cloud-gov / product

Program-level artifacts, workflow and issues for cloud.gov
Creative Commons Zero v1.0 Universal
29 stars 15 forks source link

Fearless Zero Trust effort (Gap Analysis Phase 50% Complete) #2850

Closed seanmbazemore closed 4 months ago

seanmbazemore commented 6 months ago

In order to advance cloud.gov's alignment with Cybersecurity and Infrastructure Security Agency (CISA ) Zero Trust maturity, we (cloud.gov) have contracted Fearless to assist with documenting the current baseline of the cloud.gov architecture, processes, and security; and investigate applicable laws, regulations, and guidance cloud.gov must comply with. This phase is the Gap Analysis and include analysis of alternatives which will tell cloud.gov where we are deficiency in compliance.

Fearless will present possible solutions to address the 6 different objectives in the Fearless performance work statement (PWS) based on these Gap Analysis.


Security considerations

Need to ensure as Fearless is given proper access to cloud.gov to perform work but access at this point that they may not modify anything.