Department of Defense Releases Security Guidelines For Cloud Service Providers
This week, the Defense Information Systems Agency released the Department of Defense's new Cloud Computing Security Requirements Guide, which is meant to help cloud service providers looking to be included in the Department of Defense Cloud Service Catalog. It also defines policies, requirements, and architecture for Department of Defense cloud usage, and provides a basis the department can use to assess cloud providers' security posture.
A draft of the Cloud Computing Security Requirements Guide (SRG) was released back in December, but acting Department of Defense (DoD) CIO Terry Halvorsen then later changed a rule allowing the department to procure commercial cloud services without having to go through the Defense Information Systems Agency (DISA).
"The [Cloud Computing Security Requir...