The Register® — Biting the hand that feeds IT

Feeds

NASA's cloud strategy panned by NASA auditors

Houston, you have a problem

Free ESG report : Seamless data management with Avere FXT

NASA's cloud strategy has been panned by its own auditors, proving that even technically competent oganizations can sputter when trying to soar into the tech stratosphere.

In a lengthy report released on Monday by NASA's Office of Audits, investigators slammed the agency's cloud governance, risk management, and security policies.

"We found that weaknesses in NASA's IT governance and risk management practices have impeded the Agency from fully realizing the benefits of cloud computing and potentially put NASA systems and data stored in the cloud at risk," the OA report says.

As of mid-2013 NASA spends a piddling $10m of its $1.5bn annual IT budget on public cloud services, but the agency expects that 75 percent of its new IT projects in the next five years will be all cloudy, and 40 percent of legacy systems will be migrated.

For this reason, "as NASA moves more of its systems and data to the cloud, it is imperative that the Agency strengthen its governance and risk management practices to safeguard its data while effectively spending its IT funds," the OA writes.

The problems began when the auditors asked NASA for the number of cloud services and associated service providers it was using. They found that NASA's Office of the Chief Information Officer (OCIO) "was unaware of two of the eight companies providing cloud services to NASA," and found that only three of NASA's 15 organizations believed they needed to coordinate with the agency when bringing in new cloud projects.

A further problem was that of five cloud-computing contracts reviewed during the investigation, none "came close to meeting recommended best practices" for security and management. The OA found that the contracts rarely had defined roles and responsibilities for the provider, nor guaranteed any level of system availability. None of the contracts satisfied data-privacy requirements, nor data retention and destruction policies.

The most severe problem identified by the auditors was lax security policies within NASA.

"We found that NASA's internal and external portal, which includes more than 100 websites, was operating without system security or contingency plans and with an operating authorization that expired in 2010," the OA wrote. "Even more troubling, a test of security controls on the IT services provided by the NASA Portal had never been undertaken to determine whether the system's controls were implemented correctly, operating as intended, and producing the desired results of securing the system and its data."

The team made six recommendations to NASA to help it tighten up its security and governance models for cloud projects, and NASA is in the process of implementing those, the report says.

Changes will include establishing a dedicated cloud-computing program management office, making sure that NASA organizations use contracts that mitigate risks and meet FedRAMP (a certification that assures federal buyers of cloud compliance) standards, closely monitoring migrations of moderate-to-high-impact NASA systems to public clouds and making sure this conforms with federal requirements, making all NASA CIOs look closely at FedRAMP and ensure that existing contracts can conform to it, mandating the development of NIST-compliant security and contingency plans with cloud providers and brokers, and, finally, ensuring that security officers review all IT security documentation for projects.

Though these changes seem like common sense, the fact the auditors need to recommend that NASA perform them highlights the gulf between cloud nirvana and cloud reality. Even a technically advanced organization like NASA can have trouble effectively putting clouds in place, proving that cloud computing for the public sector is not rocket science – its harder. ®

5 ways to reduce advertising network latency

Whitepapers

5 ways to reduce advertising network latency
Implementing the tactics laid out in this whitepaper can help reduce your overall advertising network latency.
Supercharge your infrastructure
Fusion­‐io has developed a shared storage solution that provides new performance management capabilities required to maximize flash utilization.
Avere FXT with FlashMove and FlashMirror
This ESG Lab validation report documents hands-on testing of the Avere FXT Series Edge Filer with the AOS 3.0 operating environment.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Email delivery: 4 steps to get more email to the inbox
This whitepaper lists some steps and information that will give you the best opportunity to achieve an amazing sender reputation.

More from The Register

next story
Dedupe-dedupe, dedupe-dedupe-dedupe: Flashy clients crowd around Permabit diamond
3 of the top six flash vendors are casing the OEM dedupe tech, claims analyst
Disk-pushers, get reel: Even GOOGLE relies on tape
Prepare to be beaten by your old, cheap rival
Dragons' Den star's biz Outsourcery sends yet more millions up in smoke
Telly moneybags went into the cloud and still nobody's making any profit
Hong Kong's data centres stay high and dry amid Typhoon Usagi
180 km/h winds kill 25 in China, but the data centres keep humming
Microsoft lures punters to hybrid storage cloud with free storage arrays
Spend on Azure, get StorSimple box at the low, low price of $0
WD unveils new MyBook line: External drives now bigger... and CHEAP
Less than £0.04/GB, but it loses the Thunderbolt speed
VMware vSAN test pilots: Don't panic but there's a chance of DATA LOSS
AHCI SATA controller won't play nice with Virtzilla's robo-storage beta
prev story