{"id":14841,"date":"2024-05-20T10:58:25","date_gmt":"2024-05-20T13:58:25","guid":{"rendered":"https:\/\/www.fie.undef.edu.ar\/ceptm\/?p=14841"},"modified":"2024-05-20T10:58:25","modified_gmt":"2024-05-20T13:58:25","slug":"ee-uu-impulsa-una-guia-de-reciprocidad-para-la-computacion-en-la-nube-en-el-borrador-del-lenguaje-ndaa","status":"publish","type":"post","link":"https:\/\/www.fie.undef.edu.ar\/ceptm\/?p=14841","title":{"rendered":"EE.UU. impulsa una gu\u00eda de reciprocidad para la computaci\u00f3n en la nube en el borrador del lenguaje NDAA"},"content":{"rendered":"<p>La legislaci\u00f3n propone que si una oficina del departamento considera oficialmente que una &#8220;plataforma, servicio o aplicaci\u00f3n basada en la nube&#8221; es lo suficientemente cibersegura para su uso, entonces todas las partes del Departamento de Defensa pueden aceptar esta ATO (Autoridad para operar).El subcomit\u00e9 de Servicios Armados de la C\u00e1mara de Representantes sobre cibern\u00e9tica, tecnolog\u00edas de la informaci\u00f3n e innovaci\u00f3n emiti\u00f3 el lunes una gu\u00eda de ciberseguridad que exige reciprocidad en los sistemas de computaci\u00f3n en la nube, presionando al Pent\u00e1gono para simplificar los procedimientos de autorizaci\u00f3n para operar, a menudo duplicados.<\/p>\n<hr \/>\n<p>WASHINGTON \u2014\u00a0The House Armed Services subcommittee on cyber, information technologies and innovation issued\u00a0<a href=\"https:\/\/docs.house.gov\/meetings\/AS\/AS00\/20240522\/117296\/BILLS-118HR8070ih-CITI.pdf\" target=\"_blank\" rel=\"noopener\">cybersecurity guidance<\/a>\u00a0requiring reciprocity on cloud computing systems Monday, pushing the Pentagon to streamline often-duplicative Authorization To Operate procedures.<\/p>\n<p>In the draft 2025 National Defense Authorization Act, the subcommittee wrote that no later than 270 days after the NDAA is implemented, the CIOs of the Army, Navy and Air Force Departments\u00a0should develop and implement a policy that enforces reciprocity for cloud computing.\u00a0In essence, if one office in the department officially deems that a\u00a0\u201ccloud-based platform, service, or application\u201d is sufficiently cybersecure to use, then all\u00a0parts of DoD can accept this \u201cAuthority To Operate\u201d (ATO) instead of having to redo the certification process.<\/p>\n<p>The idea is to eliminate redundant ATO processes, currently a major headache for both defense officials and IT contractors, who must prove a particular piece of software or hardware is secure over and over to different Authorizing Officers (AOs) with jurisdiction over different organizations, who often impose subtly different standards.<\/p>\n<p>This mandate\u00a0doesn\u2019t apply to non-cloud \u201con premise\u201d systems, which remain a large percentage of the DoD network, albeit an ever-dwindling one.<\/p>\n<p>The draft language released Monday proposes that before\u00a0approving or denying a request for authorization to operate a cloud-based platform, service or application, military department AOs must consult with the current or planned mission owners of that platform, service or application. This means that the AO from one department or office should comply with what other AOs decided when determining if a cloud computing system is cybersecure.<\/p>\n<p>Other guidance in the draft proposes that AOs shall provide documentation that is accessible and comprehensible to \u201crelevant stakeholders.\u201d Additionally, a system that compiles and shares the documentation \u201cof cloud-based platforms, services, and applications between mission owners and system owners\u201d should be developed.<\/p>\n<p>HASC\u2019s proposal of reciprocity comes after the Pentagon released cybersecurity guidance also enforcing reciprocity last week, which was not specific to only cloud computing systems.<\/p>\n<p>The plan,\u00a0<a href=\"https:\/\/dodcio.defense.gov\/Portals\/0\/Documents\/ResolvingRMF.pdf?ver=oqiQ5Io-gyI%3d\" target=\"_blank\" rel=\"noopener\">according to a one-pager<\/a>\u00a0signed by Deputy Defense Secretary Kathleen Hicks, formally titled \u201cResolving Risk Management Framework and Cybersecurity Reciprocity Issues,\u201d states that the \u201cDepartment implements the Risk Management Framework (RMF), in accordance with DoD Instruction 8510.01, to guide how we build, field, and maintain cyber secure and survivable capabilities.\u201d<\/p>\n<p>Pentagon CIO John Sherman told the GEOINT audience that this move will assure \u201cthat folks don\u2019t have to check each other\u2019s homework over and over again,\u201d unless an official has \u201cbona fide reasons\u201d to perform rechecks.<\/p>\n<p>The full guidance has yet to be released by the Pentagon, however a representative from Sherman\u2019s office told Breaking Defense in an email that the full guidance will be released \u201cin the coming weeks.\u201d<\/p>\n<p>The HASC plans to mark up the FY25 NDAA on May 22.<\/p>\n<p><strong>Fuente:<\/strong> <a href=\"https:\/\/breakingdefense.com\/2024\/05\/house-subcommittee-pushes-for-reciprocity-guidance-for-cloud-computing-in-draft-ndaa-language\/\" target=\"_blank\" rel=\"noopener\"><em>https:\/\/breakingdefense.com<\/em><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>La legislaci\u00f3n propone que si una oficina del departamento considera oficialmente que una &#8220;plataforma, servicio o aplicaci\u00f3n basada en la nube&#8221; es lo suficientemente cibersegura&hellip; <\/p>\n","protected":false},"author":1,"featured_media":14842,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[2,23],"tags":[],"_links":{"self":[{"href":"https:\/\/www.fie.undef.edu.ar\/ceptm\/index.php?rest_route=\/wp\/v2\/posts\/14841"}],"collection":[{"href":"https:\/\/www.fie.undef.edu.ar\/ceptm\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.fie.undef.edu.ar\/ceptm\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.fie.undef.edu.ar\/ceptm\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.fie.undef.edu.ar\/ceptm\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=14841"}],"version-history":[{"count":1,"href":"https:\/\/www.fie.undef.edu.ar\/ceptm\/index.php?rest_route=\/wp\/v2\/posts\/14841\/revisions"}],"predecessor-version":[{"id":14843,"href":"https:\/\/www.fie.undef.edu.ar\/ceptm\/index.php?rest_route=\/wp\/v2\/posts\/14841\/revisions\/14843"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.fie.undef.edu.ar\/ceptm\/index.php?rest_route=\/wp\/v2\/media\/14842"}],"wp:attachment":[{"href":"https:\/\/www.fie.undef.edu.ar\/ceptm\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=14841"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.fie.undef.edu.ar\/ceptm\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=14841"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.fie.undef.edu.ar\/ceptm\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=14841"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}