Computing Reviews
Today's Issue Hot Topics Search Browse Recommended My Account Log In
Review Help
Search
Federal cloud computing : the definitive guide for cloud service providers (2nd ed.)
Metheny M., Syngress Publishing, Cambridge, MA, 2017. 536 pp. Type: Book (978-0-128097-10-6)
Date Reviewed: Jul 23 2018

The title indicates that this is a guide for cloud service providers (CSPs) who deal with the US government; however, many of the sections will not be of interest to this audience. All of the many references are to government documents. Although the research and professional literature on clouds is abundant, the author seems to know only government sources. This lack of cloud “culture” makes the author confuse standards with mechanisms to comply with these standards. Surprisingly, the extensive list of standards does not include important ones such as open virtualization format (OVF) and OpenStack. The discussion of vulnerability testing does not even mention catalogs such as the Open Web Application Security Project (OWASP) and Common Vulnerabilities and Exposures (CVE). Long lists enumerate standards, defenses, vulnerabilities, and other items. These lists are not based on any conceptual model; related terms are collected together, but no logical or conceptual reason as to why is given.

The book contains several sections about the history of governmental software systems, showing how they led to clouds. Again, I doubt this is interesting to the intended audience. The book also suffers from provincialism: nothing done outside the government matters. Although the National Institute of Standards and Technology (NIST) cloud reference architecture (RA) is discussed, the chapter on security does not relate RA to its topic. Again, security is reduced to a list of recommendations, with no attempt at a conceptual model. NIST published a cloud security reference architecture (SRA) that should be used as a reference for security.

A couple of good chapters on risk management relate risks to the federal enterprise architecture (although not to the NIST SRA). Compliance with regulations, risk management, architecture, and security are treated as disjointed aspects, without any conceptual relationship. There is a good mapping of federal policies to International Organization for Standardization (ISO) standards. The Federal Risk and Authorization Management Program (FedRAMP) cloud security requirements are well described, repeating much of the earlier material--again, without a conceptual model.

The book contains an enormous amount of information, a good part of it valuable; regretfully, it is not organized in a conceptually coherent way, which makes using this knowledge much harder than is necessary. The government’s objectives when it comes to the cloud look well planned, but I am afraid that implementing them will be difficult. Some recent breaches indicate that they are still not there [1].

More reviews about this item: Amazon

Reviewer:  E. B. Fernandez Review #: CR146166 (1810-0525)
1) Lord, N. Top 10 biggest government data breaches of all time in the US. Digital Guardian Data Insider blog, https://digitalguardian.com/blog/top-10-biggest-us-government-data-breaches-all-time (accessed 07/19/2018).
Bookmark and Share
  Reviewer Selected
Featured Reviewer
 
 
Distributed Systems (C.2.4 )
 
 
Distributed Systems (H.3.4 ... )
 
 
Reference (A.2 )
 
Would you recommend this review?
yes
no
Other reviews under "Distributed Systems": Date
The evolution of a distributed processing network
Franz L., Sen A., Rakes T. Information and Management 7(5): 263-272, 1984. Type: Article
Jul 1 1985
A geographically distributed multi-microprocessor system
Angioletti W., D’Hondt T., Tiberghien J.  Concurrent languages in distributed systems: hardware supported implementation (, Bristol, UK,871985. Type: Proceedings
Oct 1 1985
A fault tolerant LAN with integrated storage, as part of a distributed computing system
Boogaard H., Bruins T., Vree W., Reijns G.  Concurrent languages in distributed systems: hardware supported implementation (, Bristol, UK,1001985. Type: Proceedings
Aug 1 1985
more...

E-Mail This Printer-Friendly
Send Your Comments
Contact Us
Reproduction in whole or in part without permission is prohibited.   Copyright 1999-2024 ThinkLoud®
Terms of Use
| Privacy Policy