Cloud Computing Security
Cloud Security Strategy and Architecture
Focuses on assisting our client in addressing concerns for enterprise security and privacy in the cloud. We help by identifying risks and developing risk mitigation plans that include strategies for integrating security into the cloud environment (private, public or hybrid).
Cloud Security Assessments
We evaluate and assess security controls and architectures for planned or existing cloud services against industry “best practices and standards”, regulatory requirements (FISMA, HIPAA, SOX, PCI, FedRAMP, etc.), and provide recommended steps to address deficiencies and improve the overall security of the cloud service (IaaS, PaaS, SaaS, or combination thereof) and protection of data within the supply chain.
Federal Risk and Authorization Management Program Readiness Assessments
We help our clients prepare for and meet compliance with the Federal Risk and Authorization Management Program which provides a standard approach to Assessing and Authorizing (A&A) cloud computing services and products.
A&A and Continuous Monitoring Support Services
We help our clients comply with by ensuring continued compliance with a multitude of federal-wide and agency-specific security requirements necessary for receiving an Authorization-To-Operate (ATO) through the A&A process and maintaining compliance as part of the CSPs ongoing Continuous Monitoring Program.
Federal Agency Cloud Migration
We assist our clients in understanding and assessing the risks associated with migrating to the cloud, while maintaining an assurance for areas such as data security (integrity and confidentiality), business continuity and disaster recovery, privacy, and isolation within a multi-tenant environment which are critical for securely adopting cloud solutions.
CSA STAR Preparation
We assist our clients in preparing a report for submission to the CSA STAR public registry. The compliance option includes either completing the Consensus Assessments Initiative Questionnaire (CAIQ) or documenting compliance with Cloud Controls Matrix (CCM). For additional information, please refer to the Cloud Security Alliance.
CSA GRC Stack Integration Strategy
We assist our clients in establishing a strategy for integrating the CSA GRC Stack for self-assessment, audit preparation and automation, information security program alignment, exiting product/service integration, and processes/procedures. The CSA GRC Stack includes the Consensus Assessments Initiative Questionnaire (CAIQ), Cloud Controls Matrix (CCM), CloudAudit API, and CloudTrust Protocol (CTP). For additional information, please refer to the Cloud Security Alliance.
Click here to download a copy of our Cloud Security Services Brochure.
