Feeds

NASA's cloud strategy panned by NASA auditors

Houston, you have a problem

Application security programs and practises

NASA's cloud strategy has been panned by its own auditors, proving that even technically competent oganizations can sputter when trying to soar into the tech stratosphere.

In a lengthy report released on Monday by NASA's Office of Audits, investigators slammed the agency's cloud governance, risk management, and security policies.

"We found that weaknesses in NASA's IT governance and risk management practices have impeded the Agency from fully realizing the benefits of cloud computing and potentially put NASA systems and data stored in the cloud at risk," the OA report says.

As of mid-2013 NASA spends a piddling $10m of its $1.5bn annual IT budget on public cloud services, but the agency expects that 75 percent of its new IT projects in the next five years will be all cloudy, and 40 percent of legacy systems will be migrated.

For this reason, "as NASA moves more of its systems and data to the cloud, it is imperative that the Agency strengthen its governance and risk management practices to safeguard its data while effectively spending its IT funds," the OA writes.

The problems began when the auditors asked NASA for the number of cloud services and associated service providers it was using. They found that NASA's Office of the Chief Information Officer (OCIO) "was unaware of two of the eight companies providing cloud services to NASA," and found that only three of NASA's 15 organizations believed they needed to coordinate with the agency when bringing in new cloud projects.

A further problem was that of five cloud-computing contracts reviewed during the investigation, none "came close to meeting recommended best practices" for security and management. The OA found that the contracts rarely had defined roles and responsibilities for the provider, nor guaranteed any level of system availability. None of the contracts satisfied data-privacy requirements, nor data retention and destruction policies.

The most severe problem identified by the auditors was lax security policies within NASA.

"We found that NASA's internal and external portal, which includes more than 100 websites, was operating without system security or contingency plans and with an operating authorization that expired in 2010," the OA wrote. "Even more troubling, a test of security controls on the IT services provided by the NASA Portal had never been undertaken to determine whether the system's controls were implemented correctly, operating as intended, and producing the desired results of securing the system and its data."

The team made six recommendations to NASA to help it tighten up its security and governance models for cloud projects, and NASA is in the process of implementing those, the report says.

Changes will include establishing a dedicated cloud-computing program management office, making sure that NASA organizations use contracts that mitigate risks and meet FedRAMP (a certification that assures federal buyers of cloud compliance) standards, closely monitoring migrations of moderate-to-high-impact NASA systems to public clouds and making sure this conforms with federal requirements, making all NASA CIOs look closely at FedRAMP and ensure that existing contracts can conform to it, mandating the development of NIST-compliant security and contingency plans with cloud providers and brokers, and, finally, ensuring that security officers review all IT security documentation for projects.

Though these changes seem like common sense, the fact the auditors need to recommend that NASA perform them highlights the gulf between cloud nirvana and cloud reality. Even a technically advanced organization like NASA can have trouble effectively putting clouds in place, proving that cloud computing for the public sector is not rocket science – its harder. ®

Eight steps to building an HP BladeSystem

More from The Register

next story
Sysadmin Day 2014: Quick, there's still time to get the beers in
He walked over the broken glass, killed the thugs... and er... reconnected the cables*
SHOCK and AWS: The fall of Amazon's deflationary cloud
Just as Jeff Bezos did to books and CDs, Amazon's rivals are now doing to it
Amazon Reveals One Weird Trick: A Loss On Almost $20bn In Sales
Investors really hate it: Share price plunge as growth SLOWS in key AWS division
US judge: YES, cops or feds so can slurp an ENTIRE Gmail account
Crooks don't have folders labelled 'drug records', opines NY beak
Auntie remains MYSTIFIED by that weekend BBC iPlayer and website outage
Still doing 'forensics' on the caching layer – Beeb digi wonk
Manic malware Mayhem spreads through Linux, FreeBSD web servers
And how Google could cripple infection rate in a second
BlackBerry: Toss the server, mate... BES is in the CLOUD now
BlackBerry Enterprise Services takes aim at SMEs - but there's a catch
The triumph of VVOL: Everyone's jumping into bed with VMware
'Bandwagon'? Yes, we're on it and so what, say big dogs
prev story

Whitepapers

Top three mobile application threats
Prevent sensitive data leakage over insecure channels or stolen mobile devices.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Designing a Defense for Mobile Applications
Learn about the various considerations for defending mobile applications - from the application architecture itself to the myriad testing technologies.
Build a business case: developing custom apps
Learn how to maximize the value of custom applications by accelerating and simplifying their development.