00:03 The,
00:04 uh,
00:05 should we start at I see at.
00:08 Yes,
00:09 uh,
00:09 we can start.
00:10 Kan,
00:10 thanks.
00:11 Yeah,
00:12 so the objective of today's BBL is to demystify cloud
00:16 computing and facilitate mainstreaming of it in our client countries.
00:22 Uh,
00:22 the agenda is opening opening remarks from Ed.
00:27 They will be our main presentation.
00:30 Then deflections from our two experts followed by a question and answer session,
00:34 and then closing remarks from Tracy.
00:37 The event is open to external participation from our clients.
00:41 Uh,
00:42 now I invite Ed to please,
00:44 uh,
00:44 open the meeting
00:46 with his opening remarks.
00:48 OK,
00:49 uh,
00:49 thank you very much,
00:50 uh,
00:51 Khuram,
00:51 and,
00:52 uh,
00:52 good morning,
00:52 good afternoon,
00:53 good evening to everyone,
00:55 depending on where you are connecting from.
00:57 Uh,
00:58 I want to,
00:59 uh,
00:59 welcome all of you to,
01:01 uh,
01:01 today's BBL,
01:03 uh,
01:03 a special welcome to our guest speaker today,
01:06 Brian Conrad,
01:07 uh,
01:08 who is the acting director of Fed RAM.
01:11 And program manager for cybersecurity
01:16 GSA
01:17 in the US government.
01:19 I would also like to welcome our discussions today,
01:22 uh,
01:23 Ken,
01:24 uh,
01:25 who is lead procurement specialist,
01:27 and also
01:29 Ed Usu,
01:29 who is,
01:30 um,
01:31 the senior advisor at digital development.
01:34 Uh,
01:34 many thanks also to Khuram and the Govtech team for organizing,
01:38 uh,
01:39 this,
01:39 uh,
01:39 event,
01:40 uh,
01:40 which is focusing on a very important topic.
01:43 As many of you
01:45 know,
01:46 advanced digital economies are mainstreaming
01:49 disruptive technologies like cloud computing.
01:53 These governments are harnessing the
01:56 transformational potential of cloud computing
01:59 to reduce costs,
02:00 strengthen security,
02:02 and accelerate innovation.
02:05 COVID-19 has provided further push to
02:09 cloud computing.
02:11 Client governments can also take advantage of cloud computing.
02:17 And
02:18 they have various concerns,
02:20 but given some of their concerns about sensitivity of data and sovereign
02:25 issues,
02:26 they can adopt different options.
02:28 And for instance,
02:30 they can use public cloud for non sensitive data
02:33 while retaining the sensitive data on premises or private cloud.
02:38 But there is really no reason why our client countries cannot use
02:42 cloud computing and take advantage of the opportunities that this offers.
02:47 In FCV settings,
02:49 saving costs,
02:50 improving access,
02:51 and ensuring business continuity
02:54 uh
02:55 make
02:56 uh
02:57 even more compelling business case for cloud
03:01 adoption.
03:02 However,
03:04 as I was alluding to,
03:06 mainstreaming cloud computing in our client countries is facing challenges.
03:11 On the one hand,
03:13 most client governments cite cybersecurity and data sovereignty as key risks.
03:20 On the other hand,
03:21 our task teams and staff do not
03:24 have adequate guidance on how to navigate cybersecurity
03:28 and cloud procurement arrangements.
03:33 Our traditional procurement models,
03:35 for instance,
03:36 are focused on capital goods.
03:39 Uh,
03:40 services,
03:41 uh,
03:42 in contrast to the subscription-based cloud services model.
03:48 There is,
03:48 however,
03:50 high demand from our clients and task teams
03:53 for guidance and knowledge sharing on cloud computing.
03:58 Given its relevance to digital transformation
04:01 and the development agenda
04:04 that we are working on.
04:07 To respond to this demand.
04:09 I want to thank the Govtech team for organizing this BBL,
04:16 which is really focused on learning lessons from the US government.
04:20 The US government is a pioneer
04:23 in mainstreaming cloud computing in government.
04:27 The Gov tech team is also preparing technical guidance
04:31 on cybersecurity assessment framework for cloud computing applicable to
04:36 cloud procurement,
04:37 and that will be made available shortly.
04:40 I will encourage our task teams to support
04:44 clients in their adoption of cloud computing.
04:47 And in this regard,
04:49 the governance,
04:50 global practice and digital development
04:54 GP
04:56 recent joint work in supporting Palestinian Authority on cloud
05:02 readiness assessment is a good example
05:05 that we could adopt going forward,
05:07 so.
05:09 Uh,
05:09 to support our clients better on this agenda,
05:12 I want to emphasize three,
05:14 key
05:15 points.
05:16 One is we need to promote a whole of government approach to procurement
05:20 rather than agency-specific piecemeal approaches,
05:24 OK.
05:24 Especially when we are talking about this,
05:26 uh,
05:26 cloud computing,
05:29 uh,
05:29 promote structured
05:31 empirical cybersecurity
05:35 assessment framework.
05:37 As we learn,
05:38 I mean,
05:38 as we will learn today from uh the various uh uh speakers,
05:42 uh,
05:42 to facilitate a risk mitigation approach
05:46 rather than the current approach of risk avoidance.
05:51 We also need to collaborate,
05:53 that is
05:54 with the digital development and other GPs to support our clients
06:00 and to share knowledge and concrete examples on cloud
06:04 computing so as to promote
06:06 and facilitate the adoption and use of cloud computing.
06:11 I really look forward to a very interesting session today.
06:15 Uh,
06:15 and again I want to thank the guest speaker and uh our discussions
06:19 and also the team that organized this.
06:22 So thank you so much,
06:23 uh,
06:23 back to you,
06:23 Korra.
06:26 Thank you,
06:27 Ed.
06:27 And now I will invite our guest speaker,
06:29 Brian Conrad
06:31 to share,
06:31 uh,
06:32 his presentation,
06:34 uh,
06:34 based on US experience.
06:36 Brian,
06:36 over to you.
07:01 Hi,
07:01 this is Janelle Thels.
07:02 I support Brian at the Feder PMO.
07:04 It looks like he might have
07:06 gotten kicked off.
07:08 So if you just wait one moment,
07:09 um,
07:10 he should be.
07:10 I'm here.
07:11 We're here.
07:11 OK,
07:12 I'm here.
07:12 My apologies.
07:14 Um,
07:15 the Webex mute button was very elusive.
07:19 Uh,
07:19 however,
07:20 I was successful in finding it.
07:23 Thank you everyone for having me today.
07:26 Um,
07:27 I am very,
07:28 uh,
07:28 honored and humbled to come and present
07:31 on the US government's
07:33 Federal Risk and Authorization Management Program known as FEDRAMP.
07:38 Um,
07:38 I will have to warn you,
07:39 the US government floats on a sea of acronyms and abbreviations.
07:44 So for such a diverse audience,
07:46 if there's,
07:46 if I say something and just blow past it,
07:49 please,
07:49 uh,
07:50 raise your hand,
07:50 keep me honest,
07:51 and,
07:52 uh,
07:53 because I will,
07:54 I will consider it,
07:55 the,
07:55 I will consider that I've done my job well today,
07:58 um,
07:58 if you leave with a greater understanding of what we're doing,
08:01 OK?
08:03 So let's get started.
08:05 Next slide,
08:06 please.
08:08 This is me,
08:09 um,
08:10 next slide.
08:15 So we're gonna start out with a little Fed ramp overview and,
08:18 and that is uh gonna be with a YouTube video that we had produced.
08:23 So,
08:23 uh,
08:23 sit back and enjoy for a couple of minutes and it will give
08:26 you an overview and then I'll go into detail after the video.
08:36 The Federal Risk and Authorization Management Program,
08:39 FEDRAMP.
08:41 Promotes the adoption of secure cloud services across the US government,
08:45 providing a standardized approach to security
08:47 assessments for cloud service offerings.
08:50 FedRAM creates a partnership between the federal government and industry.
08:54 Together
08:55 we modernize IT infrastructure while protecting federal information.
09:02 Before FedRAM,
09:03 vendors had to meet different security requirements for each federal agency.
09:08 FedRAM eliminates this duplication by providing a common security framework,
09:13 making it possible for agencies and
09:15 cloud service providers to reuse authorizations.
09:18 Agencies review a standardized set of
09:20 security materials against one common baseline.
09:24 A cloud service offering is authorized once and then the
09:27 security package can be used by any federal agency.
09:31 FedRAM's guiding principle is reuse,
09:33 do once,
09:34 use many times.
09:36 This saves money,
09:37 time and effort for both agencies and cloud service providers.
09:53 All right,
09:53 next slide,
09:54 please,
09:54 to know.
09:55 Brian,
09:56 can you open your video,
09:57 please?
09:59 Oh,
09:59 I'm sorry.
10:01 My video,
10:02 video,
10:03 yes,
10:03 thank you so much.
10:05 I have that my video is on.
10:10 Can you not see me?
10:13 Can others see Brian?
10:14 No,
10:14 no,
10:15 we cannot see you.
10:16 Yeah,
10:17 we can see just the presentation.
10:19 But we can see the presentation.
10:21 Maybe you can go ahead.
10:22 Uh,
10:22 yeah,
10:22 that's fine.
10:24 The,
10:24 the.
10:24 The presentation is much more pleasant to look at than I am.
10:27 So,
10:27 um,
10:28 I'll,
10:28 I'll get into this.
10:29 Uh,
10:30 the mission of,
10:31 of the Federal Risk and Authorization Management Program
10:34 is that we promote the adoption of secure cloud
10:37 services across the federal government by the US government
10:40 by providing a standardized approach to security and risk assessment.
10:44 So,
10:45 as the video said,
10:46 you know,
10:47 the idea of behind FedRAM is that we authorize a cloud service once
10:52 and it can be reused across the federal government.
10:54 Next slide,
10:54 please.
10:57 So,
10:58 like anything,
10:58 there is a legal and policy framework uh
11:02 that is the foundation for
11:04 uh the FEDRAM program,
11:05 OK?
11:06 We have in the US the Federal Information Security Modernization Act,
11:11 uh,
11:11 which is a federal law,
11:13 and that requires our,
11:14 our,
11:14 our government agencies to protect federal information systems.
11:18 So,
11:19 uh,
11:19 through FISMA,
11:20 they require NIST,
11:22 our National Institutes of Standards and
11:24 Technology to develop standards and guidelines.
11:28 Uh,
11:28 the Office of Management and Budget,
11:30 uh,
11:31 states that when agencies implement FISMA,
11:34 they must use those standards that were developed by NIST.
11:38 And what FedRAM does is we leverage the NIS standards
11:42 and apply those to cloud services.
11:45 So,
11:46 um,
11:47 that's,
11:47 that's how we create the standardized authorization packages and,
11:51 and we use the,
11:52 the standards developed by the,
11:54 by NIST.
11:55 Um,
11:56 the standards,
11:57 uh,
11:57 that are published by NIST,
11:58 I believe,
11:59 are,
11:59 are publicly accessible,
12:01 um,
12:02 the.
12:04 OM uh Office of Management and Budget circular A 130,
12:08 that's what that A130 is referring to.
12:10 I believe that's publicly accessible as well.
12:12 So if you're interested,
12:13 you can,
12:14 you can download those and,
12:15 and read those and,
12:16 and kind of get an idea
12:17 of what the legal and policy framework for FADRAM is.
12:20 Next slide,
12:21 please.
12:24 So,
12:25 on top of the legal and policy,
12:26 we have a governance uh structure as well.
12:30 So,
12:31 as I mentioned at the top of the diagram,
12:33 the Office of Management and Management and Budget provides oversight.
12:37 Um,
12:37 we do our cross-agency coordination through
12:40 the Chief Information Officer council.
12:43 So each agency,
12:44 uh,
12:45 has a representative on that council.
12:47 And they talk through uh issues pertaining to,
12:50 uh,
12:51 cybersecurity and technology adoption,
12:53 etc.
12:54 And then we have the National Institutes of Standards and Technology,
12:58 NIST,
12:59 uh,
13:00 which,
13:00 uh,
13:01 which,
13:02 uh,
13:02 FISMA requires to,
13:03 uh,
13:05 which FISMA has,
13:07 um,
13:08 Create the standards
13:09 and,
13:09 and the technical specifications.
13:12 And then at the very bottom of the diagram,
13:14 we see our Department of Homeland Security who does the uh
13:17 cybersecurity incident response uh for across the federal government
13:22 and uh the Department of the Defense
13:23 of Defense and the General Services Administration.
13:27 So those three agencies make up the what we call the Joint Authorization Board.
13:32 Uh,
13:32 this will become important to remember,
13:34 uh,
13:35 as I get into in a couple of slides about
13:37 how cloud service providers can get authorized to,
13:40 can,
13:40 can get FEDRAA authorization.
13:42 There's two paths,
13:43 um,
13:44 and one of those is through the,
13:45 the Joint Authorization board,
13:47 and the jab,
13:47 uh,
13:48 that we refer to as the JAB
13:50 is also sort of like our,
13:52 uh,
13:53 uh,
13:53 board of directors.
13:54 They,
13:54 they sign off on policy,
13:56 uh,
13:57 which is applied across the FedRA program as well.
14:02 Next,
14:02 please.
14:06 So in talking about our stakeholders,
14:08 we have the,
14:08 uh,
14:09 starting on the left,
14:10 we have the FedRAM Program Management Office.
14:12 We provide
14:14 all the,
14:15 the unified process for agencies and cloud services to follow,
14:19 uh,
14:19 to get,
14:20 uh,
14:20 to work towards the office.
14:21 Authorization.
14:22 We work with the joint authorization board to prioritize vendors,
14:26 uh,
14:27 to achieve the authorizations.
14:28 We support the cloud service providers and agencies through the process
14:32 and we maintain a secure repository of
14:36 security artifacts.
14:37 Um,
14:38 again,
14:38 we have the,
14:39 uh,
14:39 the
14:40 federal agencies within the government who conduct quality risk assessments.
14:44 Um,
14:45 they deposit ATO documents in our secure repository.
14:49 Uh,
14:49 of course,
14:50 we have our commercial cloud server providers,
14:52 um,
14:53 which provide the documentation
14:55 and,
14:55 and,
14:56 uh,
14:56 a very important part of this process
14:58 is our third-party assessors who maintain independence,
15:02 uh,
15:02 through,
15:03 uh,
15:03 the verification and validation
15:05 that the cloud service providers are actually doing what they're,
15:08 what they say they're doing.
15:10 Um,
15:10 when I have conversations with cloud service providers and,
15:13 and our third-party assessors and,
15:15 and the agency,
15:16 so our stakeholders across the board.
15:18 Um,
15:18 I tell them that protecting,
15:20 you know,
15:21 federal information is a team sport.
15:23 Um,
15:23 we all have our specific parts of the team and we,
15:26 it best works when we do it collaboratively,
15:29 um,
15:29 where we have,
15:30 and,
15:30 and yes,
15:31 the third-party assessors have a job,
15:33 uh,
15:34 to maintain,
15:34 make sure that the cloud service providers are doing what they're doing.
15:38 The Feder PMO has,
15:39 has to make sure that policy and process are being followed,
15:42 but it's all done in concert to,
15:44 again,
15:45 with the end goal of protecting federal information.
15:48 Next slide,
15:48 please.
15:52 So,
15:52 now we're gonna talk a little bit about the impact and you got a little bit of,
15:56 of that in the,
15:57 in the brief.
15:58 So,
15:59 federal security,
16:00 US federal security policy requires all systems to be,
16:03 to be authorized based on risk,
16:05 OK?
16:06 And what FedRAM does is it standardized that process for commercial cloud.
16:11 OK,
16:11 we have a model where we,
16:13 we authorize once so it can be used many times.
16:17 You know,
16:17 doing the security authorization right the first time allows agencies
16:22 to reuse the work and eliminate duplicative efforts.
16:26 So if you Have multiple agencies,
16:28 they don't have to do the same work twice,
16:31 uh,
16:32 as,
16:32 as Ed mentioned,
16:33 as Edward mentioned in the opening,
16:35 using that whole of government approach
16:37 to leverage the work that one agency has done across the,
16:40 across the enterprise,
16:41 so to speak.
16:43 Um,
16:43 with transparency,
16:44 we have increased collaboration.
16:47 We create a community amongst the government and the commercial vendors,
16:50 um,
16:51 that did not exist
16:53 before.
16:53 Um,
16:54 we,
16:55 FedRAM validates the,
16:57 the security authorizations to ensure that.
16:59 That there's uniformity and conformity
17:02 amongst the security packages
17:04 and I mentioned a central,
17:05 centralized repository where agencies can request
17:09 access to those existing security packages
17:11 so that,
17:12 that can expedite their,
17:14 their authorizations.
17:16 Next slide,
17:16 please.
17:20 So looking at the,
17:22 looking at continuing into some of the more detail of the,
17:26 of the FedRAM landscapes,
17:28 presently,
17:29 we have 4 different security baselines
17:32 matched to,
17:32 to risk,
17:33 OK?
17:34 Uh,
17:35 mass,
17:35 uh,
17:35 matched to sensitivity of information.
17:38 When you go and categorize the types of information you want to put in a cloud,
17:42 um,
17:43 we have,
17:44 we have,
17:44 uh,
17:45 documentation for that.
17:46 We have,
17:47 uh,
17:48 federal policy and guidance on how we do that.
17:50 Um,
17:51 it's called the Federal Information Processing Standards,
17:54 and it,
17:55 it basically serves as a guideline for agencies to categorize,
17:59 uh,
18:00 the impact level of their information.
18:02 Is it
18:03 very sensitive?
18:04 Is it high?
18:04 Is it moderate?
18:05 Um,
18:06 is it low,
18:07 publicly accessible,
18:08 publicly releasable information,
18:09 that kind of thing.
18:10 Um,
18:11 I'll have you note that this is not necessarily
18:13 used for intelligence activities or the Department of Defense
18:17 because the FedRAM baseline does not send,
18:19 does not do anything,
18:21 uh,
18:21 with classified information.
18:22 This is
18:23 for,
18:24 uh,
18:25 uh,
18:25 agencies to conduct their business.
18:27 So yes,
18:28 there may be personally,
18:29 personally identifiable information.
18:31 There might be,
18:32 uh,
18:33 personal health information included in some of these
18:36 in the information categorized,
18:38 but
18:39 So agencies would have to pick the cloud service
18:41 that meets their requirements out of those four baselines.
18:45 Presently,
18:45 we have over 211 authorized cloud services in our catalog.
18:50 Uh,
18:50 the 1st 6 years of the program,
18:52 it,
18:53 uh,
18:53 we got to 100,
18:54 but in the last 2 years,
18:56 we've doubled that number.
18:57 Um,
18:58 we have over 2100 agency reuses of authorized systems.
19:02 So I,
19:03 I wanna point this out.
19:04 So
19:05 we talked before about the value of FedRAM being.
19:08 That it can be uh the,
19:09 the cloud service provider is authorized through the cloud service offering
19:13 is authorized once and it can be reused across the government.
19:17 That 21,
19:18 that over 2100,
19:19 uh,
19:20 instances of reuse is,
19:22 is indicative of that because
19:24 that shows,
19:25 uh,
19:26 in resource savings
19:28 what the FedRAM program has been able to bring to the US federal government.
19:32 We have.
19:33 72 participating federal agencies
19:36 and we have over 220 industry partners who are participating.
19:39 And again,
19:40 those industry partners are not just the cloud service providers,
19:43 but they're also the uh third-party assessment organizations as well.
19:49 Program management office is very,
19:51 very,
19:51 uh,
19:51 active.
19:52 We,
19:53 we participate in over 750 annual meetings with agencies
19:57 and vendors and speaking engagements like this one.
20:00 we have over 4400,
20:02 uh,
20:02 followers on Twitter.
20:04 Um,
20:04 we have a listser,
20:05 uh,
20:05 uh,
20:06 basically an email,
20:07 an email list of over 13,000,
20:09 uh,
20:10 stakeholders,
20:11 and we have,
20:12 uh,
20:12 through our,
20:13 our
20:14 email.
20:15 Info at Fed ramp.gov.
20:18 Uh,
20:19 our team,
20:19 uh,
20:20 fields over 33,000 questions a year.
20:23 Um,
20:25 simple things to the most complex,
20:27 and,
20:27 uh,
20:28 and,
20:28 but our team of professionals is,
20:30 is there to handle that.
20:32 Next slide,
20:32 please.
20:37 So,
20:38 when we talk about authorizing,
20:39 we
20:40 authorize the whole cloud stack,
20:42 OK?
20:42 So agencies
20:44 ultimately end up doing an authorization for,
20:47 uh,
20:48 from
20:49 the infrastructure plat platform and software,
20:52 and each of these components plays an important security role.
20:55 So agencies must acknowledge and accept the risk
20:58 associated with their federal information with these environments.
21:02 Um.
21:03 So where this is important is
21:06 if you're an agency and you're going to put your
21:10 into a platform,
21:12 you can leverage.
21:15 Package from that particular platform if it has a FedRAM authorization
21:20 for your,
21:21 for the agency's authority to operate.
21:23 OK,
21:24 as well,
21:25 if,
21:26 if there's a uh SAS provider,
21:28 software is a service provider
21:30 who is going into a FedRAM uh authorized environment,
21:33 they get the leverage.
21:34 The controls from that authorized environment for their security package as well.
21:40 So it's a building,
21:41 sort of a building block approach
21:43 where
21:43 FedRAM-authorized cloud services at the platform
21:46 and infrastructure level can be leveraged
21:49 up the stack.
21:57 As I mentioned a couple of slides ago,
21:58 we have 4 specific baselines
22:01 according to the security impact.
22:04 Agencies.
22:05 So looking from,
22:06 from tailored up to high,
22:10 um,
22:10 those are specific,
22:11 the tailored,
22:12 uh,
22:12 low impact software as a service is specific to
22:16 those software as a service which have a,
22:18 a low-risk limited use case.
22:20 Uh,
22:21 for instance,
22:21 uh,
22:22 uh,
22:22 if your agency wants to run a survey for 30 days,
22:26 um,
22:26 the low impact,
22:28 uh,
22:29 software as a service authorization may.
22:32 Tailored authorization may be suitable for that.
22:34 Uh,
22:35 for low,
22:36 it's,
22:36 uh,
22:38 uh,
22:38 uh,
22:38 125 controls,
22:41 uh,
22:41 versus again,
22:42 do not store personally identifiable information.
22:45 Um,
22:46 moving up
22:47 to moderate,
22:47 there's 325 controls,
22:50 and this is where we find the majority of
22:52 the cloud systems that we have in our catalog.
22:54 80% of those,
22:55 uh,
22:56 of those are at the moderate level,
22:58 and then,
22:59 uh,
22:59 the high impact systems,
23:01 um.
23:02 Obviously,
23:03 are,
23:03 are more sensitive information if you think about law enforcement,
23:06 uh,
23:07 data,
23:08 uh,
23:08 immigration data,
23:10 other personally identifiable information or,
23:12 or
23:13 PHI,
23:14 uh,
23:14 personal health information that you might find that in,
23:17 in a high-impact
23:19 system.
23:19 So what it means by controls on the very first bullet point,
23:23 those are the,
23:24 that's the number of uh controls from the NIST
23:27 uh standard,
23:28 the 8,
23:30 special publication 853,
23:33 uh,
23:33 currently revision 4,
23:36 that those baselines are built off of.
23:45 And a little more about
23:47 lines,
23:47 uh.
23:49 So,
23:50 there's different,
23:51 there's 7,
23:51 there's 17 uh different control family
23:55 uh within the NIST baselines and,
23:57 and so,
23:59 for example,
24:00 there are,
24:01 uh,
24:02 there's a family around encryption,
24:04 uh,
24:04 which helps ensure that only authorized parties,
24:07 uh,
24:08 uh,
24:08 can decode the information.
24:10 There's identification and and authentication.
24:14 Um,
24:14 we have controls built into the baselines
24:16 about vulnerability scanning and malicious code,
24:19 uh,
24:20 boundary protection systems and interconnections,
24:23 as well as configuration management.
24:28 Next
24:32 So we
24:34 About the base
24:35 of FedRAM,
24:36 uh,
24:36 the legal and the policy framework
24:39 associated in the,
24:40 in the,
24:41 uh,
24:41 you know,
24:42 what we use for the controls to,
24:44 uh,
24:44 adjudicate cloud service providers.
24:46 I'm gonna go into a little bit of the mechanics on how we do it,
24:49 OK?
24:50 So,
24:51 in FedRAM,
24:51 we have 3 different designations that appear on our marketplace,
24:55 and,
24:55 uh,
24:55 those digital,
24:56 I,
24:56 I believe a link to that marketplace
24:58 is included in the,
25:00 in the later part of this presentation which you can go and look at.
25:03 So we have a FedRAM ready,
25:05 FedRAM in process and FedRAM authorized.
25:08 And this,
25:08 these designations are,
25:10 are,
25:11 were designed to
25:13 allow
25:14 uh potential agency customers to see
25:17 the,
25:17 the current state of a cloud service provider in the process,
25:21 OK?
25:22 With FedRAM ready,
25:24 um,
25:24 this is sort of a pre-check that we do
25:26 to make sure that the cloud service offering can make it through authorization.
25:30 We look at things like,
25:32 um,
25:32 what external services are being.
25:35 Uh,
25:36 the,
25:36 uh,
25:37 implementation of encryption,
25:39 uh,
25:39 those sorts of things,
25:40 just kind of as a,
25:41 as a pre-check before we do the authorization,
25:43 the actual,
25:44 uh,
25:45 initial assessment.
25:46 Um,
25:47 usually,
25:48 um,
25:48 once there is a kickoff meeting either with
25:51 an agency sponsor or the joint authorization board,
25:54 um,
25:55 that's when a cloud service provider will be listed as in process.
25:58 That means they are actively going through the initial assessment.
26:01 And their security package and their,
26:03 all their artifacts are being examined by
26:06 information systems security officers
26:08 um from,
26:09 from
26:10 the agency or the joint authorization board
26:13 and that's really the deep dive into the security package to make sure
26:17 that uh the cloud service offering is.
26:19 Meeting all the requirements that we have with FedRAM
26:22 and when all that's said and done,
26:24 um,
26:25 if everything is,
26:26 is
26:27 judged to be satisfactory and,
26:29 and,
26:29 uh,
26:30 and it meets our standard,
26:32 that's when the,
26:33 the cloud service offering will have a FedRAM authorized,
26:36 uh,
26:37 entry in the,
26:38 in the marketplace
26:39 and that shows that,
26:40 uh.
26:42 It allows sort of like a one-stop shop for agencies to come
26:45 and look at all those cloud service providers that are authorized
26:49 to see if,
26:49 if there's one in the marketplace that fits,
26:52 fits their needs.
26:53 Sorry about that,
26:54 Jana.
26:54 I didn't mean to trip you up there.
26:57 Next slide,
26:58 please.
26:59 So
27:01 You've heard me mention the Joint
27:02 Authorization Board and the agency authorization.
27:05 So in FEDRAAM,
27:06 we have two discrete paths to authorization.
27:09 So,
27:09 with the Joint Authorization Board,
27:11 this,
27:12 the JAB is the primary governance and decision-making body for the FEDRAM program.
27:16 It consists of the,
27:17 uh,
27:18 Chief Information Officers from the Department of Defense,
27:21 Department of Homeland Security,
27:22 and General Services Administration.
27:24 And they strictly review the cloud service
27:26 providers packages for applic for acceptable risk posture
27:30 using our standardized baselines.
27:32 Uh,
27:33 what's unique about this is the Joint Authorization board issues a provisional
27:38 authorization to operate.
27:40 Because
27:41 the collection of those three CIOs cannot accept risk on behalf of the government,
27:46 um,
27:46 or be on behalf of any other agency.
27:49 So each agency
27:50 who wants to leverage that package,
27:53 to leverage,
27:54 use that cloud service that has a job authorization.
27:57 We have the,
27:58 we have the package,
27:59 will have a uh
28:00 a a understanding of the cybersecurity posture
28:04 and,
28:04 and
28:05 of,
28:05 of that particular
28:07 cloud service and then they have to by US federal law,
28:11 they have to uh sign off what we call an authority to operate.
28:15 Again,
28:16 the idea is
28:17 the amount of work that they have to do is
28:19 greatly reduced because the cloud service already has that FedRAM
28:24 authorization or Jab provisional authorization.
28:27 As well,
28:28 the,
28:28 uh,
28:29 a,
28:29 any federal agency within the US government
28:32 can sponsor a FedRAM authorization as well.
28:34 So,
28:35 the onus is on the agency to conduct the review along with a third-party assessor,
28:41 um,
28:42 to make sure that the package conforms to FEDRAAM standards.
28:45 And so once that is complete,
28:47 the package comes over to FedRAM,
28:49 to the PMO.
28:50 We sign off on the completeness,
28:52 we do a check on critical controls and such
28:55 to make sure they're implemented
28:57 and they get a,
28:58 they'll be posted on the,
28:59 uh,
29:00 on the marketplace as FedRAM authorized
29:02 and the agency will sign off an,
29:04 an authority to operate or an ATO
29:06 uh for that.
29:09 OK.
29:13 So I mentioned before the FedRAM Marketplace,
29:16 and this provides a
29:17 database of all cloud services with any of those three
29:21 FedRAM designations whether they're uh ready in process or authorized.
29:25 Um,
29:26 it allows uh
29:28 it.
29:29 To look for third-party assessment organizations,
29:32 we have a,
29:33 uh,
29:33 just like we have a,
29:34 uh,
29:34 a standard
29:36 policy to authorize cloud services,
29:39 we have,
29:39 uh,
29:40 a program to manage the,
29:41 the third-party assessors who do the verification and validation
29:45 of the cloud service providers.
29:47 There's certain standards they need to meet,
29:49 uh,
29:49 in order to be accepted as FedRAMP 3 PAOs,
29:52 um,
29:53 third-party assessors,
29:54 and,
29:55 um.
29:56 We maintain uh
29:58 uh visibility on their performance as well.
30:01 So if,
30:01 if,
30:02 uh,
30:02 cloud service providers have a,
30:04 uh,
30:05 are,
30:05 are having an issue addressing vulnerabilities or anything,
30:08 you know,
30:08 we have an escalation.
30:10 Make sure that they continue to meet the,
30:13 meet our standards.
30:14 The same goes for the third-party assessors as well because we realize
30:18 the importance of that third party,
30:20 uh,
30:20 assessor to
30:21 validate the,
30:23 the cybersecurity posture and,
30:24 and
30:25 validate the fact that the cloud service providers are doing
30:27 what they tell us that they're supposed to be doing.
30:30 Next slide,
30:30 please.
30:33 I,
30:34 that's all my prepared material and I am,
30:36 I'm more than,
30:37 more than happy and prepared to take on questions from this esteemed audience.
30:44 Uh,
30:44 thank you very much,
30:45 Brian.
30:45 Thank you.
30:46 This is excellent.
30:47 And now I turn to our discussions.
30:50 Uh,
30:50 first I will ask,
30:51 uh,
30:52 Ed Sue,
30:53 uh,
30:53 senior adviser digital development,
30:56 uh,
30:56 to share with us his reflections
30:59 on how we can mainstream cloud computing
31:02 in our operations and in the client governments,
31:05 uh,
31:06 learning some of the lessons from the US experience.
31:08 Ed,
31:09 over to you.
31:11 Great,
31:11 thanks so much and uh thanks for inviting us and,
31:14 and I just wanna echo the comments before that the
31:17 governance GP and digital development are working very closely together on,
31:20 on uh several initiatives in this area
31:22 and we hope to continue that
31:24 partnership,
31:24 uh,
31:25 particularly in cloud computing and,
31:26 uh,
31:26 and in cybersecurity.
31:28 Um,
31:28 just wanna make a quick,
31:29 some comments first on cybersecurity broadly and then coming down,
31:33 back down to cloud.
31:35 Um,
31:35 we have been looking at cybersecurity.
31:38 Mostly from an
31:39 ecosystem perspective,
31:41 from a national perspective,
31:42 and have been
31:43 working with countries to do assess
31:45 where did,
31:46 where does a country stand,
31:47 uh,
31:47 in terms of their cybersecurity maturity,
31:50 um,
31:50 and now we're actually working on tools to bring that down
31:53 to a sectoral and project level and start to assess cybersecurity,
31:56 um,
31:57 from a sectoral level,
31:58 but again,
31:58 it's,
31:58 it's also looking at a network.
32:00 And looking at uh where is the data coming from,
32:03 who is using it,
32:04 who is producing it,
32:05 and where are all the cybersecurity vulnerabilities
32:07 as the data is being produced or consumed
32:09 along many different nodes or uh along the network.
32:13 Um,
32:13 so that being said,
32:14 I think that this is obviously a very important aspect of
32:19 improving cybersecurity in general,
32:21 you know,
32:21 I think that
32:22 it's,
32:23 it's almost a,
32:24 a,
32:25 a no-brainer that,
32:26 you know,
32:27 as,
32:27 as our clients can leverage
32:29 cloud and,
32:30 and
32:31 the commercial data,
32:32 data providers,
32:33 data storage providers much better,
32:35 this is going to improve cybersecurity
32:37 of the data that they store given the options that they have.
32:41 So I think this is uh
32:42 something that,
32:43 you know,
32:43 we'd be very,
32:44 you know,
32:45 we,
32:45 we need to do,
32:46 uh,
32:46 much more of,
32:47 we'd be interested to hear a bit more around,
32:49 you know,
32:49 how do you think about,
32:50 you know,
32:51 from,
32:51 from Brian,
32:51 how do you think about cybersecurity outside of,
32:54 outside of just,
32:55 you know,
32:55 just putting data on the cloud,
32:57 but of,
32:57 of as data's moving in and out,
32:59 and,
32:59 you know,
33:00 how can we also look at it from an ecosystem perspective.
33:03 Coming down to the cloud,
33:04 uh,
33:04 you know,
33:05 DD,
33:05 we're also working on a global data and cloud infrastructure study
33:08 that looks at broadly first enabling environment around how,
33:12 you know,
33:12 how does private sector
33:14 look at data infrastructure within our client countries,
33:16 how can we catalyze more investment,
33:17 and then looking very specifically at this issue like you were saying,
33:20 Karam,
33:20 how can we mobilize and mainstream more
33:23 use of.
33:24 Cloud among our,
33:25 uh,
33:25 among our projects,
33:27 a couple of things we're gonna do within this,
33:29 uh,
33:29 you know,
33:30 this study is look at,
33:31 you know,
33:31 what are we doing within World Bank projects today,
33:34 and I think that
33:35 trying to benchmark what what is happening and
33:37 the little that we've done so far we've seen there's many,
33:40 many obstacles,
33:41 uh,
33:42 that,
33:42 that our clients are facing.
33:44 Um,
33:45 and cybersecurity is just,
33:47 is one of them is not being able to accurately assess,
33:49 so I think this tool is very helpful.
33:51 We,
33:51 we definitely need to extend this tool to other areas
33:54 of other barriers of why our clients are not using cloud.
33:57 Um,
33:58 so one thing we want to do is look at sort of uh,
34:00 uh,
34:00 take a holistic cost benefit analysis of cloud,
34:03 looking at the financial benefits,
34:04 um,
34:05 uh,
34:06 comparing one-time cost versus recurring costs and maintenance costs,
34:09 looking at the economic benefits of which cybersecurity is one of them.
34:12 But there's also a lot of benefits around data modernization,
34:16 forms of IT operations,
34:17 looking at other indirect impacts when the government adopts cloud.
34:20 How does that catalyze other adoption of cloud,
34:23 and also the social aspects of how does cloud enable
34:26 improved government services.
34:28 So it would be great to kind of
34:29 Understand this model and,
34:30 and I,
34:31 you know,
34:31 like,
34:32 like I think was mentioned earlier,
34:33 a whole government approach,
34:35 we need to do this for cybersecurity,
34:36 but the government needs to also
34:38 kind of give guidance on all these other financial,
34:41 economic,
34:42 social benefits
34:43 and help agencies also,
34:44 uh,
34:44 also across that.
34:46 Um,
34:46 and
34:47 perhaps a reflection back that,
34:49 you know,
34:49 from our standpoint,
34:50 we see this as incredibly important,
34:52 as incredibly
34:53 uh useful way,
34:55 um.
34:56 Uh,
34:56 to,
34:57 um,
34:58 to,
34:58 to manage some of the cybersecurity risks,
35:00 um,
35:00 but you know,
35:01 one thing that you,
35:01 you had in your presentation was,
35:03 you know,
35:03 when you,
35:04 when you looked at
35:05 the,
35:06 uh,
35:06 the number of cloud providers you managed to authorize 211
35:10 within the US,
35:11 that,
35:11 that's quite a large number of,
35:13 of,
35:13 of providers who are able to meet your standards.
35:16 And you know,
35:17 within our client countries,
35:18 if we went through,
35:19 if our clients went through this exercise,
35:21 how many would they actually be able to
35:22 identify that meet these standards other than the top
35:26 5 or 6 global providers that we're all aware of?
35:28 Is that,
35:29 you know,
35:29 will this simply push our clients towards really
35:32 using the,
35:33 the,
35:33 the,
35:33 the hyper scales.
35:35 And,
35:35 and,
35:36 you know,
35:36 um,
35:36 so I kinda wanna,
35:37 we'd love to have some reflection on,
35:39 on,
35:39 on that from you as well,
35:40 Brian.
35:40 But again,
35:41 thank you so much.
35:41 I think this is a model for our clients,
35:44 not just for cybersecurity,
35:45 but we wanna use this model and look at all the other aspects of cloud adoption
35:49 that,
35:49 that we can standardize and,
35:50 and,
35:50 and help,
35:51 uh,
35:51 and help mainstream this across our operations.
35:53 So,
35:53 thank you so much.
35:55 Thank you.
35:55 Uh,
35:56 you know,
35:56 one of,
35:56 one of the things that I noticed that was,
35:58 uh,
35:58 that I didn't cover in,
35:59 in my presentation was,
36:01 you know,
36:02 we talked all about the initial assessment,
36:04 but,
36:05 uh,
36:05 in,
36:05 in our FedRAM requirements,
36:07 we have a very,
36:08 very strict,
36:09 uh,
36:09 continuous monitoring program
36:11 and
36:13 Requirements we have,
36:15 we,
36:15 we,
36:16 we make sure that the cloud service providers on a monthly
36:19 basis are maintaining that cloud ser that the cybersecurity posture,
36:22 that cloud service,
36:23 OK?
36:24 So we,
36:24 we,
36:25 uh,
36:25 we get uh
36:26 monthly scans from the cloud service providers and,
36:28 and,
36:29 and.
36:29 As you can imagine,
36:30 the amount of data coming from some of the hyperscale providers
36:33 is,
36:33 uh,
36:34 is,
36:34 is pretty large,
36:36 uh,
36:36 to say the least,
36:37 but,
36:37 um,
36:38 we work very closely with the cloud server providers
36:40 to make sure that they address all the,
36:42 all the vulnerabilities that are identified in their scans
36:46 and so it's an ongoing process.
36:47 The,
36:48 the initial authorization is just the first piece.
36:50 It's,
36:51 it's the continuous monitoring that happens up until,
36:54 you know,
36:54 the cloud service goes away.
36:56 Uh,
36:56 that's,
36:57 that's important as well.
36:58 And on top of the continuous monitoring,
36:59 we also do annual assessments.
37:01 So we look at a,
37:02 uh,
37:02 a subset of the,
37:03 uh,
37:04 of what,
37:04 what are considered critical controls,
37:07 um,
37:07 every,
37:08 you know,
37:09 roughly,
37:09 uh,
37:09 33% of the,
37:11 of the controls every year.
37:12 So,
37:13 uh,
37:13 ostensibly every 3 years,
37:15 they're getting a full look,
37:17 uh,
37:17 uh,
37:17 a full reassessment again,
37:19 just based on,
37:20 on the annual assessment and the continuous monitoring process.
37:22 So,
37:23 Again,
37:23 that was a little piece that I,
37:24 that I didn't mention in,
37:26 in my brief,
37:26 but I think it's very important to understand
37:29 that we just don't authorize a cloud and forget it and you know,
37:31 we don't authorize a cloud and then send it out into the wild
37:34 to be used by the federal government.
37:36 We,
37:36 we,
37:36 we have a very robust
37:38 uh
37:39 method to,
37:40 to maintain,
37:41 to ensure that the cloud service
37:42 providers are maintaining their cybersecurity posture.
37:47 Thank you Ed and thank you Brian for this clarification.
37:50 This is very helpful.
37:52 Now I return to uh Canutt Lipo.
37:56 Canutt is our lead,
37:57 uh,
37:57 procurement specialist and,
37:59 uh,
37:59 with extensive,
38:00 uh,
38:01 multi-regional experience of IT ICT procurement.
38:05 So Kut,
38:05 uh,
38:06 uh,
38:07 since,
38:07 uh,
38:08 in addition to the cybersecurity,
38:09 there's a procurement angle to the cloud service,
38:12 uh,
38:12 provision
38:13 as we learned from Brian,
38:16 how,
38:16 uh,
38:17 our,
38:17 uh,
38:17 new procurement framework,
38:19 uh,
38:19 could accommodate,
38:20 uh,
38:21 similar procurement approaches for our,
38:22 for our cloud-based services.
38:27 Yeah,
38:27 thank you.
38:28 Thank you very much,
38:29 from,
38:29 um,
38:30 and thank you very much to Ed for having me in this meeting.
38:33 And here we go again with procurement.
38:35 So
38:36 we have seen a lot of issues with ICT procurement,
38:39 not only in bank projects,
38:40 but,
38:40 uh,
38:41 even beyond.
38:42 Uh,
38:42 thanks also to Brian for a very interesting presentation,
38:46 uh,
38:46 and to Ed for his comments and contributions.
38:49 As I understand it,
38:50 FedRAM is a sort of a Framework agreement
38:53 or a standing list,
38:55 which is open to,
38:56 uh,
38:56 US companies,
38:57 to US cloud service providers,
39:00 uh,
39:00 which are validated against certain,
39:02 uh,
39:03 standards and become part of a catalog that then,
39:06 uh,
39:07 agencies,
39:07 public agencies can be,
39:09 uh,
39:09 benefit from.
39:11 Um,
39:12 what I would like to try is really to link the procurement angle
39:16 of cloud computing maybe to three major procurement principles.
39:19 One is integrity.
39:21 The other one is value for money,
39:23 and the third one is sustainability.
39:25 Uh,
39:25 quickly,
39:26 let me start with integrity.
39:28 Um,
39:28 Public procurement is about following legislation,
39:30 compliance with legislation,
39:33 and we all know that,
39:34 uh,
39:34 change in legislation is a very slow undertaking.
39:39 On the other hand,
39:40 uh,
39:40 ICT is developing at very high speed with short innovation cycles,
39:45 and a change in legislation cannot keep up with that speed,
39:48 not at all.
39:49 So I think therefore it's very important
39:51 that the procurement legislation is technology
39:55 neutral
39:56 and also provides the flexibility
39:59 to accommodate
40:00 the public acquisition of new technologies such as cloud computing.
40:04 And this is very important.
40:05 The good news is that we see this
40:07 in most of the countries in the world,
40:09 across the world,
40:10 and we also see it
40:12 in our own procurement regulations,
40:15 uh,
40:15 which is technology neutral
40:17 and also provides a lot of flexibility
40:19 to accommodate.
40:20 The purchase of innovative
40:22 technologies.
40:23 So that's not really an issue,
40:25 um,
40:26 as I would say.
40:27 And,
40:27 uh,
40:28 we have seen examples,
40:29 for example,
40:30 um,
40:31 non-consulting services.
40:32 I would categorize a cloud computing as a non-consulting service.
40:38 And in the past,
40:39 we have seen,
40:40 for example,
40:40 as part of uh capital investments,
40:42 ICT capital investments,
40:44 we have seen recurrent costs during the warranty
40:47 and post-warranty period up to 6 years or even longer.
40:51 And this was also based on a sort of service level agreement
40:54 uh for a defined number of years.
40:57 So,
40:57 uh,
40:58 the World Bank framework
40:59 is Available to accommodate procurement of cloud
41:04 computing.
41:04 And it also provides adequate,
41:06 uh,
41:07 procurement approaches,
41:09 everything from,
41:09 let's say,
41:10 framework agreement to competitive dialogue for complex projects
41:14 or contracts.
41:15 Now,
41:15 the framework agreement is very interesting.
41:19 Um,
41:20 cloud computing as a new technology.
41:22 I think that what we have seen from FedRAM,
41:24 um,
41:25 a framework agreement would,
41:27 would be maybe a good fit for purpose
41:29 in this instance to do a procurement,
41:31 uh,
41:32 for cloud computing
41:33 at a national level.
41:35 But I will talk a little bit about
41:36 the implication when we talk about open international procurement
41:40 which,
41:41 uh,
41:41 the bank,
41:41 uh,
41:42 is in favor of.
41:43 Um,
41:44 what is perhaps missing from the World Bank right now,
41:47 and this is acknowledged as part of
41:50 the procurement framework is specific guidance,
41:52 templates,
41:53 and also examples
41:55 where
41:56 cloud computing solutions have been procured
41:59 successfully.
42:00 Now,
42:00 public procurement is also about value for money,
42:02 and I I think without any doubt,
42:04 one of the
42:05 best benefit of cloud computing is cost savings.
42:09 Um,
42:10 it's just a matter of calculation to find out the break-even
42:13 if you go for cloud computing versus,
42:15 uh,
42:15 capital
42:16 ICT investments
42:18 into data centers.
42:19 Um,
42:20 there are other benefits of cloud computing.
42:23 If we talk about value for money,
42:25 and this is scalability,
42:26 flexibility,
42:27 service quality,
42:28 and so on and so forth.
42:29 And what I learned recently,
42:31 and this is a very interesting point,
42:33 security.
42:35 So there is an opinion out there and,
42:37 and maybe we can hear a little bit more on that from
42:40 Brian and also from Ed,
42:41 um,
42:42 that argues that uh cloud computing offers better security,
42:46 data security
42:48 than as if you're hosted on-premise in your own data center.
42:52 Because
42:52 this is exactly the point.
42:54 Security concerns,
42:55 in addition to data sovereignty and privacy issues,
42:59 are
43:00 considered among the highest risks
43:01 by governments when they
43:04 embark on moving data into the cloud.
43:07 Data are very sensitive,
43:08 as we could hear,
43:10 and so there is a certain resistance of.
43:12 Countries
43:13 to open up even to international cloud providers
43:18 and we have seen examples like in Estonia who
43:20 keep the cloud computing all on their own territory
43:24 and I know also about the existence of a discussion in the world right now
43:30 of a large contract,
43:31 multi-million contract for cloud computing.
43:33 Uh,
43:34 where the borrower would like to keep the data
43:38 on national territory,
43:40 mainly for security reasons and data sovereignty and privacy issues.
43:44 So we,
43:44 we are faced with that
43:46 and um
43:48 If,
43:48 if,
43:48 if that means that they don't want to hire
43:50 international cloud providers and there are big cloud providers,
43:54 in particular when there are no cloud providers in a,
43:57 in a smaller country,
43:58 um,
43:59 on the one hand,
44:00 you can understand
44:01 if it comes to data security,
44:03 sovereignty,
44:03 and privacy issues.
44:05 On the other hand,
44:06 you
44:07 consider this as a limited competition.
44:09 So you limit the competition
44:10 to national.
44:12 Territory keeping the data in national territory,
44:16 not benefiting from the best value
44:18 that maybe an international cloud service provider
44:20 could offer to you.
44:22 And there are maybe additional reasons besides security and data
44:26 privacy and sovereignty
44:28 which may contribute to the motivation to keep data hosting in the country
44:32 which is related to the promotion of the local industry.
44:36 And this links to the sustainability,
44:38 where the sustainability aspect comes in,
44:40 uh,
44:41 as part of the value for money concept as a,
44:43 as a measure.
44:46 principle of public procurement today.
44:48 So I think
44:50 as you can see there are several aspects which can play a role,
44:53 and
44:54 I think that
44:55 any requirements
44:57 that may point towards a limited competition,
45:00 for example,
45:02 you have to meet national security certifications,
45:05 you have to keep data
45:07 on national territory,
45:09 or you would like to promote local providers.
45:12 I don't think we,
45:13 we have a black and white approach here.
45:15 I think we have to assess this on a case by case basis
45:18 as part of the procurement strategy in our projects,
45:21 and we have to take into consideration several aspects like
45:24 doing a market analysis of available local cloud service providers,
45:29 um,
45:30 doing,
45:30 uh,
45:31 an analysis of existing.
45:33 strategies in the government.
45:34 We could hear,
45:35 uh,
45:36 from Ed at the beginning and the introduction,
45:39 a whole of government approach to cloud computing.
45:42 We have accepted previously in large ICT contracts,
45:45 the fact that,
45:46 for example,
45:47 certain brands have to be purchased as part of the contract for a database
45:51 when there was an existing.
45:53 In the national strategy which promoted exactly,
45:57 uh,
45:57 uh,
45:58 this,
45:58 uh,
45:58 brand.
45:59 So if there is in a country an existing
46:02 cloud computing strategy,
46:04 um,
46:04 certification program and things similar to FedRAM in the US,
46:08 this also should be taken into consideration when we make
46:11 a decision whether we can fund this or not.
46:13 Um,
46:14 existing standards,
46:15 security standards,
46:17 and also the sustainability of policies play a role.
46:20 In summary,
46:22 I think the procurement of cloud solutions can be accommodated
46:26 in bank-funded projects.
46:28 That's not an issue really.
46:30 We haven't seen too many examples,
46:31 but glad to be part of this discussion and to see how this develops
46:35 and to contribute to moving this agenda forward.
46:39 Um,
46:40 what I can say is that typically,
46:42 uh,
46:43 the procurement family in the bank would put the preference on open competition.
46:48 Uh,
46:48 open international competition approaches,
46:51 um,
46:52 and that should be based on relevant international standards,
46:54 and the question would be,
46:55 are there any
46:57 international standards in the context of cloud computing
47:00 that could be
47:01 part of,
47:02 uh,
47:02 the bidding document if you go out to the market
47:05 as a requirement.
47:06 Um,
47:07 if it comes to limitation of the competition,
47:10 keeping,
47:10 uh,
47:11 the list of data providers of,
47:13 of,
47:13 um,
47:14 of cloud,
47:15 uh,
47:15 uh,
47:15 solution providers within the country,
47:18 or at least allowing international companies,
47:21 but then making it a requirement
47:23 to keep the data
47:25 within
47:25 national territory,
47:27 uh,
47:27 this,
47:28 this has to be carefully assessed.
47:29 As I said before,
47:30 against this criteria,
47:32 um,
47:33 before making a decision in favor
47:34 or against it.
47:36 Um,
47:36 I know that further guidance will be developed with
47:39 our procurement colleagues in OPCS and in the global
47:42 procurement unit,
47:43 and,
47:44 uh,
47:44 I also know that there are more learning sessions,
47:47 uh,
47:47 almost every week on the subject matter.
47:50 This is a very good dialogue
47:51 and,
47:52 um,
47:53 And I think this is a great agenda.
47:55 So
47:56 from the procurement point of view,
47:57 I'm happy to answer any more questions that might come up
48:00 and perhaps from Brian to hear
48:04 whether this has been an issue
48:06 or whether
48:08 there is certain comfort,
48:09 you know,
48:10 to
48:11 keep
48:11 the.
48:12 A certified list of cloud providers within the US
48:16 or maybe there are international providers as well,
48:18 but given the fact that most of the cloud providers,
48:20 the large ones,
48:21 they are from the US anyway,
48:23 that might not be really a problem.
48:24 So thank you very much for the opportunity,
48:27 and we'll stay tuned and be available for questions.
48:29 Thanks.
48:31 So,
48:31 I'd,
48:31 I'd like to interject about the data sovereignty in the geolocation of,
48:35 of,
48:35 of data.
48:36 I can understand where that's an issue and,
48:37 and obviously that's the top of mind for
48:40 the US government as well.
48:41 And
48:42 through those uh NIS standards,
48:44 um,
48:44 we have,
48:46 um,
48:47 we,
48:47 there are parameters that,
48:49 that our joint authorization board has prescribed to keep,
48:52 uh,
48:53 certain types of data within the US,
48:55 US territories or geo geolocations that have US jurisdictions.
48:59 So it's possible to do with the creation of
49:02 uh parameters uh on how those security controls,
49:06 those new security controls are implemented,
49:08 um,
49:08 to,
49:09 to maintain that.
49:10 Um,
49:11 there are also other ways to do it,
49:13 um,
49:14 uh,
49:14 you know,
49:14 the,
49:15 the,
49:15 the contract is a very powerful tool,
49:17 um,
49:18 with a cloud service provider and to say,
49:21 OK,
49:21 show me how you're meeting the standard,
49:23 show me that you're keeping,
49:24 how you're keeping.
49:26 My data in within my borders,
49:28 um,
49:29 you know,
49:29 show me how
49:30 you have,
49:31 you're giving either logical or physical separation,
49:34 uh,
49:35 if it's in a community cloud,
49:36 a public cloud,
49:37 um,
49:38 you know,
49:38 how you're,
49:39 how you're maintaining that logical or physical
49:40 separation between my data and their data.
49:43 So,
49:44 uh,
49:44 you know,
49:44 what,
49:45 what you mentioned nude is a very valuable tool and that contract can be used
49:49 and formulated to,
49:50 you know,
49:50 to kind of push.
49:52 You know,
49:52 to get that last mile in and,
49:54 and have the,
49:55 have the provider meet the standards that you want to meet
49:58 without having it necessarily written within the,
50:00 within the cybersecurity standards.
50:07 Thank you Brian.
50:08 I think this is a question that is coming
50:09 from the audience as well about the data sovereignty.
50:12 There are a lot of comments on data sovereignty.
50:15 So you mentioned that within the US government data sovereignty,
50:18 uh,
50:19 you can,
50:19 uh,
50:19 you can have cloud service providers offshore,
50:22 right?
50:28 Most of,
50:29 most of the companies are US based.
50:32 Um,
50:32 however,
50:33 we understand that,
50:34 you know,
50:35 the way the internet works
50:37 is that data is going to travel,
50:39 you know,
50:40 uh,
50:41 trans,
50:41 uh,
50:41 across the globe.
50:43 Um,
50:43 however,
50:44 uh,
50:45 the focus is mostly on where the data resides.
50:49 And so we understand that for,
50:51 to get from point A to point B,
50:53 um,
50:54 it,
50:54 it will have to traverse outside US territory,
50:57 but
50:57 if the,
50:58 if the data is being held in a data center,
51:00 um,
51:01 that data center needs to be in the US,
51:04 uh,
51:04 on US territory
51:06 or in geolocations where there's US jurisdiction,
51:08 and that,
51:09 and that is strictly for,
51:11 uh,
51:11 our high-impact data.
51:14 OK.
51:15 Um,
51:16 the,
51:16 the joint authorization board has been more lenient with regards to that,
51:20 uh,
51:20 with moderate and low,
51:22 um,
51:22 because we consider low data is publicly accessible,
51:25 publicly releasable,
51:26 um,
51:27 You know,
51:28 we're not so concerned about that,
51:29 but for the high impact data,
51:31 uh,
51:31 the,
51:31 the Joint Authorization Board has,
51:33 has wanted to look at that a little more
51:35 closely and make sure that controls are in place,
51:37 uh,
51:38 to,
51:38 to make sure that that data stays within,
51:40 within,
51:41 you know,
51:41 the US ostensibly.
51:44 And,
51:45 but
51:45 also we have,
51:46 we have
51:47 encryption requirements too for data in transit.
51:49 So,
51:50 it's not just out there blowing in the wind,
51:52 uh,
51:53 so to speak,
51:53 or just live on the wire,
51:55 it's,
51:55 uh,
51:56 there,
51:56 there are encryption standards for,
51:58 for data in transit that,
51:59 that cloud service providers have to meet as well.
52:03 Thank you.
52:04 I hope Luda,
52:05 Luda had this question actually in the chat box,
52:07 so I hope that question is answered from,
52:09 uh,
52:09 uh,
52:10 on the data sovereignty.
52:11 Uh,
52:12 yes,
52:12 thank you very much,
52:13 very,
52:13 very useful,
52:15 very much appreciated.
52:17 Yeah,
52:17 thank you.
52:18 So,
52:18 given I think there are so many questions,
52:20 uh,
52:20 I will ask Nathanny to extend the session by 10 minutes.
52:24 So the next question is from Tracy.
52:27 Uh,
52:28 do you want to come in or?
52:31 Thanks
52:32 I'll ask you very quickly.
52:34 I just wanted to know what life looked like before FedRAM was set up.
52:38 So how did you reach that point?
52:40 Uh,
52:40 what was needed in terms of coordination or leadership,
52:43 uh,
52:44 to get to this kind of whole of government approach?
52:46 Thanks.
52:48 No problem.
52:48 That's a great question.
52:49 Uh,
52:49 unfortunately,
52:50 that sort of predates me,
52:51 but,
52:52 um,
52:53 having some of the history on the program,
52:55 again,
52:55 as is explained in the video previously,
52:58 um,
52:58 you know,
52:58 we saw the advent of cloud computing.
53:01 Um,
53:01 and so we,
53:03 there,
53:03 there was,
53:04 uh,
53:04 an observation that across the government that,
53:07 you know,
53:07 with 10 different federal agencies,
53:09 each agency would have,
53:11 had its own standard
53:12 to basically uh assess the same product over and over and over again.
53:17 And so,
53:18 Uh,
53:19 you know,
53:19 not only,
53:20 not only does the Fed,
53:21 so
53:22 there's resource constraints or resource costs per agency of having to do that,
53:26 but it's also a burden on the cloud service provider.
53:29 So
53:30 if you think about it from an economic model,
53:32 the more things,
53:33 if,
53:33 if the cloud service provider has to spend money
53:35 to do something over and over and over again,
53:37 that cost is not.
53:38 They're not gonna
53:39 absorb that cost that's gonna get passed back to the customer
53:42 and then this customer is the,
53:44 uh,
53:44 is the federal government.
53:45 So,
53:46 um,
53:46 part of the motivation is,
53:48 you know,
53:48 ensuring that we have a,
53:50 uh,
53:50 uh,
53:51 uh,
53:51 you know,
53:52 a,
53:52 a common framework,
53:53 a common,
53:54 uh,
53:54 standard for cloud service providers to meet with regards to cybersecurity,
53:58 but also that that's acceptable across the agencies and again,
54:01 the cloud service providers are happy about that
54:03 because they only have to do it once,
54:05 um.
54:06 You know,
54:07 OK,
54:07 so it's a little bit of a shock to them because they
54:09 don't get to charge 10 different agencies to do the same thing.
54:13 But,
54:13 you know,
54:14 looking at it from a government perspective,
54:16 we've,
54:16 we've eliminated a lot of the,
54:18 uh,
54:19 duplicative effort uh
54:21 by
54:22 agency to agency to agency to,
54:24 to basically assess the same,
54:26 same product.
54:27 Uh,
54:27 did,
54:27 did that answer your question or do you need me to go into a little more depth?
54:32 No,
54:32 that's good.
54:33 I,
54:33 I mean I think that the efficiency argument is
54:35 very well made by your presentation and the follow-up,
54:38 um I guess from our client's point of view,
54:41 That's often not enough of a driver and that there's institutional
54:46 challenges for getting to collaboration with a
54:49 different agency which requires leadership from somebody
54:52 sort of rising above that.
54:54 So I'm just wondering
54:55 with the Department of Defense in the lead here or Homeland Security or the,
55:00 you know,
55:00 something,
55:01 something from the presidency.
55:04 So that
55:07 Sorry,
55:07 I went the wrong way.
55:08 So that,
55:09 that kind of,
55:10 that still exists as a,
55:11 as an issue,
55:12 is a challenge we have in the federal government because
55:15 as I mentioned,
55:15 our federal law requires agencies to,
55:18 each agency to authorize the cloud product.
55:21 Um,
55:22 so,
55:23 depending on the difference of risk appetite of an authorizing official,
55:27 we have,
55:28 we have an individual in the agencies who work,
55:30 who
55:31 function as an authorizing official.
55:32 So they're the one who signs the paper that says
55:35 we're giving,
55:36 we're,
55:36 we're,
55:36 we're giving,
55:37 granting the authority to operate
55:39 for this particular system,
55:40 OK?
55:41 It has a FedRAM authorization.
55:43 We've looked at the package and,
55:44 and we're,
55:45 you know,
55:46 they're the ones who are accepting risk on behalf of their agency and so the issue is.
55:51 The risk appetite
55:53 is different
55:54 across the agencies and,
55:56 you know,
55:56 it's,
55:57 it's a three-fold thing.
55:58 It's,
55:58 it's personality-driven,
55:59 it's,
56:00 um,
56:01 you know,
56:01 my data,
56:02 my,
56:02 I think my data or my,
56:03 my data may be a little more sensitive,
56:06 so I'm gonna require,
56:08 um,
56:08 one of the things that we see frequently
56:10 is additional controls that,
56:12 that cloud service providers are asked to do uh is about having US personnel,
56:17 um,
56:17 access,
56:18 being able to access the environment.
56:20 Um.
56:22 At all
56:23 on the data that the agency is putting into the cloud
56:26 and
56:26 and the risk appetite of the organization,
56:29 so we haven't been able to necessarily
56:31 standardize that across the federal government,
56:33 but the starting point is
56:35 that when you look at the FedRAM package,
56:37 we know up to a certain point
56:39 that that,
56:40 that has addressed the majority of the issues.
56:45 Thanks,
56:45 bye.
56:48 Uh,
56:48 OK.
56:48 Our next question is from Hain Von Lee.
56:51 Uh,
56:52 this is regarding interoperability.
56:53 Hain,
56:54 you are around to ask the question,
56:55 or you want me to?
56:58 Uh,
56:58 hi,
56:58 Crown.
56:59 Can you hear me?
57:01 Um,
57:02 thanks,
57:02 Brian and thanks foram.
57:03 Um,
57:04 so my question was more,
57:05 um,
57:06 on interoperability of the system and,
57:09 um,
57:09 if,
57:10 um,
57:11 if
57:12 there's a service that needs to pull,
57:14 uh,
57:14 multiple sources of data across different agencies,
57:18 um,
57:20 what were some of the measures that you had to introduce to make sure,
57:24 um,
57:25 the interoperability between data sharing and the system,
57:28 um,
57:28 is guaranteed,
57:30 um.
57:31 Yeah,
57:31 thank you.
57:38 My apologies,
57:39 I.
57:40 Can you hear me?
57:42 Yeah,
57:42 yeah,
57:43 OK,
57:43 so
57:44 that the,
57:44 the data interoperability is not really
57:48 a responsibility of FedRAM.
57:49 That is something that the agencies need to work out on the agency level.
57:54 We are making sure that the environment in which they're put,
57:57 in which they put their data is secure.
58:01 Yeah.
58:03 OK,
58:04 the next question is from Fasil.
58:06 Uh,
58:07 and this is regarding uh institutional readiness.
58:11 Vessel.
58:17 So I can ask a question.
58:19 Sure,
58:19 uh,
58:20 OK,
58:20 please,
58:21 uh,
58:21 so that,
58:22 uh,
58:23 how did you,
58:24 uh,
58:24 promote the institutional readiness
58:27 for cloud adoption?
58:29 Again,
58:30 that,
58:30 you know,
58:31 providing an environment that,
58:33 that meets a specific standard with regards to cybersecurity,
58:36 uh,
58:37 sort of allays a lot of fears,
58:39 um,
58:39 that once,
58:41 once agencies see exactly the standard that,
58:43 that cloud,
58:44 that cloud service offerings that have FedRAM authorizations meet,
58:48 um,
58:48 they understand that it's not just,
58:50 uh,
58:51 the initialment but it's the continuous monitoring,
58:54 um.
58:54 And also our continuous monitoring data is
58:57 available to the agency customers and anybody who
58:59 is thinking about a uh uh a US federal agency who's thinking about using that cloud
59:04 can,
59:04 can request that data,
59:06 so they can see
59:07 the,
59:08 the,
59:08 the,
59:08 the performance record of the cloud service and so,
59:12 Knowing the standard and being able to see their performance
59:16 has allayed a lot of fears on,
59:18 uh,
59:19 you know,
59:19 just walking in,
59:20 just throwing their data into a cloud,
59:22 um,
59:23 you know,
59:23 they,
59:23 they have to be very judicious with what they're doing,
59:26 uh,
59:26 with their resources,
59:27 obviously,
59:28 and,
59:28 and they want to make sure that their data is protected.
59:31 And so again,
59:31 it's that FedRAM authorization and understanding their,
59:34 their track record which,
59:36 uh,
59:36 provides a level of confidence to agencies that,
59:38 that allows them to do that.
59:42 Thank you.
59:43 And now
59:44 Rajendra Singh,
59:45 you wanted to ask a question directly.
59:50 Thank you very much.
59:50 Uh,
59:51 thank you,
59:51 Koram.
59:52 Uh,
59:52 my point was,
59:53 uh,
59:54 and thank you,
59:54 Brian,
59:55 for this excellent presentation.
59:57 This is in continuation of the questions asked by,
1:00:00 by my previous colleagues.
1:00:03 See,
1:00:04 when we look at it from our client country's point of view,
1:00:07 I mean,
1:00:08 look,
1:00:08 in the United States,
1:00:10 you have NITA,
1:00:11 you have excellent partnership within the government and
1:00:15 outside government.
1:00:17 What I'm wondering is,
1:00:18 uh,
1:00:19 like,
1:00:19 uh,
1:00:20 in our client countries,
1:00:21 where to pick up the threat.
1:00:25 You know,
1:00:26 everything is in a complete mess,
1:00:28 and they are investing a lot of money
1:00:31 on creating their own data centers.
1:00:33 Sometimes different ministries,
1:00:35 they have their own
1:00:36 data centers.
1:00:37 So
1:00:38 where exactly we as an institution,
1:00:41 we should make the intervention.
1:00:43 And say that,
1:00:44 uh,
1:00:44 you know,
1:00:45 this is like uh
1:00:46 our procurement colleague,
1:00:47 he mentioned about,
1:00:49 uh,
1:00:49 you know,
1:00:50 value for money and all those things.
1:00:52 Uh,
1:00:53 so,
1:00:53 how do we start it in our project?
1:00:56 Uh,
1:00:56 what is your suggestion?
1:00:57 Thank you.
1:01:00 So,
1:01:02 uh,
1:01:02 I,
1:01:02 I,
1:01:03 I'll take a swing at this.
1:01:04 This is kind of outside my wheelhouse,
1:01:05 but we had a,
1:01:06 a concerted effort,
1:01:08 uh,
1:01:08 in the US government to,
1:01:10 um,
1:01:10 move to cloud.
1:01:12 Um,
1:01:13 there was,
1:01:14 uh,
1:01:14 executive leadership at the department,
1:01:16 at,
1:01:17 at the agency heads,
1:01:18 at the agency leadership level,
1:01:20 um,
1:01:21 to move to cloud,
1:01:22 um.
1:01:24 And recognizing that the inefficiencies of each
1:01:29 agency having their own data centers,
1:01:31 you know,
1:01:32 we understand that that's appropriate because there are some,
1:01:34 there,
1:01:35 there may be some instances and some use cases where
1:01:38 an agency having their own data centers completely appropriate,
1:01:41 um.
1:01:43 But also on those,
1:01:45 on those things that can be leveraged,
1:01:47 um,
1:01:47 because there are a lot of capital expenses,
1:01:49 uh,
1:01:50 dealing with,
1:01:50 with data centers,
1:01:52 um,
1:01:52 and,
1:01:53 and the management of the,
1:01:54 of the systems inside,
1:01:56 um.
1:01:57 You know,
1:01:57 it,
1:01:58 there was a push
1:01:59 to,
1:02:00 uh,
1:02:00 to cloud from uh executive leadership in,
1:02:04 in the US,
1:02:05 uh,
1:02:06 from the agency level and,
1:02:07 and on down.
1:02:08 I believe President Obama was,
1:02:10 uh,
1:02:10 pushed,
1:02:11 uh,
1:02:11 cloud computing quite a bit during his administration as well.
1:02:15 So it's,
1:02:15 it's,
1:02:17 it's
1:02:18 moving towards,
1:02:18 and,
1:02:19 and it's understanding too
1:02:20 that the cloud provides capabilities that are,
1:02:25 that are expensive to build and maintain.
1:02:27 Um,
1:02:27 and there,
1:02:28 the elasticity and the availability of the cloud is there when you need it and,
1:02:33 and it can go away when you don't.
1:02:35 Um,
1:02:35 I think that is a,
1:02:36 that is huge,
1:02:37 is a huge selling point for the cloud.
1:02:39 Um,
1:02:40 it allows,
1:02:41 uh,
1:02:41 it allows,
1:02:42 uh,
1:02:43 it has allowed our government agencies to innovate
1:02:46 because of the computing power that,
1:02:48 uh,
1:02:48 that it,
1:02:49 that the cloud brings,
1:02:50 um,
1:02:51 that they would,
1:02:51 it would,
1:02:52 it would just be again too very expensive to replicate.
1:02:55 Uh,
1:02:55 in their own data center,
1:02:56 but,
1:02:57 you know,
1:02:57 there's,
1:02:58 uh,
1:02:59 and,
1:02:59 and we saw it with,
1:03:00 uh,
1:03:00 with the advent,
1:03:02 not the advent,
1:03:02 that's a poor word,
1:03:03 but with the,
1:03:04 with the onset of COVID,
1:03:06 um,
1:03:07 we saw that the,
1:03:08 uh,
1:03:09 the cloud computing capability is critical
1:03:12 for supporting a,
1:03:13 a,
1:03:13 a,
1:03:14 uh,
1:03:14 dispersed workforce,
1:03:16 um,
1:03:17 not just in the,
1:03:18 on the commercial side,
1:03:19 but on the,
1:03:20 uh,
1:03:20 on the government side as well.
1:03:22 Uh,
1:03:22 we've,
1:03:23 and,
1:03:23 and we've seen our numbers of reuse of authorized cloud services,
1:03:27 uh,
1:03:28 basically take off exponentially,
1:03:30 uh,
1:03:30 since April of last year,
1:03:32 as you can imagine,
1:03:33 because,
1:03:34 you know,
1:03:34 all the
1:03:35 cloud systems that were required are,
1:03:37 are being used or wanting to be used by,
1:03:40 uh,
1:03:40 federal agencies to support,
1:03:42 uh,
1:03:42 uh,
1:03:42 a new work paradigm that they weren't necessarily used to doing.
1:03:48 Uh,
1:03:49 a similar question to Rajendra is my question.
1:03:51 Uh,
1:03:52 sorry,
1:03:52 I'm jumping the queue because this is relevant to Rajendra's question.
1:03:55 This is regarding enforcement.
1:03:57 Uh,
1:03:58 is there any agency in the US government,
1:04:00 uh,
1:04:01 they can use their own budget to build their own
1:04:02 data center or continue using their own data center,
1:04:05 or there is some enforcement mechanism for Fed ramp.
1:04:09 So,
1:04:10 yeah,
1:04:10 I,
1:04:11 I,
1:04:11 you know,
1:04:12 depending on agency policy
1:04:14 and depending on what they're doing with their data
1:04:17 and what type of data it is,
1:04:18 I'm sure they could.
1:04:19 Um,
1:04:20 we,
1:04:20 we do again have enforcement,
1:04:22 we have,
1:04:23 uh,
1:04:24 Enforcement mechanisms within FedRAM.
1:04:26 So if the I,
1:04:27 I mentioned continuous monitoring and the
1:04:29 vulnerability addressing the vulnerabilities that,
1:04:31 that are,
1:04:32 that are reported each month,
1:04:33 if a cloud service provider isn't doing what they're doing
1:04:36 or what they're supposed to be doing,
1:04:37 we can,
1:04:38 we can remove them from the marketplace.
1:04:40 We can,
1:04:41 the joint authorization board has the,
1:04:43 has the power basically to revoke their authorization
1:04:46 and,
1:04:47 and that's not a good look for a commercial cloud service
1:04:49 who wants to keep doing business with the federal government,
1:04:52 um.
1:04:54 So there's other methods
1:04:55 um that can be done.
1:04:57 Newt mentioned the,
1:04:57 uh,
1:04:58 the contracting if,
1:04:59 if there,
1:05:00 if there are clauses put in the contract about performance SLAs
1:05:04 and the like,
1:05:05 um,
1:05:05 those are,
1:05:06 those are methods of enforcement as well.
1:05:08 Um,
1:05:09 so there's something built in,
1:05:10 but we don't have a central agency who says,
1:05:13 you know,
1:05:13 you're going to do this.
1:05:15 I,
1:05:15 it's,
1:05:16 we,
1:05:16 we manage that for commercial cloud services
1:05:19 with FedRAM authorizations at the PMO.
1:05:23 The next question is from Atul.
1:05:25 This is regarding,
1:05:25 uh,
1:05:26 given the data breaches of the federal systems,
1:05:28 are there specific advantages of using cloud,
1:05:32 uh,
1:05:32 compared to the traditional data centers?
1:05:34 I think you have answered this question,
1:05:35 but just briefly recap.
1:05:40 Yeah,
1:05:40 um,
1:05:43 Uh,
1:05:44 Kuram,
1:05:44 if I may,
1:05:45 uh,
1:05:45 yeah,
1:05:46 uh,
1:05:46 Brian,
1:05:47 Brian,
1:05:47 uh,
1:05:47 thank you for a very informative presentation.
1:05:49 I mean,
1:05:49 uh,
1:05:50 my question basically was,
1:05:51 you know,
1:05:51 one has heard about,
1:05:52 uh,
1:05:53 data breaches of federal systems,
1:05:55 uh,
1:05:55 in the last few years,
1:05:57 more often than earlier.
1:05:58 I mean,
1:05:58 uh,
1:05:59 just before the elections,
1:06:00 around the 2016 elections.
1:06:02 Uh,
1:06:03 so I was wondering,
1:06:03 I mean,
1:06:03 uh,
1:06:04 one,
1:06:04 has it,
1:06:05 has this,
1:06:05 uh,
1:06:06 more regular breach.
1:06:07 of,
1:06:08 uh,
1:06:08 uh,
1:06:09 you know,
1:06:09 data,
1:06:10 federal data systems got anything to do with the
1:06:12 move from,
1:06:13 uh,
1:06:14 using traditional data centers to using cloud service providers
1:06:18 and from a data protection perspective,
1:06:20 um,
1:06:21 are there specific advantages of using,
1:06:23 uh,
1:06:24 CSPs,
1:06:24 uh,
1:06:25 vis a vis the traditional data centers?
1:06:26 I mean,
1:06:27 are they related,
1:06:27 uh,
1:06:28 in a way,
1:06:29 uh,
1:06:30 in terms of security systems?
1:06:31 Thanks.
1:06:38 So I'm not sure.
1:06:40 I,
1:06:40 I,
1:06:41 I don't have any statistics or data on,
1:06:44 you know,
1:06:44 which,
1:06:45 which one is safer.
1:06:46 I know
1:06:48 that um,
1:06:51 Basically the standard in which we,
1:06:53 we,
1:06:53 we
1:06:54 hold the commercial cloud service providers to,
1:06:57 um,
1:06:58 there's they have reporting requirements to us,
1:07:01 um.
1:07:03 Yeah,
1:07:03 that's,
1:07:03 that's a hard question to answer.
1:07:05 Um,
1:07:06 again,
1:07:06 not having any side by side comparison between,
1:07:09 you know,
1:07:09 on-prem,
1:07:10 you know,
1:07:10 agency data centers and,
1:07:12 and the cloud,
1:07:13 um,
1:07:14 you know,
1:07:14 the.
1:07:16 Each agency though,
1:07:17 it,
1:07:17 it,
1:07:18 the security in the cloud,
1:07:19 especially with commercial cloud,
1:07:20 it's a shared responsibility model.
1:07:22 OK.
1:07:23 And so,
1:07:25 you know,
1:07:25 we're,
1:07:25 we're very,
1:07:26 the cloud service providers are,
1:07:28 are very adamant about,
1:07:29 and,
1:07:29 and they're very good about meeting the standard that we,
1:07:32 that we prescribe,
1:07:34 um,
1:07:35 but again,
1:07:35 it's a,
1:07:36 it's a shared,
1:07:36 it's a shared system.
1:07:38 So,
1:07:38 you know,
1:07:39 each agency who uses that cloud,
1:07:40 each customer
1:07:42 has to make sure that they're doing the right thing,
1:07:44 that,
1:07:44 that
1:07:45 they're configuring their instance properly.
1:07:46 Properly and things of that nature.
1:07:48 Um,
1:07:49 and so it's a,
1:07:50 it,
1:07:51 it's a more holistic effort with regards to security
1:07:54 in,
1:07:54 in,
1:07:54 in,
1:07:55 you know,
1:07:55 creating that defense in depth because the agencies
1:07:58 are doing what they're supposed to be doing.
1:07:59 The,
1:08:00 uh,
1:08:00 the cloud service providers are doing what they're supposed to be doing,
1:08:03 and,
1:08:03 and there's,
1:08:04 and,
1:08:04 and there's validation along that,
1:08:05 you know,
1:08:06 we have,
1:08:06 we do that with our continuous monitoring and
1:08:08 the agencies do that internally as well.
1:08:11 So again,
1:08:11 I'm not sure if I can,
1:08:13 if that really answered your question or if I've provided the right.
1:08:16 You know,
1:08:16 insight to that,
1:08:17 but,
1:08:18 um,
1:08:19 you know,
1:08:19 maybe I can take another stab at it if,
1:08:21 if,
1:08:21 if that didn't work.
1:08:24 No,
1:08:24 it's fine.
1:08:24 I mean,
1:08:24 I was just wondering whether accountability gets diffused then.
1:08:27 I mean,
1:08:27 uh,
1:08:28 rather than having a single point of
1:08:30 accountability onto like a departmental data center,
1:08:33 whether this cloud thing kind of dilutes accountability and responsibility.
1:08:36 But thank you.
1:08:37 I think that was helpful.
1:08:39 Mhm.
1:08:40 Next question is from Anat Levin.
1:08:42 Uh,
1:08:42 this is regarding matrix.
1:08:43 Anat.
1:08:44 Yes,
1:08:45 thanks very much.
1:08:46 Um,
1:08:46 my question is,
1:08:47 is whether there are metrics that measure the effectiveness of this,
1:08:50 uh,
1:08:51 FedRAM framework,
1:08:52 um,
1:08:52 in preventing the hacks,
1:08:54 breaches,
1:08:54 and attacks that we see so often in the news right now.
1:08:57 So,
1:08:57 where my question is coming from is,
1:08:59 of course,
1:08:59 we see
1:09:00 cybersecurity attacks.
1:09:01 and breaches even against cybersecurity firms and even against
1:09:05 major cybersecurity agencies,
1:09:07 uh,
1:09:08 so obviously the attacks are increasing in terms of their,
1:09:11 um,
1:09:13 um,
1:09:13 and at the same time we see that in our client countries,
1:09:16 uh,
1:09:16 you know,
1:09:17 they wouldn't,
1:09:17 uh,
1:09:17 they wouldn't be prepared at this stage to sort of take on
1:09:21 something to the level of depth and intricacy.
1:09:22 As,
1:09:23 as you're proposing with FedRAM,
1:09:24 but it would be interesting to see how effective is the Fed,
1:09:27 the FedRAM governance framework right now
1:09:30 in preventing hacks,
1:09:32 um,
1:09:33 and is there a way for,
1:09:34 for us at the World Bank to look at maybe a FedRAM light
1:09:38 or sort of a FedRAM phase one,
1:09:41 that might be appropriate for some of our client countries.
1:09:43 Thank you.
1:09:44 No,
1:09:44 that's a great question.
1:09:45 Uh,
1:09:45 we don't have any specific metrics on how effective it is for,
1:09:50 um.
1:09:52 Preventing hacks,
1:09:53 um,
1:09:54 again,
1:09:55 it,
1:09:55 it's,
1:09:56 we have,
1:09:56 because of the shared security model,
1:09:58 we have
1:09:59 different sets of eyes looking at it.
1:10:00 So when we,
1:10:01 when,
1:10:02 when there's anomalous activity that's noted,
1:10:04 um,
1:10:05 or that's discovered within the,
1:10:07 within the boundary,
1:10:08 so when,
1:10:08 when a cloud service.
1:10:09 Uh,
1:10:11 when a cloud service provider comes to FedRAM,
1:10:13 they bring a specific cloud service offering,
1:10:15 and
1:10:16 the way we authorize it is we look
1:10:18 at the specific security boundary in which they're,
1:10:21 which they're proposing,
1:10:22 and then we do all the assessment and the testing,
1:10:25 uh,
1:10:26 against that proposed boundary,
1:10:28 um,
1:10:28 but
1:10:29 we don't have any statistics on how effective it is in preventing hacks.
1:10:33 It's a
1:10:35 Uh,
1:10:35 the analogy I've heard before with regard to,
1:10:38 uh,
1:10:39 uh,
1:10:39 football is being a goalie.
1:10:42 Um,
1:10:42 it's,
1:10:42 it's trying to make sure that they don't get in,
1:10:45 um,
1:10:46 and then mitigating as soon as possible,
1:10:48 uh,
1:10:48 with as less,
1:10:49 with as little impact,
1:10:51 um,
1:10:52 should they get in.
1:10:53 Um,
1:10:54 we know that there are advanced persistent threats and
1:10:57 we try and tailor controls to address those,
1:11:00 um,
1:11:00 but
1:11:01 in terms of metrics,
1:11:02 we don't have anything specific.
1:11:04 Um,
1:11:04 with regards to adoption,
1:11:06 we've had
1:11:07 Other governments
1:11:09 um
1:11:10 that have uh been interested in the FEDRAM program.
1:11:14 Also,
1:11:15 um,
1:11:15 there is,
1:11:16 uh,
1:11:17 amongst the 50 states,
1:11:18 uh,
1:11:18 within the US
1:11:20 there's a,
1:11:20 a consortium of chief information officers
1:11:23 who are looking at the FedRAMP standard to
1:11:26 apply towards cloud services that are being used by state governments as well.
1:11:32 Thank you.
1:11:33 And last question to Brian before I turn to Canutt.
1:11:37 Cute,
1:11:37 you have two questions,
1:11:38 but,
1:11:38 uh,
1:11:39 uh,
1:11:39 that will be the last.
1:11:40 Uh,
1:11:41 so last question is on international standards on cloud security.
1:11:45 Uh,
1:11:45 are there any international regulations requirements?
1:11:47 This is from Sadiq Assad.
1:11:49 Uh,
1:11:49 requirements that could be used during procurement.
1:11:53 Any international standards or regulations?
1:11:59 Uh,
1:11:59 from our perspective,
1:12:00 uh,
1:12:01 you know,
1:12:01 we,
1:12:02 we adhere to the
1:12:03 NIST 853 standards,
1:12:05 uh,
1:12:06 that are published by the US government,
1:12:07 and,
1:12:08 um,
1:12:10 Because
1:12:10 our,
1:12:11 our work is strictly across,
1:12:13 uh,
1:12:13 the US federal agencies,
1:12:15 um,
1:12:15 we haven't had to address international standards.
1:12:18 Um,
1:12:19 we know that cloud service providers though,
1:12:21 they have,
1:12:22 uh,
1:12:22 multiple,
1:12:23 uh,
1:12:24 multiple regimes in which they have to comply with
1:12:27 because they do business transnationally.
1:12:30 Um,
1:12:30 but with regards to what the US government is looking for,
1:12:33 we,
1:12:33 we,
1:12:34 uh,
1:12:34 hang our,
1:12:35 our proverbial hat on those NIST,
1:12:37 uh,
1:12:37 security controls.
1:12:39 Yeah,
1:12:40 I can answer this question.
1:12:41 There is ISO 27,017
1:12:45 international standard,
1:12:46 uh,
1:12:46 applicable together with the Security international standard 27,001 and 2.
1:12:52 So together these three standards are the international standard that can be used.
1:12:57 So,
1:12:57 uh,
1:12:58 Kut,
1:12:58 uh,
1:12:59 uh,
1:12:59 Tracy had a question regarding,
1:13:01 uh,
1:13:01 procurement,
1:13:02 and Tracy,
1:13:03 maybe you can ask
1:13:04 directly.
1:13:11 I think it has answered the question actually so it seems
1:13:13 that this has not been taken up widely in our projects.
1:13:17 Thanks.
1:13:18 OK.
1:13:19 Yeah,
1:13:19 uh,
1:13:19 Kuram,
1:13:19 I try to,
1:13:21 I answered in,
1:13:22 in the chat function to everyone,
1:13:26 but maybe,
1:13:27 maybe I can,
1:13:28 I can say a few words on what Brian just mentioned and,
1:13:30 and you as well on the availability of standards.
1:13:33 Uh,
1:13:33 this,
1:13:34 this has been always the discussion,
1:13:35 and it will be,
1:13:36 of course,
1:13:37 in the future if it comes to procurement under bank funded projects,
1:13:40 um.
1:13:41 The preferred option is if there were international standards like you mentioned,
1:13:45 the ISO 27,000,
1:13:47 I think 17 for security in combination with one and two.
1:13:52 So if this is given and sufficient,
1:13:54 and this depends also from the technical team of course in a project to assess this,
1:14:01 this is the preferred option.
1:14:02 If it comes to national standards,
1:14:04 we always have been struggling with the fact.
1:14:06 Does it exclude providers or not?
1:14:09 And this goes back to the need of doing a market analysis.
1:14:13 Is there a sufficient market available in the country to do that,
1:14:17 so which would maybe
1:14:20 not so interested for international.
1:14:22 Providers,
1:14:23 so this really has been an issue,
1:14:24 will be an issue,
1:14:25 but always I point out
1:14:28 during the project procurement strategy for
1:14:31 development in the preparation phase,
1:14:33 those are the areas that have to be addressed
1:14:36 and solutions have to be found.
1:14:38 Thanks.
1:14:40 Uh,
1:14:40 thank you very much for a very rich conversation.
1:14:43 And now I will request Tracy Lane,
1:14:45 our practice manager,
1:14:46 for her closing remarks.
1:14:48 Thank you,
1:14:49 Karam.
1:14:49 And let me also just start by thanking our presenter,
1:14:52 Brian and colleague Janelle,
1:14:54 uh,
1:14:54 for this,
1:14:55 uh,
1:14:55 fantastic presentation and,
1:14:57 uh,
1:14:58 really very clear and informative for us.
1:15:01 Thanks to to Ed and Not because they,
1:15:04 their comments really stimulated a great debate and discussion this morning.
1:15:08 For me,
1:15:08 it's clear that cloud computing has great opportunities.
1:15:13 As an economist,
1:15:14 you had me at
1:15:16 your efficiency gains for private sector and federal savings.
1:15:19 So
1:15:20 this,
1:15:21 this US model really is something I think we can all
1:15:24 learn from.
1:15:25 But it's also clear from our discussion and debate that our clients still have some
1:15:29 way to go before they're ready to take on board these kind of opportunities.
1:15:34 Um,
1:15:34 I really think the fact that the bank is,
1:15:36 is thinking about this,
1:15:38 that we're looking at the technical issues,
1:15:40 institutional issues,
1:15:41 and procurement issues
1:15:43 is going to prove to be of,
1:15:45 uh,
1:15:45 help and support to clients on the,
1:15:48 to our clients
1:15:49 directly,
1:15:49 but also to our child's teams on the ground,
1:15:51 and maybe I can just take this opportunity to flag
1:15:54 upcoming work.
1:15:56 That Kara is going to lead
1:15:58 in partnership with uh with Ed and DD and in procurement to provide that guidance in a
1:16:04 in a way that uh builds off this this
1:16:07 BBL today and you should expect to see that
1:16:10 by the end of the fiscal year.
1:16:11 I hope I'm not raising too many eyebrows from the team by saying that.
1:16:14 So really,
1:16:15 um,
1:16:16 this,
1:16:16 uh,
1:16:16 is a new area.
1:16:17 For us,
1:16:18 great opportunities but also risks and clearly our
1:16:21 clients are not yet where the US is.
1:16:24 So it's good for us to explore both the US but other examples of how this is being taken
1:16:29 forward to look at what might be some of the
1:16:32 steps and the map towards this kind of institutional setup
1:16:36 that we've we've had explained to us today.
1:16:39 Um,
1:16:40 really want to thank everybody,
1:16:41 but also acknowledge,
1:16:42 um,
1:16:43 Ed and his time that he spent with us today
1:16:45 and the fact that we had,
1:16:47 um,
1:16:47 more than 50 of you,
1:16:49 um,
1:16:49 here this morning.
1:16:50 So really thanks to all of you for,
1:16:51 for giving us your time and attention to this topic.
1:16:54 Thanks a lot everybody and enjoy the rest of your day.
1:17:02 Very much.
1:17:04 Thank you.
- add-style
- lp-body-content