Government  Health IT
TwitterFacebookLinkedIn
  • Home
  • Topics
    • Cloud Computing
    • Election 2012
    • Electronic Health Record
    • ePrescribing
    • Health Information Exchange (HIE)
    • Meaningful Use
    • Medicaid
    • Medicare
    • Military Health
    • Mobile/ Wireless
    • NHIN
    • Policy & Legislation
    • Population Health
    • Privacy and Security
    • Quality and Safety
    • Telehealth
    • Workforce Management
  • Issues
    • Sept/Oct 2011
    • July/August 2011
    • May/June 2011
    • March/April 2011
    • Jan/Feb 2011
    • Nov/Dec 2010
  • Webinars
    • Upcoming Webinars
    • On Demand Webinars
  • White Papers
  • Blog
  • Events
  • Jobs
  • RSS
  • Slideshows
  • Videos
  • Podcasts
  • Newsletters
  • Advertise
  • LOGIN
  • REGISTER
  • SUBSCRIBE
Home » News » Cloud Computing | Privacy and Security
Receive News
By Email

  • del.icio.us
  • Digg
  • Facebook
  • Google
  • Reddit
  • StumbleUpon
  • RSS Icon
  

Tweet

NASCIO's 12 tips to states considering the cloud

May 15, 2012 | Kate Spies, Contributing Writer

Suggested Content

  • IDC's 5 stages to ACO maturity
  • Will it cost more to close fed datacenters than agencies save?
  • HIMSS network study shows IT challenges, priorities
  • Perspective: HIE, 'omics' and personalized medicine
  • Alongside meaningful use progress, survey finds obstacles remain
  • 5 reasons to consider clinical analytics
  • KLAS Top 5 cloud concerns of non-users
  • 5 steps to managing data security risks in the cloud

Related Resources

  • Cloud Services Leverage Provider IT Resources and Ensure Continued Service Levels
  • Securing Mobile Devices in the Business Environment
  • Sizing Up Your Cloud Options - Is Now the Time?
  • Futureproofing Healthcare with Converged Medical Infrastructure
  • Key Benefits to a Secure & Elastic Private Cloud

For state CIOs, leveraging cloud technology has the potential to optimize system efficiency, reduce costs, and enhance service delivery. The journey to joining the cloud, however, is not without issue; acclimating demands the careful consideration and involvement of state CIOs.

To that end, the National Association of State Chief Information Officers (NASCIO) recently released a report on the issues related to cloud privacy and security.

“The general state approach to cloud adoption has been in the development of private cloud solutions and in the migration to enterprise email solutions in both private and public cloud scenarios,” NASCIO explained in the report. “In these initiatives, states are learning from each other.”

[Related: NIST's 10 cloud computing requirements.]

Beyond this state-to-state collaboration, individual agencies within the state infrastructure are aligning as cloud computing is examined. “All of this activity is converging on a developing government strategy for maturing and harvesting the value of cloud computing,” according to NASCIO.

To clarify this strategy, NASCIO outlined twelve recommendations for state CIOs as they maneuver onto the cloud. State leaders must:

  1. Mobilize internal support for cloud adoption through education and awareness, while clearly articulating the new security and privacy risks
  2. Weigh the benefits and risks of cloud computing in terms of cost versus security and privacy concerns
  3. Continue to temper expectations about savings opportunities and to examine risks and requirements
  4. Educate policy makers on the differences between consumer cloud requirements versus the industrial-strength requirements of state government
  5. Examine the state’s standard terms and conditions for procurement and consider modifications to address cloud computing
  6. Communicate and educate government officials on the terms of service presented and assumed for third-party cloud services
  7. Start with a private cloud solution first where state data is highly sensitive; this will ensure protection early in the adoption process of cloud technology
  8. Develop an enterprise security policy that controls unauthorized use of cloud services while enabling legitimate business needs
  9. Continually scan network traffic to uncover the use of unauthorized cloud services; work to determine the reasons for non-compliance and the use of unauthorized cloud services
  10. Consider a cloud broker approach: develop roles specific for cloud management, like “broker” and “service portfolio manager” to enhance security and efficiency
  11. Work with the federal government to develop common interpretation of security requirements so that comprehensive cloud requirements can be identified and relied upon
  12. Stay tuned to the Federal Risk and Authorization Management Program (FedRAMP) as it evolves and leverages approved vendors; the program will provide a list of approved cloud providers for beginning states

The FedRAMP program referenced in the final tip is headed by the Office of Management and Budget. FedRAMP “provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services,” according to NASCIO’s report.

[Related: Mitigating PHI danger in the cloud.]

Beyond maintaining an awareness of FedRAMP, NASCIO urged states to practice an overall consciousness of the changing requirements and lessons related to the cloud adoption process.

“This report has provided a discussion of some of the issues regarding cloud security and privacy,” NASCIO explained. “The discussion will continue going forward as new lessons are learned and new requirements arrive.”
 

Related Topics:
  • Online Only
  • Cloud Computing
  • Privacy and Security
  • computing
  • Office of Management and Budget

Reader Comments (1)Login to Post a Comment

groenpj says: Open Source Cloud Solutions
May 15, 2012 | 4:01PM GMT
Additional guidance for NASCIO and its members would be to seriously look at using the highly popular open source cloud computing solutions like OpenStack, OpenNebula, Cloudstack, Hadoop, and Eucalyptus.

Most Popular

Latest Headlines
Most Popular
  • Why modernizing state IT infrastructures is crucial for HIX
  • Report: HIT market will swell to $56B by 2017
  • OIG lets state Medicaid fraud units use federal funds for analytics
  • ONC launches cancer care app challenge
  • $1M grant bringing HIE to rural CA providers
  • 10 health reform benefits at risk in the election
  • Would Romney kill meaningful use?
  • CMS circulates final 2014 MU clinical quality measures
  • HIE is critical public utility in Sandy disaster
  • HIMSS: The intangibles of HIT employee retention
more news

WEBINARS AND WHITE PAPERS

  • WHITE PAPERS
    Enterprise-class API Patterns for Cloud & Mobile
  • WHITE PAPERS
    HIE Interoperability case study: Health-e-cITi-NJ
  • WHITE PAPERS
    Cloud Computing in the Healthcare Environment
  • WHITE PAPERS
    Your Cloud in Healthcare - How to Use the Cloud to Achieve Greater Business Agility
  • WHITE PAPERS
    The VNA Strategy: Balancing Workflow and Enterprise Imaging Management
More Resources
Syndicate content

HIMSS JOBMINE

  • Director of Clinical Applications - MidMichigan Health - Midland, MI
  • Information Services Director - Central Peninsula Hospital - Soldotna, AK
  • Director, Marketing and Business Development - Vermont Information Technology Leaders, Inc. - Burlington, VT
  • CIO - Bend Memorial Clinic - Bend, Oregon
  • Director of Clinical Transformation - Agnesian Healthcare - Fond du Lac, WI
more jobs
receive news by email

Marketplace

  • Home
  • Resource Central
  • Blog
  • Events
  • Jobs
  • Mobile Site
  • Advertise
  • RSS
  • About
  • Site map
  • Privacy Policy
Follow Government Health IT on TwitterLike Government Health IT on FacebookJoin Government Health IT on LinkedInRSS Subscriptions
BlogEvents
JobsMobile SiteMobile App
 
Healthcare IT NewsHealthcare Finance NewsHealthcare Payer NewsHIEWatch ICD10Watch mHIMSS PhysBizTech
©2013 MedTech Media Government Health IT is a publication of MedTech Media
Advertise About Us Privacy Policy