Artwork

Contenuto fornito da The Oakmont Group and John Gilroy. Tutti i contenuti dei podcast, inclusi episodi, grafica e descrizioni dei podcast, vengono caricati e forniti direttamente da The Oakmont Group and John Gilroy o dal partner della piattaforma podcast. Se ritieni che qualcuno stia utilizzando la tua opera protetta da copyright senza la tua autorizzazione, puoi seguire la procedura descritta qui https://it.player.fm/legal.
Player FM - App Podcast
Vai offline con l'app Player FM !

Ep. 180 Keys to Success in FedRAMP

23:47
 
Condividi
 

Manage episode 447074272 series 3610832
Contenuto fornito da The Oakmont Group and John Gilroy. Tutti i contenuti dei podcast, inclusi episodi, grafica e descrizioni dei podcast, vengono caricati e forniti direttamente da The Oakmont Group and John Gilroy o dal partner della piattaforma podcast. Se ritieni che qualcuno stia utilizzando la tua opera protetta da copyright senza la tua autorizzazione, puoi seguire la procedura descritta qui https://it.player.fm/legal.

https://content.leadquizzes.com/lp/fk1JL_FgeQ

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

FedRAMP was launched fourteen years ago; today we get an update on metrics and use cases to help companies considering certification.

James Leach has been immersed in the world of FedRAMP since the beginning. Today, he gives listeners insight on navigating the FedRAMP compliance process.

Commercial companies understand, in detail, the business problem they can solve. For some reason, when it comes to the federal government, they think they can “copy and paste” a business case and have it resonate.

When they apply, they may reference a single-threaded business case without federal business. Or they may promote an on-premises model and not include a cloud reference. Finally, organizations may dive into a hybrid cloud environment where it is a challenge to get sponsors.

First, one must do business with an agency and understand their requirements in detail; they will have different priorities from a regular “for profit” company. You will also need an agency to sponsor your application.

Once these basic hurdles are achieved, then one can begin to study cloud reference architecture. During the interview, James Leach gave several guidelines.

>> You need to understand FedRAMP more as a maturity model than a checklist for compliance.

>> You need to understand the controls but, more importantly, how the mandates are implemented.

Commercial companies can expend considerable resources to achieve FedRAMP certification, only to get frustrated in the end. FedRAMP is not a walk in the park and must be taken seriously.

  continue reading

218 episodi

Artwork
iconCondividi
 
Manage episode 447074272 series 3610832
Contenuto fornito da The Oakmont Group and John Gilroy. Tutti i contenuti dei podcast, inclusi episodi, grafica e descrizioni dei podcast, vengono caricati e forniti direttamente da The Oakmont Group and John Gilroy o dal partner della piattaforma podcast. Se ritieni che qualcuno stia utilizzando la tua opera protetta da copyright senza la tua autorizzazione, puoi seguire la procedura descritta qui https://it.player.fm/legal.

https://content.leadquizzes.com/lp/fk1JL_FgeQ

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

FedRAMP was launched fourteen years ago; today we get an update on metrics and use cases to help companies considering certification.

James Leach has been immersed in the world of FedRAMP since the beginning. Today, he gives listeners insight on navigating the FedRAMP compliance process.

Commercial companies understand, in detail, the business problem they can solve. For some reason, when it comes to the federal government, they think they can “copy and paste” a business case and have it resonate.

When they apply, they may reference a single-threaded business case without federal business. Or they may promote an on-premises model and not include a cloud reference. Finally, organizations may dive into a hybrid cloud environment where it is a challenge to get sponsors.

First, one must do business with an agency and understand their requirements in detail; they will have different priorities from a regular “for profit” company. You will also need an agency to sponsor your application.

Once these basic hurdles are achieved, then one can begin to study cloud reference architecture. During the interview, James Leach gave several guidelines.

>> You need to understand FedRAMP more as a maturity model than a checklist for compliance.

>> You need to understand the controls but, more importantly, how the mandates are implemented.

Commercial companies can expend considerable resources to achieve FedRAMP certification, only to get frustrated in the end. FedRAMP is not a walk in the park and must be taken seriously.

  continue reading

218 episodi

All episodes

×
 
Loading …

Benvenuto su Player FM!

Player FM ricerca sul web podcast di alta qualità che tu possa goderti adesso. È la migliore app di podcast e funziona su Android, iPhone e web. Registrati per sincronizzare le iscrizioni su tutti i tuoi dispositivi.

 

Guida rapida

Ascolta questo spettacolo mentre esplori
Riproduci