Driving cybersecurity and digital transformation with cloud technologies

Aishwarya Patil
4 min readDec 13, 2020

Commercial cloud computing systems offer an entire set of computing, safety, governance and compliance offerings which might be supported through standardized and externally licensed techniques and procedures. AWS has invested in acquiring numerous extensively used accreditations which includes FedRAMP, SOC-2, ISO 27001 and lots of extra.

FIG 1 CLOUD SECURITY

Further, cloud carrier carriers like Amazon Web Services (AWS) have study control and operations techniques to assist guard virtual belongings and permit agencies to innovate. All those investments make it less complicated for public zone and controlled markets to leverage those present offerings to enhance the safety posture rapidly.

Large US authorities groups — including US Treasury, Food and Drug Administration (FDA), GSA and NASA, amongst others — have efficiently carried out transformation applications primarily based totally on permitted cloud offerings. State groups just like the District of Columbia’s Health Benefits Exchanges (DC-HBX) have additionally followed cloud-primarily based totally virtual transformation offerings to now no longer best supply fitness advantages coverage offerings to residents in their state, however additionally pioneered a shared offerings transport version with different states which includes the State of Massachusetts to supply efficiencies.

All those applications have a few not unusual place styles and procedures which might be critical for public groups trying to rework and modernize thru cloud technologies. Any cloud initiative need to have truly described desires and objectives. Public zone agencies have an pressing want to fill their safety backlog and maintain to supply citizen dealing with offerings with scarce assets and constrained budgets. These elements make cloud-primarily based totally answers a great transformation platform.

Establish a digital transformation tiger team

Given the complexity and paradigm change, it’s far vital to set up a virtual transformation workplace staffed with influenced and certified specialists with hands-on transport experience. Some of the extra a hit examples of such agencies encompass GSA’s 18F, Treasury’s Treasury Digital Service, and Defense Digital Service (DDS) among others.

Smaller agencies just like the DC-HBX distinct an empowered technical crew to pursue cloud-primarily based totally modernization techniques. The Digital Transformation crew establishes the infrastructure to assist jumpstart the modernization adventure. The composition of the virtual crew is important — it need to encompass technologists, commercial enterprise concern count number specialists and safety experts to make sure that compliance and safety necessities may be met.

Governance, strategy and shared services

A vital element to making sure the monetary advantages of adopting cloud systems is the adoption of a Shared Services-primarily based totally Consumption Model. The layout of a Shared Services primarily based totally governance and cloud adoption framework permits for extra safety and decreasing of the general fee of operations. There is a superb deal of pliability and fashions to pick from (e.g., the District of Columbia’s Health Benefits

Exchange and the State of Massachusetts partnered as much as supply fitness advantages coverage through the use of a not unusual place AWS-primarily based totally cloud platform). This helped fund the improvement and operations of the general platform. Other agencies just like the US Treasury evolved their very own cloud-primarily based totally platform referred to as Workplace.gov Community Cloud (WC2) to supply FedRAMP permitted cloud offerings to different workplaces and bureau’s. The cap potential to provide cloud-answers primarily based totally on a shared offerings transport version permits for fee sharing, reduces duplication and hurries up the transport of answers.

FIG 2 CHALLENGES OF DATA GOVERNANCE IN MULTI CLOUD WORLD

Digital innovation lab and accelerator

Most a hit cloud modernization projects are excessive on code, actionable examples, and fast trouble solving. Creating a virtual innovation lab and accelerator with well-hooked up templates, layout guard-rails and documented quality practices is vital for success. Organizations that embark on a cloud modernization adventure need to make it easy, actionable and offer get entry to to self-carrier equipment that supply fast outcomes.

I even have had the possibility to help some of US federal and public-zone agencies layout, expand and install such answers. The Digital Innovation Lab is ready to assist the employer solution the maximum not unusual place questions including — is my utility prepared to transport to the cloud? Should we use IaaS, PaaS or SaaS? What is the anticipated fee to function with inside the cloud? How are we able to quick take a look at or examine cloud-answers? How will we steady our programs and facts with inside the cloud?

Many agencies create useful virtual equipment like a Cloud Readiness Assessment or Cloud Decision Tree that captures quality practices and supplies fast solutions the use of automation thereby rushing up the process. Developing such equipment additionally creates virtual belongings that may be leveraged throughout the employer. Once a surely useful and usable Digital Innovation Lab/Showcase has been evolved, we then are prepared to embark at the very last step.

Deliver the solution as a ‘product’

Successful cloud modernization and transformation efforts want sturdy and powerful communications techniques to force change. One of the best equipment I even have visible is the cap potential to emblem the cloud application or assignment into a “product.” This consists of giving it a call and organizing a brand in addition to defining product features, advantages and a product website.

Organizations like US Treasury have efficiently executed that with their cloud modernization effort calling it Workplace.gov Community Cloud (WC2). Similarly, GSA has efficiently hooked up agencies like 18F for turning in virtual consulting offerings and created the catchy Cloud.gov carrier. Using a tested playbook that has efficiently labored for different public-zone agencies can assist lessen the studying curve and presents blueprints that may be leveraged and delicate to enhance cybersecurity posture and supply new offerings the use of cloud offerings.

--

--