news.volyx.in

Despite doubts, federal cyber experts approved Microsoft cloud service (propublica.org)

487 points by hn_acker · 166 days ago · 225 comments on HN

Article summary

Federal cyber experts had significant concerns about the security of Microsoft's Government Community Cloud High (GCC High) but approved it anyway, despite the company's inability to provide adequate documentation and evidence of its security measures. The approval was made after the product was already being used across the government and defense industry. This decision has raised questions about the effectiveness of the Federal Risk and Authorization Management Program (FedRAMP) in ensuring the security of cloud services used by the government. The program has been criticized for being slow and ineffective, with some arguing that it has become a rubber stamp for industry.

Main themes

  • Cloud Security
  • Government Procurement
  • FedRAMP Effectiveness
  • Microsoft Cloud Services
  • Cybersecurity Risks
  • Government Regulation

What commenters say

  • The government's approval of Microsoft's GCC High despite security concerns is an example of a bureaucracy prioritizing expediency over security and proper procedure.
  • The FedRAMP process is flawed and has become a rubber stamp for industry, allowing companies to push through products with inadequate security measures.
  • The market, rather than government agencies, should decide which cloud providers to use, as this would lead to better outcomes and more efficient decision-making.
  • The government has a history of solving complex problems and is capable of effectively evaluating and regulating cloud services, contrary to claims of inefficiency.
  • Private companies and market forces are not necessarily more effective or efficient than government agencies in addressing complex issues like cloud security.
  • The complexity of cloud security and the need for customization can lead to difficulties in implementation and use, even with products from major providers like Microsoft.
  • Conflicts of interest and the influence of industry on government decision-making can compromise the security and integrity of cloud services used by the government.
  • The effectiveness of FedRAMP and other regulatory programs is hindered by limited resources, inadequate staffing, and inefficient processes.