meet our standards. The same goes for the third-party assessors as well because we realize the importance of that third party, uh, assessor to validate the, the cybersecurity posture and, and validate the fact that the cloud service providers are doing what they tell us that they're supposed to be doing. Next slide, please. I, that's all my prepared material and I am, I'm more than, more than happy and prepared to take on questions from this esteemed audience. Uh, thank you very much, Brian. Thank you. This is excellent. And now I turn to our discussions. Uh, first I will ask, uh, Ed Sue, uh, senior adviser digital development, uh, to share with us his reflections on how we can mainstream cloud computing in our operations and in the client governments, uh, learning some of the lessons from the US experience. Ed, over to you. Great, thanks so much and uh thanks for inviting us and, and I just wanna echo the comments before that the governance GP and digital development are working very closely together on, on uh several initiatives in this area and we hope to continue that partnership, uh, particularly in cloud computing and, uh, and in cybersecurity. Um, just wanna make a quick, some comments first on cybersecurity broadly and then coming down, back down to cloud. Um, we have been looking at cybersecurity. Mostly from an ecosystem perspective, from a national perspective, and have been working with countries to do assess where did, where does a country stand, uh, in terms of their cybersecurity maturity, um, and now we're actually working on tools to bring that down to a sectoral and project level and start to assess cybersecurity, um, from a sectoral level, but again, it's, it's also looking at a network. And looking at uh where is the data coming from, who is using it, who is producing it, and where are all the cybersecurity vulnerabilities as the data is being produced or consumed along many different nodes or uh along the network. Um, so that being said, I think that this is obviously a very important aspect of improving cybersecurity in general, you know, I think that it's, it's almost a, a, a no-brainer that, you know, as, as our clients can leverage cloud and, and the commercial data, data providers, data storage providers much better, this is going to improve cybersecurity of the data that they store given the options that they have. So I think this is uh something that, you know, we'd be very, you know, we, we need to do, uh, much more of, we'd be interested to hear a bit more around, you know, how do you think about, you know, from, from Brian, how do you think about cybersecurity outside of, outside of just, you know, just putting data on the cloud, but of, of as data's moving in and out, and, you know, how can we also look at it from an ecosystem perspective. Coming down to the cloud, uh, you know, DD, we're also working on a global data and cloud infrastructure study that looks at broadly first enabling environment around how, you know, how does private sector look at data infrastructure within our client countries, how can we catalyze more investment, and then looking very specifically at this issue like you were saying, Karam, how can we mobilize and mainstream more use of. Cloud among our, uh, among our projects, a couple of things we're gonna do within this, uh, you know, this study is look at, you know, what are we doing within World Bank projects today, and I think that trying to benchmark what what is happening and the little that we've done so far we've seen there's many, many obstacles, uh, that, that our clients are facing. Um, and cybersecurity is just, is one of them is not being able to accurately assess, so I think this tool is very helpful. We, we definitely need to extend this tool to other areas of other barriers of why our clients are not using cloud. Um, so one thing we want to do is look at sort of uh, uh, take a holistic cost benefit analysis of cloud, looking at the financial benefits, um, uh, comparing one-time cost versus recurring costs and maintenance costs, looking at the economic benefits of which cybersecurity is one of them. But there's also a lot of benefits around data modernization, forms of IT operations, looking at other indirect impacts when the government adopts cloud. How does that catalyze other adoption of cloud, and also the social aspects of how does cloud enable improved government services. So it would be great to kind of Understand this model and, and I, you know, like, like I think was mentioned earlier, a whole government approach, we need to do this for cybersecurity, but the government needs to also kind of give guidance on all these other financial, economic, social benefits and help agencies also, uh, also across that. Um, and perhaps a reflection back that, you know, from our standpoint, we see this as incredibly important, as incredibly uh useful way, um. Uh, to, um, to, to manage some of the cybersecurity risks, um, but you know, one thing that you, you had in your presentation was, you know, when you, when you looked at the, uh, the number of cloud providers you managed to authorize 211 within the US, that, that's quite a large number of, of, of providers who are able to meet your standards. And you know, within our client countries, if we went through, if our clients went through this exercise, how many would they actually be able to identify that meet these standards other than the top 5 or 6 global providers that we're all aware of? Is that, you know, will this simply push our clients towards really using the, the, the, the hyper scales. And, and, you know, um, so I kinda wanna, we'd love to have some reflection on, on, on that from you as well, Brian. But again, thank you so much. I think this is a model for our clients, not just for cybersecurity, but we wanna use this model and look at all the other aspects of cloud adoption that, that we can standardize and, and, and help, uh, and help mainstream this across our operations. So, thank you so much. Thank you. Uh, you know, one of, one of the things that I noticed that was, uh, that I didn't cover in, in my presentation was, you know, we talked all about the initial assessment, but, uh, in, in our FedRAM requirements, we have a very, very strict, uh, continuous monitoring program and Requirements we have, we, we, we make sure that the cloud service providers on a monthly basis are maintaining that cloud ser that the cybersecurity posture, that cloud service, OK? So we, we, uh, we get uh monthly scans from the cloud service providers and, and, and. As you can imagine, the amount of data coming from some of the hyperscale providers is, uh, is, is pretty large, uh, to say the least, but, um, we work very closely with the cloud server providers to make sure that they address all the, all the vulnerabilities that are identified in their scans and so it's an ongoing process. The, the initial authorization is just the first piece. It's, it's the continuous monitoring that happens up until, you know, the cloud service goes away. Uh, that's, that's important as well. And on top of the continuous monitoring, we also do annual assessments. So we look at a, uh, a subset of the, uh, of what, what are considered critical controls, um, every, you know, roughly, uh, 33% of the, of the controls every year. So, uh, ostensibly every 3 years, they're getting a full look, uh, uh, a full reassessment again, just based on, on the annual assessment and the continuous monitoring process. So, Again, that was a little piece that I, that I didn't mention in, in my brief, but I think it's very important to understand that we just don't authorize a cloud and forget it and you know, we don't authorize a cloud and then send it out into the wild to be used by the federal government. We, we, we have a very robust uh method to, to maintain, to ensure that the cloud service providers are maintaining their cybersecurity posture. Thank you Ed and thank you Brian for this clarification. This is very helpful. Now I return to uh Canutt Lipo. Canutt is our lead, uh, procurement specialist and, uh, with extensive, uh, multi-regional experience of IT ICT procurement. So Kut, uh, uh, since, uh, in addition to the cybersecurity, there's a procurement angle to the cloud service, uh, provision as we learned from Brian, how, uh, our, uh, new procurement framework, uh, could accommodate, uh, similar procurement approaches for our, for our cloud-based services. Yeah, thank you. Thank you very much, from, um, and thank you very much to Ed for having me in this meeting. And here we go again with procurement. So we have seen a lot of issues with ICT procurement, not only in bank projects, but, uh, even beyond. Uh, thanks also to Brian for a very interesting presentation, uh, and to Ed for his comments and contributions. As I understand it, FedRAM is a sort of a Framework agreement or a standing list, which is open to, uh, US companies, to US cloud service providers, uh, which are validated against certain, uh, standards and become part of a catalog that then, uh, agencies, public agencies can be, uh, benefit from. Um, what I would like to try is really to link the procurement angle of cloud computing maybe to three major procurement principles. One is integrity. The other one is value for money, and the third one is sustainability. Uh, quickly, let me start with integrity. Um, Public procurement is about following legislation, compliance with legislation, and we all know that, uh, change in legislation is a very slow undertaking. On the other hand, uh, ICT is developing at very high speed with short innovation cycles, and a change in legislation cannot keep up with that speed, not at all. So I think therefore it's very important that the procurement legislation is technology neutral and also provides the flexibility to accommodate the public acquisition of new technologies such as cloud computing. And this is very important. The good news is that we see this in most of the countries in the world, across the world, and we also see it in our own procurement regulations, uh, which is technology neutral and also provides a lot of flexibility to accommodate. The purchase of innovative technologies. So that's not really an issue, um, as I would say. And, uh, we have seen examples, for example, um, non-consulting services. I would categorize a cloud computing as a non-consulting service. And in the past, we have seen, for example, as part of uh capital investments, ICT capital investments, we have seen recurrent costs during the warranty and post-warranty period up to 6 years or even longer. And this was also based on a sort of service level agreement uh for a defined number of years. So, uh, the World Bank framework is Available to accommodate procurement of cloud computing. And it also provides adequate, uh, procurement approaches, everything from, let's say, framework agreement to competitive dialogue for complex projects or contracts. Now, the framework agreement is very interesting. Um, cloud computing as a new technology. I think that what we have seen from FedRAM, um, a framework agreement would, would be maybe a good fit for purpose in this instance to do a procurement, uh, for cloud computing at a national level. But I will talk a little bit about the implication when we talk about open international procurement which, uh, the bank, uh, is in favor of. Um, what is perhaps missing from the World Bank right now, and this is acknowledged as part of the procurement framework is specific guidance, templates, and also examples where cloud computing solutions have been procured successfully. Now, public procurement is also about value for money, and I I think without any doubt, one of the best benefit of cloud computing is cost savings. Um, it's just a matter of calculation to find out the break-even if you go for cloud computing versus, uh, capital ICT investments into data centers. Um, there are other benefits of cloud computing. If we talk about value for money, and this is scalability, flexibility, service quality, and so on and so forth. And what I learned recently, and this is a very interesting point, security. So there is an opinion out there and, and maybe we can hear a little bit more on that from Brian and also from Ed, um, that argues that uh cloud computing offers better security, data security than as if you're hosted on-premise in your own data center. Because this is exactly the point. Security concerns, in addition to data sovereignty and privacy issues, are considered among the highest risks by governments when they embark on moving data into the cloud. Data are very sensitive, as we could hear, and so there is a certain resistance of. Countries to open up even to international cloud providers and we have seen examples like in Estonia who keep the cloud computing all on their own territory and I know also about the existence of a discussion in the world right now of a large contract, multi-million contract for cloud computing. Uh, where the borrower would like to keep the data on national territory, mainly for security reasons and data sovereignty and privacy issues. So we, we are faced with that and um If, if, if that means that they don't want to hire international cloud providers and there are big cloud providers, in particular when there are no cloud providers in a, in a smaller country, um, on the one hand, you can understand if it comes to data security, sovereignty, and privacy issues. On the other hand, you consider this as a limited competition. So you limit the competition to national. Territory keeping the data in national territory, not benefiting from the best value that maybe an international cloud service provider could offer to you. And there are maybe additional reasons besides security and data privacy and sovereignty which may contribute to the motivation to keep data hosting in the country which is related to the promotion of the local industry. And this links to the sustainability, where the sustainability aspect comes in, uh, as part of the value for money concept as a, as a measure. principle of public procurement today. So I think as you can see there are several aspects which can play a role, and I think that any requirements that may point towards a limited competition, for example, you have to meet national security certifications, you have to keep data on national territory, or you would like to promote local providers. I don't think we, we have a black and white approach here. I think we have to assess this on a case by case basis as part of the procurement strategy in our projects, and we have to take into consideration several aspects like doing a market analysis of available local cloud service providers, um, doing, uh, an analysis of existing. strategies in the government. We could hear, uh, from Ed at the beginning and the introduction, a whole of government approach to cloud computing. We have accepted previously in large ICT contracts, the fact that, for example, certain brands have to be purchased as part of the contract for a database when there was an existing. In the national strategy which promoted exactly, uh, uh, this, uh, brand. So if there is in a country an existing cloud computing strategy, um, certification program and things similar to FedRAM in the US, this also should be taken into consideration when we make a decision whether we can fund this or not. Um, existing standards, security standards, and also the sustainability of policies play a role. In summary, I think the procurement of cloud solutions can be accommodated in bank-funded projects. That's not an issue really. We haven't seen too many examples, but glad to be part of this discussion and to see how this develops and to contribute to moving this agenda forward. Um, what I can say is that typically, uh, the procurement family in the bank would put the preference on open competition. Uh, open international competition approaches, um, and that should be based on relevant international standards, and the question would be, are there any international standards in the context of cloud computing that could be part of, uh, the bidding document if you go out to the market as a requirement. Um, if it comes to limitation of the competition, keeping, uh, the list of data providers of, of, um, of cloud, uh, uh, solution providers within the country, or at least allowing international companies, but then making it a requirement to keep the data within national territory, uh, this, this has to be carefully assessed. As I said before, against this criteria, um, before making a decision in favor or against it. Um, I know that further guidance will be developed with our procurement colleagues in OPCS and in the global procurement unit, and, uh, I also know that there are more learning sessions, uh, almost every week on the subject matter. This is a very good dialogue and, um, And I think this is a great agenda. So from the procurement point of view, I'm happy to answer any more questions that might come up and perhaps from Brian to hear whether this has been an issue or whether there is certain comfort, you know, to keep the. A certified list of cloud providers within the US or maybe there are international providers as well, but given the fact that most of the cloud providers, the large ones, they are from the US anyway, that might not be really a problem. So thank you very much for the opportunity, and we'll stay tuned and be available for questions. Thanks. So, I'd, I'd like to interject about the data sovereignty in the geolocation of, of, of data. I can understand where that's an issue and, and obviously that's the top of mind for the US government as well. And through those uh NIS standards, um, we have, um, we, there are parameters that, that our joint authorization board has prescribed to keep, uh, certain types of data within the US, US territories or geo geolocations that have US jurisdictions. So it's possible to do with the creation of uh parameters uh on how those security controls, those new security controls are implemented, um, to, to maintain that. Um, there are also other ways to do it, um, uh, you know, the, the, the contract is a very powerful tool, um, with a cloud service provider and to say, OK, show me how you're meeting the standard, show me that you're keeping, how you're keeping. My data in within my borders, um, you know, show me how you have, you're giving either logical or physical separation, uh, if it's in a community cloud, a public cloud, um, you know, how you're, how you're maintaining that logical or physical separation between my data and their data. So, uh, you know, what, what you mentioned nude is a very valuable tool and that contract can be used and formulated to, you know, to kind of push. You know, to get that last mile in and, and have the, have the provider meet the standards that you want to meet without having it necessarily written within the, within the cybersecurity standards. Thank you Brian. I think this is a question that is coming from the audience as well about the data sovereignty. There are a lot of comments on data sovereignty. So you mentioned that within the US government data sovereignty, uh, you can, uh, you can have cloud service providers offshore, right? Most of, most of the companies are US based. Um, however, we understand that, you know, the way the internet works is that data is going to travel, you know, uh, trans, uh, across the globe. Um, however, uh, the focus is mostly on where the data resides. And so we understand that for, to get from point A to point B, um, it, it will have to traverse outside US territory, but if the, if the data is being held in a data center, um, that data center needs to be in the US, uh, on US territory or in geolocations where there's US jurisdiction, and that, and that is strictly for, uh, our high-impact data. OK. Um, the, the joint authorization board has been more lenient with regards to that, uh, with moderate and low, um, because we consider low data is publicly accessible, publicly releasable, um, You know, we're not so concerned about that, but for the high impact data, uh, the, the Joint Authorization Board has, has wanted to look at that a little more closely and make sure that controls are in place, uh, to, to make sure that that data stays within, within, you know, the US ostensibly. And, but also we have, we have encryption requirements too for data in transit. So, it's not just out there blowing in the wind, uh, so to speak, or just live on the wire, it's, uh, there, there are encryption standards for, for data in transit that, that cloud service providers have to meet as well. Thank you. I hope Luda, Luda had this question actually in the chat box, so I hope that question is answered from, uh, uh, on the data sovereignty. Uh, yes, thank you very much, very, very useful, very much appreciated. Yeah, thank you. So, given I think there are so many questions, uh, I will ask Nathanny to extend the session by 10 minutes. So the next question is from Tracy. Uh, do you want to come in or? Thanks I'll ask you very quickly. I just wanted to know what life looked like before FedRAM was set up. So how did you reach that point? Uh, what was needed in terms of coordination or leadership, uh, to get to this kind of whole of government approach? Thanks. No problem. That's a great question. Uh, unfortunately, that sort of predates me, but, um, having some of the history on the program, again, as is explained in the video previously, um, you know, we saw the advent of cloud computing. Um, and so we, there, there was, uh, an observation that across the government that, you know, with 10 different federal agencies, each agency would have, had its own standard to basically uh assess the same product over and over and over again. And so, Uh, you know, not only, not only does the Fed, so there's resource constraints or resource costs per agency of having to do that, but it's also a burden on the cloud service provider. So if you think about it from an economic model, the more things, if, if the cloud service provider has to spend money to do something over and over and over again, that cost is not. They're not gonna absorb that cost that's gonna get passed back to the customer and then this customer is the, uh, is the federal government. So, um, part of the motivation is, you know, ensuring that we have a, uh, uh, uh, you know, a, a common framework, a common, uh, standard for cloud service providers to meet with regards to cybersecurity, but also that that's acceptable across the agencies and again, the cloud service providers are happy about that because they only have to do it once, um. You know, OK, so it's a little bit of a shock to them because they don't get to charge 10 different agencies to do the same thing. But, you know, looking at it from a government perspective, we've, we've eliminated a lot of the, uh, duplicative effort uh by agency to agency to agency to, to basically assess the same, same product. Uh, did, did that answer your question or do you need me to go into a little more depth? No, that's good. I, I mean I think that the efficiency argument is very well made by your presentation and the follow-up, um I guess from our client's point of view, That's often not enough of a driver and that there's institutional challenges for getting to collaboration with a different agency which requires leadership from somebody sort of rising above that. So I'm just wondering with the Department of Defense in the lead here or Homeland Security or the, you know, something, something from the presidency. So that Sorry, I went the wrong way. So that, that kind of, that still exists as a, as an issue, is a challenge we have in the federal government because as I mentioned, our federal law requires agencies to, each agency to authorize the cloud product. Um, so, depending on the difference of risk appetite of an authorizing official, we have, we have an individual in the agencies who work, who function as an authorizing official. So they're the one who signs the paper that says we're giving, we're, we're, we're giving, granting the authority to operate for this particular system, OK? It has a FedRAM authorization. We've looked at the package and, and we're, you know, they're the ones who are accepting risk on behalf of their agency and so the issue is. The risk appetite is different across the agencies and, you know, it's, it's a three-fold thing. It's, it's personality-driven, it's, um, you know, my data, my, I think my data or my, my data may be a little more sensitive, so I'm gonna require, um, one of the things that we see frequently is additional controls that, that cloud service providers are asked to do uh is about having US personnel, um, access, being able to access the environment. Um. At all on the data that the agency is putting into the cloud and and the risk appetite of the organization, so we haven't been able to necessarily standardize that across the federal government, but the starting point is that when you look at the FedRAM package, we know up to a certain point that that, that has addressed the majority of the issues. Thanks, bye. Uh, OK. Our next question is from Hain Von Lee. Uh, this is regarding interoperability. Hain, you are around to ask the question, or you want me to? Uh, hi, Crown. Can you hear me? Um, thanks, Brian and thanks foram. Um, so my question was more, um, on interoperability of the system and, um, if, um, if there's a service that needs to pull, uh, multiple sources of data across different agencies, um, what were some of the measures that you had to introduce to make sure, um, the interoperability between data sharing and the system, um, is guaranteed, um. Yeah, thank you. My apologies, I. Can you hear me? Yeah, yeah, OK, so that the, the data interoperability is not really a responsibility of FedRAM. That is something that the agencies need to work out on the agency level. We are making sure that the environment in which they're put, in which they put their data is secure. Yeah. OK, the next question is from Fasil. Uh, and this is regarding uh institutional readiness. Vessel. So I can ask a question. Sure, uh, OK, please, uh, so that, uh, how did you, uh, promote the institutional readiness for cloud adoption? Again, that, you know, providing an environment that, that meets a specific standard with regards to cybersecurity, uh, sort of allays a lot of fears, um, that once, once agencies see exactly the standard that, that cloud, that cloud service offerings that have FedRAM authorizations meet, um, they understand that it's not just, uh, the initialment but it's the continuous monitoring, um. And also our continuous monitoring data is available to the agency customers and anybody who is thinking about a uh uh a US federal agency who's thinking about using that cloud can, can request that data, so they can see the, the, the, the performance record of the cloud service and so, Knowing the standard and being able to see their performance has allayed a lot of fears on, uh, you know, just walking in, just throwing their data into a cloud, um, you know, they, they have to be very judicious with what they're doing, uh, with their resources, obviously, and, and they want to make sure that their data is protected. And so again, it's that FedRAM authorization and understanding their, their track record which, uh, provides a level of confidence to agencies that, that allows them to do that. Thank you. And now Rajendra Singh, you wanted to ask a question directly. Thank you very much. Uh, thank you, Koram. Uh, my point was, uh, and thank you, Brian, for this excellent presentation. This is in continuation of the questions asked by, by my previous colleagues. See, when we look at it from our client country's point of view, I mean, look, in the United States, you have NITA, you have excellent partnership within the government and outside government. What I'm wondering is, uh, like, uh, in our client countries, where to pick up the threat. You know, everything is in a complete mess, and they are investing a lot of money on creating their own data centers. Sometimes different ministries, they have their own data centers. So where exactly we as an institution, we should make the intervention. And say that, uh, you know, this is like uh our procurement colleague, he mentioned about, uh, you know, value for money and all those things. Uh, so, how do we start it in our project? Uh, what is your suggestion? Thank you. So, uh, I, I, I'll take a swing at this. This is kind of outside my wheelhouse, but we had a, a concerted effort, uh, in the US government to, um, move to cloud. Um, there was, uh, executive leadership at the department, at, at the agency heads, at the agency leadership level, um, to move to cloud, um. And recognizing that the inefficiencies of each agency having their own data centers, you know, we understand that that's appropriate because there are some, there, there may be some instances and some use cases where an agency having their own data centers completely appropriate, um. But also on those, on those things that can be leveraged, um, because there are a lot of capital expenses, uh, dealing with, with data centers, um, and, and the management of the, of the systems inside, um. You know, it, there was a push to, uh, to cloud from uh executive leadership in, in the US, uh, from the agency level and, and on down. I believe President Obama was, uh, pushed, uh, cloud computing quite a bit during his administration as well. So it's, it's, it's moving towards, and, and it's understanding too that the cloud provides capabilities that are, that are expensive to build and maintain. Um, and there, the elasticity and the availability of the cloud is there when you need it and, and it can go away when you don't. Um, I think that is a, that is huge, is a huge selling point for the cloud. Um, it allows, uh, it allows, uh, it has allowed our government agencies to innovate because of the computing power that, uh, that it, that the cloud brings, um, that they would, it would, it would just be again too very expensive to replicate. Uh, in their own data center, but, you know, there's, uh, and, and we saw it with, uh, with the advent, not the advent, that's a poor word, but with the, with the onset of COVID, um, we saw that the, uh, the cloud computing capability is critical for supporting a, a, a, uh, dispersed workforce, um, not just in the, on the commercial side, but on the, uh, on the government side as well. Uh, we've, and, and we've seen our numbers of reuse of authorized cloud services, uh, basically take off exponentially, uh, since April of last year, as you can imagine, because, you know, all the cloud systems that were required are, are being used or wanting to be used by, uh, federal agencies to support, uh, uh, a new work paradigm that they weren't necessarily used to doing. Uh, a similar question to Rajendra is my question. Uh, sorry, I'm jumping the queue because this is relevant to Rajendra's question. This is regarding enforcement. Uh, is there any agency in the US government, uh, they can use their own budget to build their own data center or continue using their own data center, or there is some enforcement mechanism for Fed ramp. So, yeah, I, I, you know, depending on agency policy and depending on what they're doing with their data and what type of data it is, I'm sure they could. Um, we, we do again have enforcement, we have, uh, Enforcement mechanisms within FedRAM. So if the I, I mentioned continuous monitoring and the vulnerability addressing the vulnerabilities that, that are, that are reported each month, if a cloud service provider isn't doing what they're doing or what they're supposed to be doing, we can, we can remove them from the marketplace. We can, the joint authorization board has the, has the power basically to revoke their authorization and, and that's not a good look for a commercial cloud service who wants to keep doing business with the federal government, um. So there's other methods um that can be done. Newt mentioned the, uh, the contracting if, if there, if there are clauses put in the contract about performance SLAs and the like, um, those are, those are methods of enforcement as well. Um, so there's something built in, but we don't have a central agency who says, you know, you're going to do this. I, it's, we, we manage that for commercial cloud services with FedRAM authorizations at the PMO. The next question is from Atul. This is regarding, uh, given the data breaches of the federal systems, are there specific advantages of using cloud, uh, compared to the traditional data centers? I think you have answered this question, but just briefly recap. Yeah, um, Uh, Kuram, if I may, uh, yeah, uh, Brian, Brian, uh, thank you for a very informative presentation. I mean, uh, my question basically was, you know, one has heard about, uh, data breaches of federal systems, uh, in the last few years, more often than earlier. I mean, uh, just before the elections, around the 2016 elections. Uh, so I was wondering, I mean, uh, one, has it, has this, uh, more regular breach. of, uh, uh, you know, data, federal data systems got anything to do with the move from, uh, using traditional data centers to using cloud service providers and from a data protection perspective, um, are there specific advantages of using, uh, CSPs, uh, vis a vis the traditional data centers? I mean, are they related, uh, in a way, uh, in terms of security systems? Thanks. So I'm not sure. I, I, I don't have any statistics or data on, you know, which, which one is safer. I know that um, Basically the standard in which we, we, we hold the commercial cloud service providers to, um, there's they have reporting requirements to us, um. Yeah, that's, that's a hard question to answer. Um, again, not having any side by side comparison between, you know, on-prem, you know, agency data centers and, and the cloud, um, you know, the. Each agency though, it, it, the security in the cloud, especially with commercial cloud, it's a shared responsibility model. OK. And so, you know, we're, we're very, the cloud service providers are, are very adamant about, and, and they're very good about meeting the standard that we, that we prescribe, um, but again, it's a, it's a shared, it's a shared system. So, you know, each agency who uses that cloud, each customer has to make sure that they're doing the right thing, that, that they're configuring their instance properly. Properly and things of that nature. Um, and so it's a, it, it's a more holistic effort with regards to security in, in, in, you know, creating that defense in depth because the agencies are doing what they're supposed to be doing. The, uh, the cloud service providers are doing what they're supposed to be doing, and, and there's, and, and there's validation along that, you know, we have, we do that with our continuous monitoring and the agencies do that internally as well. So again, I'm not sure if I can, if that really answered your question or if I've provided the right. You know, insight to that, but, um, you know, maybe I can take another stab at it if, if, if that didn't work. No, it's fine. I mean, I was just wondering whether accountability gets diffused then. I mean, uh, rather than having a single point of accountability onto like a departmental data center, whether this cloud thing kind of dilutes accountability and responsibility. But thank you. I think that was helpful. Mhm. Next question is from Anat Levin. Uh, this is regarding matrix. Anat. Yes, thanks very much. Um, my question is, is whether there are metrics that measure the effectiveness of this, uh, FedRAM framework, um, in preventing the hacks, breaches, and attacks that we see so often in the news right now. So, where my question is coming from is, of course, we see cybersecurity attacks. and breaches even against cybersecurity firms and even against major cybersecurity agencies, uh, so obviously the attacks are increasing in terms of their, um, um, and at the same time we see that in our client countries, uh, you know, they wouldn't, uh, they wouldn't be prepared at this stage to sort of take on something to the level of depth and intricacy. As, as you're proposing with FedRAM, but it would be interesting to see how effective is the Fed, the FedRAM governance framework right now in preventing hacks, um, and is there a way for, for us at the World Bank to look at maybe a FedRAM light or sort of a FedRAM phase one, that might be appropriate for some of our client countries. Thank you. No, that's a great question. Uh, we don't have any specific metrics on how effective it is for, um. Preventing hacks, um, again, it, it's, we have, because of the shared security model, we have different sets of eyes looking at it. So when we, when, when there's anomalous activity that's noted, um, or that's discovered within the, within the boundary, so when, when a cloud service. Uh, when a cloud service provider comes to FedRAM, they bring a specific cloud service offering, and the way we authorize it is we look at the specific security boundary in which they're, which they're proposing, and then we do all the assessment and the testing, uh, against that proposed boundary, um, but we don't have any statistics on how effective it is in preventing hacks. It's a Uh, the analogy I've heard before with regard to, uh, uh, football is being a goalie. Um, it's, it's trying to make sure that they don't get in, um, and then mitigating as soon as possible, uh, with as less, with as little impact, um, should they get in. Um, we know that there are advanced persistent threats and we try and tailor controls to address those, um, but in terms of metrics, we don't have anything specific. Um, with regards to adoption, we've had Other governments um that have uh been interested in the FEDRAM program. Also, um, there is, uh, amongst the 50 states, uh, within the US there's a, a consortium of chief information officers who are looking at the FedRAMP standard to apply towards cloud services that are being used by state governments as well. Thank you. And last question to Brian before I turn to Canutt. Cute, you have two questions, but, uh, uh, that will be the last. Uh, so last question is on international standards on cloud security. Uh, are there any international regulations requirements? This is from Sadiq Assad. Uh, requirements that could be used during procurement. Any international standards or regulations? Uh, from our perspective, uh, you know, we, we adhere to the NIST 853 standards, uh, that are published by the US government, and, um, Because our, our work is strictly across, uh, the US federal agencies, um, we haven't had to address international standards. Um, we know that cloud service providers though, they have, uh, multiple, uh, multiple regimes in which they have to comply with because they do business transnationally. Um, but with regards to what the US government is looking for, we, we, uh, hang our, our proverbial hat on those NIST, uh, security controls. Yeah, I can answer this question. There is ISO 27,017 international standard, uh, applicable together with the Security international standard 27,001 and 2. So together these three standards are the international standard that can be used. So, uh, Kut, uh, uh, Tracy had a question regarding, uh, procurement, and Tracy, maybe you can ask directly. I think it has answered the question actually so it seems that this has not been taken up widely in our projects. Thanks. OK. Yeah, uh, Kuram, I try to, I answered in, in the chat function to everyone, but maybe, maybe I can, I can say a few words on what Brian just mentioned and, and you as well on the availability of standards. Uh, this, this has been always the discussion, and it will be, of course, in the future if it comes to procurement under bank funded projects, um. The preferred option is if there were international standards like you mentioned, the ISO 27,000, I think 17 for security in combination with one and two. So if this is given and sufficient, and this depends also from the technical team of course in a project to assess this, this is the preferred option. If it comes to national standards, we always have been struggling with the fact. Does it exclude providers or not? And this goes back to the need of doing a market analysis. Is there a sufficient market available in the country to do that, so which would maybe not so interested for international. Providers, so this really has been an issue, will be an issue, but always I point out during the project procurement strategy for development in the preparation phase, those are the areas that have to be addressed and solutions have to be found. Thanks. Uh, thank you very much for a very rich conversation. And now I will request Tracy Lane, our practice manager, for her closing remarks. Thank you, Karam. And let me also just start by thanking our presenter, Brian and colleague Janelle, uh, for this, uh, fantastic presentation and, uh, really very clear and informative for us. Thanks to to Ed and Not because they, their comments really stimulated a great debate and discussion this morning. For me, it's clear that cloud computing has great opportunities. As an economist, you had me at your efficiency gains for private sector and federal savings. So this, this US model really is something I think we can all learn from. But it's also clear from our discussion and debate that our clients still have some way to go before they're ready to take on board these kind of opportunities. Um, I really think the fact that the bank is, is thinking about this, that we're looking at the technical issues, institutional issues, and procurement issues is going to prove to be of, uh, help and support to clients on the, to our clients directly, but also to our child's teams on the ground, and maybe I can just take this opportunity to flag upcoming work. That Kara is going to lead in partnership with uh with Ed and DD and in procurement to provide that guidance in a in a way that uh builds off this this BBL today and you should expect to see that by the end of the fiscal year. I hope I'm not raising too many eyebrows from the team by saying that. So really, um, this, uh, is a new area. For us, great opportunities but also risks and clearly our clients are not yet where the US is. So it's good for us to explore both the US but other examples of how this is being taken forward to look at what might be some of the steps and the map towards this kind of institutional setup that we've we've had explained to us today. Um, really want to thank everybody, but also acknowledge, um, Ed and his time that he spent with us today and the fact that we had, um, more than 50 of you, um, here this morning. So really thanks to all of you for, for giving us your time and attention to this topic. Thanks a lot everybody and enjoy the rest of your day. Very much. Thank you.
showAllTranscripts
no
duration
PT1H17M8S
scene7File
worldbank/Cloud_Computing_Navigating_Procurement_and_Cybersecurity_Challenges
scene7Domain
https://worldbank.scene7.com/
scene7FileAvs
worldbank/Cloud_Computing_Navigating_Procurement_and_Cybersecurity_Challenges-AVS
title
Cloud Computing Navigating Procurement and Cybersecurity Challenges
description
Cloud_Computing_Navigating_Procurement_and_Cybersecurity_Challenges
showTimestampAndTranscript
yes
col-xs-12
col-sm-12
col-md-3
col-lg-3
col-xs-12
col-sm-12
col-md-7
col-lg-7
  • add-style
  • lp-body-content
Cloud Computing has huge potential to save costs, strengthen cybersecurity, improve resilience, and promote local jobs. The objective of this BBL is to demystify cloud computing and its potential for developing countries. Recorded January 28, 2021.
col-xs-12
col-sm-12
col-md-2
col-lg-2