cloud-gov / product

Program-level artifacts, workflow and issues for cloud.gov
Creative Commons Zero v1.0 Universal
29 stars 15 forks source link

Fearless Zero Trust effort (Discovery Phase 100% Complete) #2849

Closed seanmbazemore closed 5 months ago

seanmbazemore commented 6 months ago

In order to advance cloud.gov's alignment with Cybersecurity and Infrastructure Security Agency (CISA ) Zero Trust maturity, we (cloud.gov) have contracted Fearless to assist with documenting the current baseline of the cloud.gov architecture, processes, and security; and investigate applicable laws, regulation, and guidance cloud.gov must comply with. In order to perform the next phase (gap analysis) this discovery phase must occur. Once the Gap analysis is performed with analysis of alternatives, Fearless will present possible solutions to address the 6 different objectives in the Fearless performance work statement (PWS).


Security considerations

Need to ensure as Fearless is given proper access to cloud.gov to perform work but access at this point that they may not modify anything.