Copyright
Acquiring Editor: Chris Katsaropolous
Development Editor: Meagan White
Project Manager: Mohanambal Natarajan
Designer: Joanne Blank
Syngress is an imprint of Elsevier
225 Wyman Street, Waltham, MA 02451, USA
Copyright 2013 Elsevier, Inc. All rights reserved.
No part of this publication may be reproduced or transmitted in any form or by any means, electronic or mechanical, including photocopying, recording, or any information storage and retrieval system, without permission in writing from the publisher. Details on how to seek permission, further information about the Publishers permissions policies and our arrangements with organizations such as the Copyright Clearance Center and the Copyright Licensing Agency, can be found at our website: www.elsevier.com/permissions.
This book and the individual contributions contained in it are protected under copyright by the Publisher (other than as may be noted herein).
Notices
Knowledge and best practice in this fi eld are constantly changing. As new research and experience broaden our understanding, changes in research methods or professional practices, may become necessary. Practitioners and researchers must always rely on their own experience and knowledge in evaluating and using any information or methods described herein. In using such information or methods they should be mindful of their own safety and the safety of others, including parties for whom they have a professional responsibility.
To the fullest extent of the law, neither the Publisher nor the authors, contributors, or editors, assume any liability for any injury and/or damage to persons or property as a matter of products liability, negligence or otherwise, or from any use or operation of any methods, products, instructions, or ideas contained in the material herein.
Library of Congress Cataloging-in-Publication Data
Metheny, Matthew.
Federal cloud computing : the defi nitive guide for cloud service providers / Matthew MethenyFirst edition.
pages cm
Summary: In recent years cloud computing has emerged as a model for providing IT infrastructure, resources and services that has the potential to drive significant value to organizations through increased IT efficiency, agility and innovation. However, Federal agencies who were early adopters of cloud computing have learned that there are many challenges and risks that must be addressed in order to realize these benefitsProvided by publisher.
Includes bibliographical references and index.
ISBN 978-1-59749-737-4 (pbk.)
1. Cloud computingSecurity measure. 2. Web servicesGovernment policy. I. Title.
QA76.585.M48 2012
004.6782dc23
2012030642
British Library Cataloguing-in-Publication Data
A catalogue record for this book is available from the British Library.
Printed in the United States of America
13 14 15 16 17 10 9 8 7 6 5 4 3 2 1
For information on all Syngress publications visit our website at www.syngress.com
Excerpts from Federal Information Processing Standards, Special Publications, and Interagency Reports referenced in this book are courtesy of the National Institute of Standards and Technology.
Dedication 1
This book is dedicated to my wonderful wife. Her support in giving me the opportunity to write this book cannot be expressed in simple words. For her continuous patience, encouragement, and for those times sacrifice. For her inspiration and incredible love for reading and editing, even when the subject matter may not have been of interest to her.
To my dear, loving wife Erin, you make me complete.
Thank you for tirelessly standing by my side and supporting me every step of the way. There are many times in ones life where the task may seem too difficult, but having someone like you there as a guiding arm to encourage and to consult has been a blessing.
You have always been there when the times were challenging. It is with great honor to share this accomplishment with you.
To my wife, with love.
Dedication 2
In memory of Ron Knode.
Ron was a gift that left an impression of a smile, kind words, encouragement, and a unique way to make one think and see in a different perspective. I feel extremely honored to have had the opportunity to know and be mentored by Ron.
Ron, you have left an impression on many that will never be forgotten.
About the Author
Matthew Metheny, PMP, CISSP, CAP, CISA, CSSLP, CRISC, CCSK, is the founder of One Enterprise Consulting Group, LLC (1ECG), a privately held consulting firm that specializes in providing professional services that include cloud strategy and architecture, cloud security assessments, cloud migration, and cloud computing training. Mr. Metheny is a member of the Board of Directors for the Cloud Security Alliance (CSA) Washington, DC Metro Chapter, the CloudTrust Protocol (CTP) Working Group Co-Chair, and is a CSA-certified instructor for the Certificate of Cloud Security Knowledge (CCSK). Prior to 1ECG, Mr. Metheny held senior-level program management and executive-level positions with various consulting firms supporting both the federal government and the private sector with a focus on governance, risk management, emerging technologies, and security compliance. In addition, he is the founder of FedRAMP.net, which is focused on supporting cloud service providers and federal agencies with addressing the requirements of the Federal Risk and Authorization Management Program (FedRAMP). Mr. Metheny holds a Master of Science degree in Information Assurance from the University of Maryland University College (UMUC) and multiple internationally recognized certifications.
About the Technical Editor
Janis Orsino is an IT security consultant with more than two decades experience delivering technology and business consulting services for the U.S. federal government, in both civilian and defense sectors. She is presently a Senior Managing Consultant with IBM Global Business Services, U.S. Federal Cybersecurity and Privacy Consulting Practice.
From 2009 to 2011, during a contract assignment with the Defense-wide Information Assurance Program, Janis helped to shape the Federal Risk and Authorization Management Program (FedRAMP) from its inception as a key advisor to the DoD Joint Authorization Board. She was also engaged in the cloud computing security guidance development efforts of the Federal CIO Councils Information Security and Identity Management Committee, Network and Infrastructure Security Subcommittee.
Janis holds a Bachelor of Science degree in Social Psychology from Park University, a Graduate Certificate in Legal Studies from The George Washington University, and a string of industry certifications, including Certified Information Systems Security Professional (CISSP), Certified Information Systems Manager (CISM), Certified in Risk and Information Systems Control (CRISC), GIAC Security Leadership Certification (GSLC) and the Certificate of Cloud Security Knowledge (CCSK).