ReadWriteCloud

Amazon Adds FISMA Moderate Authorization and Accreditation

Amazon continues to woo government agencies for their cloud business. The company announced today that it has achieved Federal Information Security Management Act (FISMA) Moderate authorization and accreditation from the General Services Administration (GSA).

The FISMA accreditation covers three Amazon services: Elastic Compute Cloud (EC2), Simple Storage Service (S3) and Virtual Private Cloud (VPC). What does this mean?

According to the AWS info page on the accreditation, it covers an "extensive set of security configuration and controls" along with requirements to document management, operational, and "technical prowess" to secure the physical and virtual infrastructure. It also requires third party audits.

FISMA certification might sound like a pretty dull topic, but it's enough to get providers like Google and Microsoft into a spat. AWS joins Google App Engine and Microsoft's Business Productivity Online Services (BPOS), which also have FISMA Moderate accreditation.

In addition to FISMA, AWS has PCI DSS Level 1, FIPS 140-2, ISO 27001, and SAS-70 type II. See the NIST page on FISMA for more information about the act.


ReadWriteWeb encourages comments, but please remember: Keep it nice, keep it clean, and avoid promotional comments. We do pre-moderate some comments with links. For more information, please read our full comment policy.
blog comments powered by Disqus
Recommended Story
RWW SPONSORS



RWW PARTNERS