fbpx Skip to content

How Resilient are FedRAMP Clouds Anyway?

Yahoo-Microsoft Merger Proxy Fight – May 14, 2008

By G C Network | May 18, 2008

As I alluded to last week, “It’s not over ’till it’s over” Carl Ichan Looking to Start Yahoo Proxy Fight Money – The Microsoft-Yahoo Merger may not be over. Billionaire investor Carl C. Icahn is considering the prospect of starting a proxy fight to gain several seats on Yahoo’s board in hopes of restarting negotiations…

Now in the ring Sun/Amazon! – May 04, 2008

By G C Network | May 18, 2008

The Sun/Amazon cloud may be announced soon. Sun CEO Jonathan Schwartz delivered a short keynote at Startup Camp in San Francisco, an adjunct event to the JavaOne Conference. According to Om Malik at “buzzya“, he let on to some interesting cloud computing news coming out later this week. Important Article on Cloud Computing and Jeff…

Microsoft gives up on Yahoo? – May 04, 2008

By G C Network | May 18, 2008

“Cloud computing is far more than a concept. With Broadband Internet connections now all-but-ubiquitous and microcomputers and locally-run software now so trouble-prone, Cloud Computing’s time has come.” This is a quote from Steve Stroh’s newly started blog on cloud computing. Steve has been writing about about Broadband Wireless Internet Access systems and technology since beginning…

IBM, Google and the Blue Business Platform – May 01, 2008

By G C Network | May 18, 2008

Today was good !! This morning. there was a main session built around “CIO 2.0”. The basic premise was that CIOs have now earned a seat at the business management table. With that privilege, they now need to have something worthwhile to say. In accordance with the session’s title then, CIOs are now at a…

The coming cloud – April 30, 2008

By G C Network | May 18, 2008

I attended the IBM Public Sector briefing this morning. The IBM executives were clearly basking in a financial performance glow. After ending 2007 with increases in revenue, profit and earnings per share, IBM also turned in an impressive 1Q’08. This being a partner conference, a big highlight was the fact that 36% of IBM’s revenue…

Google, Cloud Computing, and the US Intelligence Community – April 29, 2008

By G C Network | May 18, 2008

Just arrived in Los Angeles for the IBM Business Partner Leadership Conference. IBM is billing this as a “new” conference, but I have my doubts. I am, however, very interested in hearing many of the speakers, particularly Eric Schmidt, Chairman and CEO of Google. His presentation on “The Future of the Web, Cloud Computing and…

Location Based Services – April 25, 2008

By G C Network | May 18, 2008

INmobile.org is a exclusive community for executives in wireless industry. As a member, I have the opportunity to participate in a number of interesting discussions about mobile and wireless technology. Here’s a summary of the points made in a recent discussion about location based services. Thanks goes to Adam Zawel for this excellent summary. CARRIER’S…

IBM Business Partner Leadership Conference – April 23, 2008

By G C Network | May 18, 2008

I just completed registration for the IBM Business Partner Leadership Conference. This is a new invitation-only conference being held this year in Los Angeles from Wednesday, April 30th through Friday, May 2nd. I’m looking forward to renewing my IBM contacts “in person” versus the “virtual” meetings that have become such a fixture of today’s business…

Telephone & Web = WOW !! – April 21, 2008

By G C Network | May 18, 2008

The power of the Internet and the web lies in its ability to provide access to information. The mobile web takes this one step further with its ability to provide information relevant to a specific location. Although the promise of this marriage is mind boggling, computer and smart-phone keyboards have slowed the adoption and widespread…

The Power of Family Oral History – April 19, 2008

By G C Network | May 18, 2008

Although I just started this yesterday, I’ve decided to backdate this entry to last Saturday, April 12, 2008. That’s when my family had it’s 3rd Annual Black History Party. The main reason I’m doing this is because of the life lesson that experience taught me. That lesson was the power of family oral history. For…


By Jodi Kohut
For the uninitiated, FedRAMP is the Federal Risk Authorizationand Management Program, a government-wide program that provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services. Implemented to support the Administration’s “Cloud First” policy, some have pointed to FedRAMP as a great model for commercial industry’s adoption of cloud as well. But when it comes to disaster recovery in the cloud, is that necessarily the case?
One of the questions I’ve been asked from the beginning of the Federal Cloud First initiative, is, “If my data is in   The answer is not as clear-cut as the question.  In theory, most cloud services offer extremely resilient platforms and a modicum of disaster recovery is built in. In fact, those cloud service provider (CSP) systems that have received an ATO through the FedRAMP program do have fairly sophisticated contingency plans in place, with Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) clearly articulated- and plenty of alternate processing sites, policies, and procedures in place in the event of a contingency.  So, it’s in there right?

Not so fast- it depends on what services you are acquiring and how you are deploying and managing them.  The baseline of this discussion is however rooted in availability and uptime. 

the cloud, isn’t my disaster recovery built in? Isn’t that the benefit of being in the cloud?”

A CSP may be able to provide a more resilient infrastructure than an Agency can build internally.  For example, recent research from the International Working Group on Cloud Computing Resiliency (IWGCR) reported 2013 total downtime hours from major providers as follows:

  • Amazon – 28.23 hours
  • Rackspace – 97.98 hours
  • Verizon – 136 hours

The availability percentages of these providers range from 98.44-99.68%.  Even though the IWGCR believes this data may under report outages, the data may also overstate service downtime.  Let me explain.
The cloud providers mentioned here provide SLA’s for individual services.  Often these are subject to separate SLA’s rather than aggregated ones.   In practice, CSPs orchestrate these services in such a way that a customer can expect 100% availability at a fraction of a cost of building the same solution internally. Considering that only 8% of federal government agencies report confidence in being able to recover 100% of the data required by their governing SLA’s, FedRAMP authorized clouds seem to be perfect for addressing disaster recovery. These same agencies also report an inability to test their disaster recovery plans as often or as thoroughly as they would like. In addition, from an alternative processing site standpoint, Cloud Service Providers offer more, geographically distributed sites for a fraction of the cost of building equivalent solutions internally.  And contrary to the emotions of some, moving disaster recovery to the cloud does not mean relinquishing control of the process or data.  FedRAMP mandatory contractual clauses give the government absolute control of all of its data, all of the time.
So with this in mind, “Is FedRAMP a good model?” Compared to the current state of government IT affairs, the answer is an unequivocal YES! Budget cuts, rapidly increasing IT requirements and the rising threat of cyber-attack are also great arguments for rapid adoption of commercially available, FedRAMP authorized cloud baseddisaster response services. Commercial companies operating in government-regulated industries should leverage this process as well by making FedRAMP provisional approval a minimum requirement for their own cloud service providers.   The list of companies currently in process to receive provisional authorization status for FedRAMP shows industry commitment to security of systems “In the cloud”.   

(This post was written as part of the Dell Insight Partners program, which provides news and analysis about the evolving world of tech. To learn more about tech news and analysis visit TechPageOne. Dell sponsored this article, but the opinions are our own and don’t necessarily represent Dell’s positions or strategies.)

Bookmark and Share

Cloud Musings

( Thank you. If you enjoyed this article, get free updates by email or RSS – © Copyright Kevin L. Jackson 2012)

Follow me at https://Twitter.com/Kevin_Jackson
Posted in

G C Network

Leave a Comment





Crate

Purchase Crate

Shipping and discount codes are added at checkout.

Checkout
Scroll To Top