In 2011, the White House announced its Cloud First initiative, mandating that federal IT decision-makers initially consider cloud-based services when seeking to add a new IT system or solution. Since then, the federal government has made significant strides toward broad cloud adoption. In many ways, agencies have even managed to surpass the private sector when it comes to cloud deployments.
The success of FedRAMP is perhaps the single biggest signal of this trend. As the General Service Administration recently reported, more than four-fifths of all federal cloud implementations went through FedRAMP during the six-month period observed. This is an encouraging figure, but it’s also true that there are still obstacles standing in the way of an optimized, government-wide embrace of cloud computing.
FedRAMP and the cloud
The purpose of the FedRAMP program is to vet cloud services for security concerns, ensuring that they meet the base-level requirements for most federal agencies. This is an essential process for overall government cloud adoption, as security remains the leading concern for most decision-makers when it comes to cloud implementations. This is particularly pronounced in the public sector, where the potential consequences of a data breach can be exceedingly damaging. Many, perhaps most, federal agencies do not have the talent and resources in-house to thoroughly vet potential cloud services to ensure they comply with federal guidelines, but FedRAMP largely reduces this requirement.
The GSA’s latest report makes it clear that FedRAMP is fulfilling this purpose. According to the study, 82 percent of the more than 1,400 federal cloud deployments examined received security clearance from FedRAMP. This figure is due to a number of factors, including the increase in the number of FedRAMP-certified cloud service providers by 41 percent to 38 total over the six-month period analyzed, Fierce Government IT reported.
Not only has FedRAMP increased federal agencies’ ability to embrace cloud solutions confidently, according to the GSA, but it has also saved $70 million per year by eliminating independent security assessment which would prove redundant, the source noted.
Room for improvement
Yet as positive as these results are, it is important to note that the federal government still has a ways to go in the realm of cloud adoption. Writing for The Washington Post, Aaron Levie recently emphasized that numerous government systems remain quite out of date. In many cases, agencies have favored short-term fixes over large-scale upgrades – such as moving data and operations into cloud environments. This has left agencies vulnerable to cyberattacks. The writer pointed to the recent breach of approximately 18 million federal records at the Office of Personnel Management as a leading example.
According to Levie, the older a piece of legacy IT is, the better the chances that cyberattackers will know or discover a way of exploiting its vulnerabilities. Embracing cloud services can therefore not only improve efficiency and productivity, but also shore up agencies’ cybersecurity capabilities. However, to enjoy these benefits, federal decision-makers will need to look for managed services providers that can offer the experience and expertise needed to ensure a smooth, save transition to cloud-based IT.