How Resilient are FedRAMP Clouds Anyway?

Thank You GetVoIP!!

By G C Network | April 25, 2014

Thank you for the honor of being named a “Top 100 Cloud Professionals to Follow on G+”! Congratulations also to my 99 colleagues.  Read more at: ↑ Grab this Headline…

Facilitators Announced For NGA Agile Cloud Brainstorming Event

By G C Network | April 14, 2014

The Information Technology Acquisition Advisory Council (ITAAC) and the Telecommunications Industry Association (TIA) are announcing a slate of innovative leaders to serve as facilitators for the upcoming  “Agile Sourcing Environment…

MBO Partners Spotlights GovCloud Founder Kevin L. Jackson

By G C Network | April 6, 2014

Associate Spotlight Interview with Kevin L. JacksonMBO Associate Since 10/2013 1)    Tell us a little bit about what you do.I am the CEO and founder of GovCloud Network, LLC. In…

ITAAC/ICH and TIA To Host Commercial Cloud Sourcing Brainstorming Session for NGA

By G C Network | April 1, 2014

The Information Technology Acquisition Advisory Council (ITAAC) and Telecommunications Industry Association (TIA) are honored to team with NGA in hosting the first “Agile Sourcing Environment for Commercial Cloud” brainstorming session,…

Author and Tech Strategist Melvin Greer Profiled by WashingtonExec

By G C Network | March 17, 2014

Congratulations to my NCOIC colleague and dear friend Melvin Greer on his impressive WashingtonExec interview. A senior fellow and chief strategist at Lockheed Martin, Mel has more than 29 years’…

IT Risk Management Summit – March 26, 2013 – Reston, VA

By G C Network | March 12, 2014

In response to growing demand for formal software risk and quality management tools, the nations’ most respected standards bodies and IT communities of practice have joined forces to advance the…

PerspecSys Survey Reveals Cloud-based Security Concerns for 2014

By G C Network | March 10, 2014

Today PerspecSys announced the results of a survey conducted at the 2014 RSA Conference concerning the attitudes and policies of organizations towards cloud-based security. After polling 130 security professionals on…

NCOIC Debuts Roadmap for Designing, Managing Cyber-secure Hybrid Computing Environment

By G C Network | March 5, 2014

Open process by the Network Centric Operations Industry Consortium uses cloud infrastructure to cut computing costs in half and enable collaboration by different systems and users WASHINGTON—March 5, 2014—The Network…

Why State & Local Governments Should be Prepared for Cloud

By G C Network | February 17, 2014

You are invited to attend the Cloud Webinar Series: Why State & Local Governments Should be Prepared for Cloud. This educational webinar is brought to you by RISC Networks, and…

IBM Hybrid Cloud Debate: Experts debate: Are Hybrid Clouds the End All Be All?

By G C Network | February 12, 2014

A hybrid cloud may become the solution as the debate between public vs private cloud becomes so 2013. The industry’s experts will debate on when the hybrid clouds are and…


By Jodi Kohut
For the uninitiated, FedRAMP is the Federal Risk Authorizationand Management Program, a government-wide program that provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services. Implemented to support the Administration’s “Cloud First” policy, some have pointed to FedRAMP as a great model for commercial industry’s adoption of cloud as well. But when it comes to disaster recovery in the cloud, is that necessarily the case?
One of the questions I’ve been asked from the beginning of the Federal Cloud First initiative, is, “If my data is in   The answer is not as clear-cut as the question.  In theory, most cloud services offer extremely resilient platforms and a modicum of disaster recovery is built in. In fact, those cloud service provider (CSP) systems that have received an ATO through the FedRAMP program do have fairly sophisticated contingency plans in place, with Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) clearly articulated- and plenty of alternate processing sites, policies, and procedures in place in the event of a contingency.  So, it’s in there right?

Not so fast- it depends on what services you are acquiring and how you are deploying and managing them.  The baseline of this discussion is however rooted in availability and uptime. 

the cloud, isn’t my disaster recovery built in? Isn’t that the benefit of being in the cloud?”

A CSP may be able to provide a more resilient infrastructure than an Agency can build internally.  For example, recent research from the International Working Group on Cloud Computing Resiliency (IWGCR) reported 2013 total downtime hours from major providers as follows:

  • Amazon – 28.23 hours
  • Rackspace – 97.98 hours
  • Verizon – 136 hours

The availability percentages of these providers range from 98.44-99.68%.  Even though the IWGCR believes this data may under report outages, the data may also overstate service downtime.  Let me explain.
The cloud providers mentioned here provide SLA’s for individual services.  Often these are subject to separate SLA’s rather than aggregated ones.   In practice, CSPs orchestrate these services in such a way that a customer can expect 100% availability at a fraction of a cost of building the same solution internally. Considering that only 8% of federal government agencies report confidence in being able to recover 100% of the data required by their governing SLA’s, FedRAMP authorized clouds seem to be perfect for addressing disaster recovery. These same agencies also report an inability to test their disaster recovery plans as often or as thoroughly as they would like. In addition, from an alternative processing site standpoint, Cloud Service Providers offer more, geographically distributed sites for a fraction of the cost of building equivalent solutions internally.  And contrary to the emotions of some, moving disaster recovery to the cloud does not mean relinquishing control of the process or data.  FedRAMP mandatory contractual clauses give the government absolute control of all of its data, all of the time.
So with this in mind, “Is FedRAMP a good model?” Compared to the current state of government IT affairs, the answer is an unequivocal YES! Budget cuts, rapidly increasing IT requirements and the rising threat of cyber-attack are also great arguments for rapid adoption of commercially available, FedRAMP authorized cloud baseddisaster response services. Commercial companies operating in government-regulated industries should leverage this process as well by making FedRAMP provisional approval a minimum requirement for their own cloud service providers.   The list of companies currently in process to receive provisional authorization status for FedRAMP shows industry commitment to security of systems “In the cloud”.   

(This post was written as part of the Dell Insight Partners program, which provides news and analysis about the evolving world of tech. To learn more about tech news and analysis visit TechPageOne. Dell sponsored this article, but the opinions are our own and don’t necessarily represent Dell’s positions or strategies.)

Bookmark and Share

Cloud Musings

( Thank you. If you enjoyed this article, get free updates by email or RSS – © Copyright Kevin L. Jackson 2012)

Follow me at https://Twitter.com/Kevin_Jackson
Posted in

G C Network