home.social

#fedramp — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #fedramp, aggregated by home.social.

fetched live
  1. Proud to share that RELIANOID is aligned with the FEDRAMP Moderate Baseline.

    Our commitment to secure federal and regulated environments includes:

    🔹 Risk management & security governance
    🔹 RBAC & MFA
    🔹 Continuous vulnerability monitoring
    🔹 Secure releases and updates
    🔹 Incident response
    🔹 Supply-chain security
    🔹 Business continuity & disaster recovery

    Building secure, resilient, and high-performance digital infrastructure.

    relianoid.com/security-complia

  2. I'm trying to understand why I would choose a regular AWS endpoint over FIPS. I know why and when I have to use FIPS. Given that I have a subset of customers that require it, why not just use it for all customers? One would hope if the ciphers in FIPS are good enough for the government, they're good enough for regular use.

    #InfoSec #FIPS #FedRamp #AWS

  3. Ryan has some thoughts about the recent FedRamp approval for Microsoft, even though the feds called it 💩. In The Long Run, maybe you should be able to explain how things like encryption and security controls work in your environment? #TheCloudPod #NewEpisode #FedRamp #Microsoft

  4. I teach cybersecurity. And I genuinely don't know what to tell my students after this one. Federal reviewers spent years trying to get basic encryption documentation from Microsoft for its GCC High government cloud. They couldn't get it. One reviewer called the system a "pile of spaghetti pies," with data traveling from point A to point B the way you'd get from Chicago to New York: a bus to St. Louis, a ferry to Pittsburgh, and a flight to Newark. Each leg is a potential hijacking. They knew this. They said this out loud in writing. Then they approved it anyway in December 2024, because too many agencies were already using it. 🔐 That's not a security review. That's a hostage negotiation. Two things in this story should make every CISO and CIO uncomfortable:

    🧩 Microsoft built its federal cloud on top of decades of legacy code that it apparently can't fully document itself
    👮 "Digital escorts" often ex-military with minimal software engineering backgrounds are the firewall between Chinese engineers working on the system and classified U.S. networks 🤦🏻‍♂️

    The scariest line in the whole ProPublica investigation isn't the "pile of shit" quote. It's this: FedRAMP determined that refusing authorization wasn't feasible because agencies were already using the product. Read that again. The security review process reached a conclusion based on sunk cost, not risk. Ex Post Facto Fallacy

    If that logic holds, the compliance framework is just documentation theater. And right now, CISA is being hollowed out, so there are fewer people left to even run the theater.

    arstechnica.com/information-te
    #Cybersecurity #Microsoft #FedRAMP #Leadership #RiskManagement #security #privacy #cloud #infosec

  5. I find myself at a point where I'm encountering irreconcilable differences between my moral, ethical, and technical objections to the use of LLMs, and my employer's leadership's desire to force the use of LLMs into every aspect of day to day operations. As a result, I find myself #OpenToWork .

    I have decades of experience in the #SysAdmin / #SRE / #DevOps / #CICD / #CloudComputing range of skills. Currently acting as a subject matter expert on #Kubernetes , #Terraform , and #Observability . Mostly supporting #GCP platforms these days, but I am comfortable pivoting to other #cloud platforms like #AWS or even #OnPrem . Can do #ProjectManagement and #TeamLeadership. Experienced in #DevSecOps and #FedRAMP processes.

    I would strongly prefer to deal with no LLM tooling at all, but will settle for having to use it less than in the current environment.

    Location: #Canada (remote), #WaterlooRegion (Ontario) (hybrid).

    #FediHire #FediHired #GetFediHired

  6. "For years, reviewers said, Microsoft had tried and failed to fully explain how it protects sensitive information in the cloud as it hops from server to server across the digital terrain. Given that and other unknowns, government experts couldn’t vouch for the technology’s security.

    Such judgments would be damning for any company seeking to sell its wares to the U.S. government, but it should have been particularly devastating for Microsoft. The tech giant’s products had been at the heart of two major cybersecurity attacks against the U.S. in three years. In one, Russian hackers exploited a weakness to steal sensitive data from a number of federal agencies, including the National Nuclear Security Administration. In the other, Chinese hackers infiltrated the email accounts of a Cabinet member and other senior government officials.

    The federal government could be further exposed if it couldn’t verify the cybersecurity of Microsoft’s Government Community Cloud High, a suite of cloud-based services intended to safeguard some of the nation’s most sensitive information.

    Yet, in a highly unusual move that still reverberates across Washington, the Federal Risk and Authorization Management Program, or FedRAMP, authorized the product anyway, bestowing what amounts to the federal government’s cybersecurity seal of approval. FedRAMP’s ruling — which included a kind of “buyer beware” notice to any federal agency considering GCC High — helped Microsoft expand a government business empire worth billions of dollars."

    propublica.org/article/microso

    #Microsoft #FedRAMP #USA #Trump #CyberSecurity #Cloud #CloudComputing

  7. IT-Security-Leute der US-Regierung sollten die MS-Cloud auf Tauglichkeit für geheime Daten prüfen. Wertung:

    "Pile of shit"
    “lack of proper detailed security documentation”
    “lack of confidence in assessing the system’s overall security posture”

    Auch wird der Vergleich zu #AWS und #GCP gezogen - dort wäre das Design auf die Anforderungen angepasst, Microsoft hätte einfach bestehendes irgendwie zurechtgegaffat.

    Wurde nach politischem Druck natürlich trotzdem für geheime Dokumente zugelassen.

    propublica.org/article/microso

    #azure #microsoft #microslop #FedRAMP

  8. A rather technical deep dive into verification systems run by #Persona, followed by some interesting questions that deserve answers.

    Persona seems to use the same code base for a #KYC system that verifies potential customers that want to sign up with #OpenAI to use GPT-5; as well as for another system that does #FedRAMP security assessments for #US government agencies (including automated notifications of agencies in special cases).

    (Read "0x11 - the architecture" first)

    vmfunc.re/blog/persona/

    via @raptor

    #security #privacy #ageverification

  9. When you wake up and you see a new message in the (cancelled) `#fedramp-[project name]` channel 😱

  10. Plans, Policies, and Procedures: FedRAMP
    A government program that provides a standardized approach to security assessment, and continuous monitoring for cloud products and services used by federal agencies.

    blackcatwhitehatsecurity.com

    #FedRAMP #Governance #Risk #Compliance #Programming

  11. Imagine getting enterprise-grade container security without the enterprise price tag. Docker’s new catalog offers rapid 7-day patches, vetted by experts and even FedRAMP-ready—perfect for startups looking to level up their defense. Curious how?

    thedefendopsdiaries.com/docker

    #dockersecurity
    #containersecurity
    #smallbusiness
    #hardenedimages
    #cybersecurity
    #fedramp
    #devsecops
    #vulnerabilitymanagement
    #cloudsecurity

  12. 🚀 NEW on We ❤️ Open Source 🚀

    Compliance = growth? You bet. benny Vasquez (@benny) explores how standards like FIPS and FedRAMP are powering open source adoption by building trust, attracting innovators, and proving reliability.

    allthingsopen.org/articles/com

    #WeLoveOpenSource #OpenSource #Compliance #FOSS #FedRAMP #Linux