As Defense Department officials accelerate the Pentagon’s adoption of commercial cloud services, they’re taking a more critical look at the security and the relationships that underpin the move.
Acting DoD CIO Terry Halvorsen is looking for ways to better embrace industry’s cloud offerings, including streamlining the military’s traditionally complex security requirements, examining new ways of running cloud services and changing up how the Pentagon and industry interact with each other. And he sees such changes as potentially going beyond just DoD.
“All of you want your data to be secure too…if we can raise that national bar together, we can do [cloud] much more effectively and much more efficiently,” Halvorsen told hundreds of attendees at his office’s industry day in Washington on Jan. 29. “What’s really the right level of security for things like financial data or personnel data? If we get those answers right, that’s way beyond just what we can use at DoD.”
Halvorsen pointed to the Pentagon’s mass volumes of data as just one hurdle in the military’s move to the cloud, noting that DoD has the potential to be the government’s largest consumer of cloud services. But a number of steps must be taken before that can happen, including a re-evaluation of some of the security standards applied to DoD data to determine how much and what ends up in the cloud.
“Are my data storage requirements right for archived data? That’s what I want to look at in DoD. Am I putting too much security structure around archived data that, when it was recent, was really sensitive? Ten-year-old data isn’t that sensitive,” Halvorsen said. “We’re really in the nascent stages of how to do that analysis.”
The scrutiny of just how much security DoD needs goes beyond just how old or what kind of data it is. Security requirements around data and cloud continue to change at DoD, most recently with new guidance published earlier this month.
Don’t expect those changes to end anytime soon, Halvorsen indicated, including potential shifts in DoD’s augmented use of current government-wide FedRAMP standards, known as “FedRAMP-plus.”
Halvorsen hopes the hard look at security requirements will have broader impact than just at DoD, or even just within the government.
“If we get this FedRAMP-plus right…we actually could have a national standard that’s not just government,” Halvorsen said. For example, “if you have a certain type of medical data, this ought to be the level it’s protected at – commercial, government, academic, any place. We ought to have that level of protection, and it’s the right level, not [overpriced], not overprotected. I hope this will get a national dialog about that started.”
Halvorsen also expects changes to the relationships between government and industry, calling for a more honest conversation between the two and even between commercial providers.
“This is going to have to be a much better partnership between industry and government in how we do this in a way that makes you money,” he said, adding that both sides need to step up transparency, especially when it comes to liability and security incidents. “We do well until we talk about, ‘well, that means you’re going to have to say our company was part of the loss.’ Yep, it does, and we need to work through that.”
Halvorsen additionally said he expects there to be changes in the ways the government operates cloud services and facilities in cooperation with industry. The immediate goal is to move as much public-facing information as possible to a public cloud solution, and he expects that DoD’s next iteration of enterprise e-mail will be completely commercial.
Looking a little further down the road, Halvorsen’s already gotten the green light from Frank Kendall, under secretary of Defense for acquisition, technology and logistics, to evaluate a scenario where commercial cloud providers operate in DoD facilities and still serve non-government entities.
“I’m very open to saying, ‘Why couldn’t we put what amounts to a commercial data distribution center on government property in a government building?’” Halvorsen said. “I’m waiting for that proposal with all the costs associated with it. I think it’s an outstanding idea.”




