Welcome!

Government Cloud Authors: Elizabeth White, Liz McMillan, Pat Romanski, Dana Gardner, Gopala Krishna Behara

Related Topics: @CloudExpo, Microservices Expo, Containers Expo Blog, Agile Computing, Cloud Security, Government Cloud

@CloudExpo: Blog Feed Post

Government SaaS Entrepreneur

What are these high security standards, where and how are they defined?

As the name suggests our Government SaaS Entrepreneur program tailors their venture accelerator for apps for the public sector.

Examples of apps that have already gone through this process include Huddle IL3, referring to it being suitable for the UK’s information security classification IL3. This has resulted in the Huddle app grabbing the lions share of the G-Cloud market.

In this interview with Dave Nicholl, CIO for Ontario Province, talks about how they would consider this type of service for key requirements like their Drivers Licence applications, with a critical point about security:

“Typically, software as a service providers don’t create applications tailored for governments, he said. That said, “if we could find a drivers [licence] system that was software as a service we’d absolutely look at it,” he added – if it had adequate security.”

Secure Government SaaS – Specifications

So what are these high security standards, where and how are they defined?

This is the purpose of our new OASIS open standards group, called PACR, read more here in the launch briefing. This encompasses:

  • Cloud Security Alliance best practices - The CSA provides a comprehensive framework for securing Cloud environments, the backbone of which is the use of encryption at different levels: Encrypting VMs, data at rest and also in transit from the Cloud to the corporate data centre.
  • Cloud Identity Ecosystem - In the USA the NSTIC experts are pioneering the ‘Identity Ecosystem‘, where online service access is streamlined for citizens through “Social sign-on”. Microsoft provides a thorough expanation of how Government can apply these principles and technologies in this PPT presentation (42-page PDF)
  • Cloud Archiving and Compliance – A critical piece for governments is the Cloud Providers ability to meet their compliance needs. In line with standards like ISO 27037 this encompasses being able to verify digital evidence-ready record keeping, implementing litigation holds, maintaining an always-on irrefutable record of all transactions and other chain-of-custody features required for e-discovery.

Service Innovation and Solution Accelerators

The above technical capabilities are enabled by an ecosystem of vendor partners offering new technology products, that can be adopted by Cloud Providers and integrated into their environments to achieve a Government Secure SaaS platform.

This opens up opportunities for new service innovations, which can be pre-packaged into Solution Accelerators that helps entrepreneurs fast-track their venture

Guardtime – Keyless Signatures

This solution development process provides a context for the innovations that our Vendor partners are creating.

For example Guardtime has invented ‘Keyless Signatures’ that can play a major role in securing the integrity of information, the fundamental requirement for legally admissible materials.

It can be built into Cloud environments, as described here, and enable a variety of new services relevant to government. For example cMail, for Certified Email, that could be used for financial transactions through to doctors eReferals.

Read the original blog entry...

More Stories By Cloud Best Practices Network

The Cloud Best Practices Network is an expert community of leading Cloud pioneers. Follow our best practice blogs at http://CloudBestPractices.net

IoT & Smart Cities Stories
At CloudEXPO Silicon Valley, June 24-26, 2019, Digital Transformation (DX) is a major focus with expanded DevOpsSUMMIT and FinTechEXPO programs within the DXWorldEXPO agenda. Successful transformation requires a laser focus on being data-driven and on using all the tools available that enable transformation if they plan to survive over the long term. A total of 88% of Fortune 500 companies from a generation ago are now out of business. Only 12% still survive. Similar percentages are found throug...
Every organization is facing their own Digital Transformation as they attempt to stay ahead of the competition, or worse, just keep up. Each new opportunity, whether embracing machine learning, IoT, or a cloud migration, seems to bring new development, deployment, and management models. The results are more diverse and federated computing models than any time in our history.
At CloudEXPO Silicon Valley, June 24-26, 2019, Digital Transformation (DX) is a major focus with expanded DevOpsSUMMIT and FinTechEXPO programs within the DXWorldEXPO agenda. Successful transformation requires a laser focus on being data-driven and on using all the tools available that enable transformation if they plan to survive over the long term. A total of 88% of Fortune 500 companies from a generation ago are now out of business. Only 12% still survive. Similar percentages are found throug...
Dion Hinchcliffe is an internationally recognized digital expert, bestselling book author, frequent keynote speaker, analyst, futurist, and transformation expert based in Washington, DC. He is currently Chief Strategy Officer at the industry-leading digital strategy and online community solutions firm, 7Summits.
Digital Transformation is much more than a buzzword. The radical shift to digital mechanisms for almost every process is evident across all industries and verticals. This is often especially true in financial services, where the legacy environment is many times unable to keep up with the rapidly shifting demands of the consumer. The constant pressure to provide complete, omnichannel delivery of customer-facing solutions to meet both regulatory and customer demands is putting enormous pressure on...
IoT is rapidly becoming mainstream as more and more investments are made into the platforms and technology. As this movement continues to expand and gain momentum it creates a massive wall of noise that can be difficult to sift through. Unfortunately, this inevitably makes IoT less approachable for people to get started with and can hamper efforts to integrate this key technology into your own portfolio. There are so many connected products already in place today with many hundreds more on the h...
The standardization of container runtimes and images has sparked the creation of an almost overwhelming number of new open source projects that build on and otherwise work with these specifications. Of course, there's Kubernetes, which orchestrates and manages collections of containers. It was one of the first and best-known examples of projects that make containers truly useful for production use. However, more recently, the container ecosystem has truly exploded. A service mesh like Istio addr...
Digital Transformation: Preparing Cloud & IoT Security for the Age of Artificial Intelligence. As automation and artificial intelligence (AI) power solution development and delivery, many businesses need to build backend cloud capabilities. Well-poised organizations, marketing smart devices with AI and BlockChain capabilities prepare to refine compliance and regulatory capabilities in 2018. Volumes of health, financial, technical and privacy data, along with tightening compliance requirements by...
Charles Araujo is an industry analyst, internationally recognized authority on the Digital Enterprise and author of The Quantum Age of IT: Why Everything You Know About IT is About to Change. As Principal Analyst with Intellyx, he writes, speaks and advises organizations on how to navigate through this time of disruption. He is also the founder of The Institute for Digital Transformation and a sought after keynote speaker. He has been a regular contributor to both InformationWeek and CIO Insight...
Andrew Keys is Co-Founder of ConsenSys Enterprise. He comes to ConsenSys Enterprise with capital markets, technology and entrepreneurial experience. Previously, he worked for UBS investment bank in equities analysis. Later, he was responsible for the creation and distribution of life settlement products to hedge funds and investment banks. After, he co-founded a revenue cycle management company where he learned about Bitcoin and eventually Ethereal. Andrew's role at ConsenSys Enterprise is a mul...