ombegov / cloud.cio.gov

Federal Cloud Computing Strategy Website
Other
13 stars 6 forks source link

Comments re: Cloud Smart / Use Case? #2

Open etc31265 opened 5 years ago

etc31265 commented 5 years ago

My Personal Comments / Experience Our Agency has been using Cloud Email for about a year and a half +. I am speaking as someone who sees the user’s issues daily. There have been many frustrations to include, but not limited to: • Email Latency • The Workforce that Manages the TIC / Monitoring Tools to the Cloud • Data Loss Prevention Issues (DLP) (sensitive email getting out) • SPAM Issues (the legit email doesn’t get out or in) • Outlook Client Performance Issues (Online Mode vs Cache Mode) The responses to these issues are classics: • Don’t treat this as a critical system, and in the same breath, we need to implement Records Management Retention policy in the same system • Your data could be stored in any cloud data center • There is no Service Level Agreement (SLA) in place My Comments re: Cloud Smart The points you have made in the document are spot on and the CIO Council Actions should help to resolve most issues and help us to make progress towards greater maturity. I pulled these sentences from the document that jumped out at me. One way in which adoptions fail is when organizations buy solutions without proper identification of requirements and intended outcomes. To accelerate cloud adoption, agencies should be expected to regularly evaluate their current state of maturity across the agency. Additionally, it is critical that agencies have comprehensive visibility of their data, both on-premises and in the cloud, and perform continuous monitoring in order to detect malicious activity.
However, with this update, agencies will need to think in terms of intended outcomes and capabilities, not merely programs, in approaching security holistically. Additionally, where a cloud solution is deployed by a vendor, a Service Level Agreement (SLA) should be in place that provides the agency with continuous awareness of the confidentiality, security, and availability of its data. I guess my comments could be considered an example of a Use Case and a general framework. My comments cover / focus on identification of the requirements / the outcomes / the procurement / service level agreement / deployment and continuous evaluation. Can I get dedicated servers / infrastructure for my Agency? Where are your data centers located? I would like my users strategical placed in data centers that are closest to them. Can you provide me with best practices for running Email Management Center on government side (TIC / EINSTEIN / IronPort / DMARC / Monitoring Tools)? Do you have a IDIQ / contract vehicle with qualified contractors / vendors that can run my Email Management Center? Can you provide have a portal / a dashboard so that I can see the status of the service that you are providing my Agency? I want a direct line to the service provider. I want contacts assigned to my Agency.