finn :verified: · @finn
14 followers · 6 posts · Server otter.buzz

Cisco Umbrella is navigating the rigorous process to ensure secure cloud services for federal agencies. Currently "In-Process", Umbrella is preparing for stringent 3PAO audits. This milestone underlines Cisco's commitment to helping the government innovate securely for the future.

blogs.cisco.com/government/und

#fedramp #cloudsecurity #ciscoumbrella #governmentinnovation

Last updated 1 year ago

Peter Burkholder · @pburkholder
173 followers · 86 posts · Server infosec.exchange

The draft SAR (Security Assessment Report) I got from our is solid. Can't believe we paid for subpar work the last few years.

#3pao #fedramp

Last updated 1 year ago

infosec-jobs.com · @infosec_jobs
1465 followers · 14577 posts · Server mastodon.social
Matt Wilkerson · @chat_with_matt
2 followers · 5 posts · Server hachyderm.io

How do I deliver a secure and reliable k8s platform with guardrails?

It's challenging and the topic arises often with my customers. My awesome teammate Poonam unveils an essential tool.

, , , , ,

buff.ly/3wqvjK0

#gke #k8s #security #policycontroller #anthos #fedramp #FIPS

Last updated 2 years ago

Greg Hurlman :verified: · @98codes
382 followers · 204 posts · Server hachyderm.io

Shoutout to the guy in this coffee shop writing something about the importance of , while also leaving his laptop unlocked while he took 30s to get his coffee.

The lack of basic security knowledge and behavior in consistently astonishes me.

#fedramp #seattle

Last updated 2 years ago

HyenaTech · @hyenatech
58 followers · 383 posts · Server cyberfurz.social

Slept for a while after I got home from the doctor's office. Feeling like crap and now my sleep schedule is kind of jacked. So, now I am up and reading NIST SP 800-190 and associated FedRAMP container security documentation, as well as trying to dig a bit more into container vulnerability scanning.

#nist #fedramp #security #infosec #containers #kubernetes #docker #podman #linux #vulnerability

Last updated 2 years ago

John Allison · @johnallison
44 followers · 707 posts · Server toot.community

If you are a startup, please think hard before you decide to try . There are many reasons to do it, but don't listen to anyone that tells you that it will be easy and quick. FedRAMP is a lifestyle change, not a side project for a small company.

#fedramp

Last updated 2 years ago

Peter Burkholder · @pburkholder
147 followers · 339 posts · Server mastodon.social

All in for adopting post-quantum cryptography, but requiring an inventory of quantum-vulnerable systems has ZERO value when _everything_ is -vulnerable

(CRQC: cryptographically relevant quantum computer)

#crqc #omb #fedramp

Last updated 2 years ago

Shane Milton ☁️:clippy: · @Jaxidian
130 followers · 329 posts · Server mastodon.online

Can any of my people familiar with can tell me why GCC High shows that it is not FedRAMP'd in the FedRAMP marketplace?

All sorts of Microsoft docs say that it is FedRAMP High compliant, but the Marketplace seems to disagree.

marketplace.fedramp.gov/#!/pro

#azure #fedramp #office #m365 #o365 #microsoft365 #infosec #microsoft

Last updated 2 years ago

John Allison · @johnallison
36 followers · 609 posts · Server toot.community

If you are into , the AWS GovCloud team has a program called ATO on AWS that will give you some free consulting on how to configure AWS services to be FedRAMP compliant. Now, the issue is that they don't advertise this well, so you could be like me and only learn about this way too late.

#fedramp

Last updated 2 years ago

Keith Crawford · @tsudo
426 followers · 324 posts · Server infosec.exchange

As the National Defense Authorization Act (NDAA) has passed both the Senate and the House it is now expected to be signed by President Biden. It has language that changes FedRAMP.

From Fedscoop:

  • It establishes a board & cloud advisory comm.
  • Includes a "presumption of adequacy" which seems to mean "cloud service offering has met baseline security standards established by the program and should be considered approved for use across the federal government." source
  • establishes some expectation of assessment metrics and annual report.

The bill H.R.7776 can be tracked at Congress.gov, specific language in case you are incredibly bored is Sec.5921 FedRAMP Authorization Act text

#fedramp #ndaa #hr7776

Last updated 2 years ago

👍🏻 reform legislation appended to National Defense Authorization Act - One of the most consequential aspects of the FedRAMP reform bill is a “presumption of adequacy” clause, which would allow FedRAMP-authorized tools to be used in an agency without additional oversight or verification. It will also create a separate cloud advisory committee consisting of five representatives from services companies fedscoop.com/fedramp-reform-le

#fedramp #cloud #infosec

Last updated 2 years ago

Ross K · @rossk
209 followers · 105 posts · Server hachyderm.io

Giving authorizations the “presumption of adequacy” would be... a BFD (in Biden-speak) fedscoop.com/fedramp-reform-le

#fedramp

Last updated 2 years ago

Mark Carter · @markcarter
75 followers · 90 posts · Server hachyderm.io

🤔 Announcing data protection in Amazon CloudWatch Logs, helping you detect, and protect sensitive data-in-transit - Data protection in CloudWatch Logs enables customers to define and apply data protection policies that scan log data-in-transit for sensitive data and mask sensitive data that is detected. log data protection can help with regulations such as Payment Card Industry Data Security Standard -DSS) and aws.amazon.com/about-aws/whats

#hipaa #gdpr #pci #fedramp #infosec

Last updated 2 years ago

jessesanford · @jessesanford
8 followers · 3 posts · Server infosec.exchange

I was able to put together a quick case study of our use of @sigstore at Autodesk. Check it out if you have a few mins and are interested in container provenance and ! Big thanks to Tracy Miranda and the Chainguard team for all the help! blog.sigstore.dev/using-sigsto

#fedramp #supplychainsecurity

Last updated 2 years ago

Jason "JK" Keirstead · @BlueTeamJK
15 followers · 39 posts · Server infosec.exchange

It would be a great accelerator for adoption if there was a way to leverage them to accelerate / /

If one was able to digitally attest to known approved versions of software libraries in their SBOM, you would think it could reduce their certification burden.

The current NIAP/CC/FedRAMP process is endlessly broken and this could be a great way to start to modernize it.

#SBOM #niap #fips #fedramp

Last updated 2 years ago

Matthew Lorimor · @mattlorimor
10 followers · 11 posts · Server infosec.exchange

Never did an , apparently.

My name is Matthew Lorimor. I have most often just gone by "Lorimor" since I have been on too many teams with too many Matts.

I've been at this InfoSec thing for a decade or so, now. I came by way of being a software engineer and having persistent security friends (let's be honest, it's mostly the fault of @matthewsullivan).

I currently work as a cloud security engineer for a company called Benchling. We do cool science software stuff.

Previously, I was at Workiva helping secure all sorts of Fortune 500 financial and reporting data with @matthewsullivan, @Trickster88, @ojensen, @benmontour, and @stuckshut. Most notably, I got to wade through the land of Moderate. What a joy that was.

I thought I had an acute problem of helping companies put on their enterprise security pants, but my move to Benchling a year ago seems to have proven that it's a chronic one instead.

I like AWS, Docker, and scanning tools of all kinds. I hate AWS, Docker, and scanning tools of all kinds.

#introduction #fedramp

Last updated 2 years ago

Never did an , apparently.

My name is Matthew Lorimor. I have most often just gone by "Lorimor" since I have been on too many teams with too many Matts.

I've been at this InfoSec thing for a decade or so, now. I came by way of being a software engineer and having persistent security friends (let's be honest, it's mostly the fault of @matthewsullivan).

I currently work as a cloud security engineer for a company called Benchling. We do cool science software stuff.

Previously, I was at Workiva helping secure all sorts of Fortune 500 financial and reporting data with @matthewsullivan, @Trickster88, @ojensen, @benmontour, and @stuckshut. Most notably, I got to wade through the land of Moderate. What a joy that was.

I thought I had an acute problem of helping companies put on their enterprise security pants, but my move to Benchling a year ago seems to have proven that it's a chronic one instead.

I like AWS, Docker, and scanning tools of all kinds. I hate AWS, Docker, and scanning tools of all kinds.

#introduction #fedramp

Last updated 2 years ago

Peter Burkholder · @pburkholder
90 followers · 100 posts · Server mastodon.social

Brain: let’s think about / and !
Me: its 4:48 it can wait let’s sleep
Brain: 🖕

#fedramp #FISMA #fips140

Last updated 2 years ago

Peter Burkholder · @pburkholder
86 followers · 95 posts · Server mastodon.social

They say civil servants are risk averse, but I'm like:

> We will not adopt
in contexts where we determine it would undermine our security stance. If this stance will costs
us our authorization, then we will proceed to wind down our CSP and tell our customers to
move their workloads.

#fips140 #fedramp

Last updated 2 years ago