Home / Companies / Box / Blog / April 2021

April 2021 Summaries

10 posts from Box

Filter
Month: Year:
Post Summaries Back to Blog
The Washington State Department of Health has adopted Box's cloud content management platform to enhance collaboration and information sharing amid the COVID-19 pandemic. This partnership aims to improve the department's ability to deliver timely information, manage incident responses, address environmental health hazards, and provide health and safety information, while also ensuring efficient communication among state agencies, local jurisdictions, and healthcare providers. Box's platform, which supports secure collaboration and real-time data access, has been recognized for its compliance with federal security standards, including FedRAMP and Department of Defense authorizations. This initiative places the Washington State Department of Health among other prominent organizations like the U.S. Department of the Air Force and the FDA that utilize Box to foster innovative and secure government operations.
Apr 29, 2021 301 words in the original blog post.
FedRAMP Tailored, introduced in August 2017, is a streamlined process designed to expedite the adoption of cloud services for low-risk use cases by minimizing the number of required security controls. This program specifically targets Low-Impact Software-as-a-Service (LI-SaaS), which demands compliance with a subset of the Low Impact baseline's 125 security controls, focusing only on the most relevant requirements. It allows vendors to leverage existing FedRAMP Authorized products to inherit security controls, making it easier and more cost-effective to achieve authorization. LI-SaaS is intended for applications that pose minimal risk to federal agencies if compromised and must not contain personally identifiable information beyond basic login credentials. The program offers a quicker pathway for vendors to enter the federal market by allowing them to first obtain LI-SaaS authorization as a stepping stone to higher levels of authorization. However, it is only suitable for low-risk applications, and the traditional FedRAMP process remains necessary for systems requiring Moderate or High impact categorizations. Since its inception, nearly 30 LI-SaaS FedRAMP Authorized applications have been launched, highlighting the program's potential to accelerate cloud adoption in the federal sector.
Apr 28, 2021 1,280 words in the original blog post.
FedRAMP's Agency Authorization to Operate (ATO) process is a crucial pathway for Cloud Service Providers (CSPs) seeking to offer their services to U.S. Federal Agencies, as agencies are required to purchase cloud products through the FedRAMP marketplace. The Agency ATO, distinct from the Joint Authorization Board (JAB) Provisional Authorization to Operate (P-ATO), is generally faster and involves direct collaboration between the CSP and a federal agency, without JAB's involvement but with a final review by the Program Management Office (PMO). This path is particularly suited for products with low impact or those categorized as LI-SaaS, especially when there is demand from one or two specific agencies. The process includes four phases: Partnership Establishment, Full Security Assessment, Authorization Process, and Continuous Monitoring, with an emphasis on leveraging existing FedRAMP Authorized infrastructures like AWS or Azure to streamline certification. While the Agency ATO grants the same FedRAMP Authorization status as a JAB P-ATO, it is tailored to a specific agency's needs, potentially requiring other agencies to conduct additional evaluations for adoption. Continuous monitoring and annual assessments are mandatory to maintain the authorization status, ensuring ongoing compliance with FedRAMP requirements.
Apr 28, 2021 1,486 words in the original blog post.
FedRAMP, or the Federal Risk and Authorization Management Program, is a crucial initiative that standardizes the security authorizations of cloud services for U.S. federal agencies, facilitating their adoption while ensuring security and reducing IT costs. Established under the Federal Information Security Management Act (FISMA), FedRAMP harmonizes security requirements across agencies, enabling them to leverage cloud technology through a unified process that involves a rigorous risk management framework developed by the National Institute for Standards and Technology (NIST). This framework outlines a series of phases—prepare, categorize, select, implement, assess, authorize, and monitor—that guide agencies and Cloud Service Providers (CSPs) in managing security and privacy risks. FedRAMP offers two primary paths for authorization: the Joint Authorization Board (JAB) Provisional Authorization to Operate (P-ATO) and the Agency Authorization to Operate (ATO), each catering to different types of cloud services and agency needs. The program is governed by entities like the JAB, FedRAMP Program Management Office (PMO), and the Department of Homeland Security (DHS), which collaboratively ensure compliance and facilitate the re-use of security packages across federal entities. The FedRAMP Marketplace serves as a central repository, listing all FedRAMP-authorized services and helping agencies and CSPs navigate the program's complex requirements.
Apr 27, 2021 5,910 words in the original blog post.
FedRAMP is a crucial program for Cloud Service Providers (CSPs) seeking to sell cloud services to U.S. Federal Agencies, requiring them to gain authorization through the FedRAMP marketplace. The Joint Authorization Board (JAB), comprising CIOs from the GSA, DoD, and DHS, is responsible for granting a limited number of Provisional Authorizations to Operate (P-ATO) each year, making it a competitive process that ensures products meet high security standards. To improve their chances, CSPs are advised to obtain the FedRAMP Ready status before applying, which demonstrates their preparation and commitment. The authorization process involves a detailed security assessment and continuous monitoring, coordinated by a third-party assessor (3PAO), and culminates in a JAB decision after an in-depth review. Although a JAB P-ATO opens significant market opportunities, each federal agency must conduct its own review before issuing its authorization, ensuring the product meets specific agency requirements.
Apr 27, 2021 1,315 words in the original blog post.
Information security, or infosec, is a key component of cybersecurity focused on safeguarding data through structured programs that include access control, employee training, and tailored data protection measures. Companies across various sectors, such as healthcare and finance, often require infosec programs, sometimes mandated by law, to manage personal or client data securely. Two principal methodologies for implementing infosec are the bottom-up approach, where responsibility lies with a designated expert or department, and the top-down approach, initiated by upper management, involving policy creation and strategic oversight. A layered approach to information security is advocated, covering web, network, device, application, and physical security, along with disaster recovery plans, to address potential vulnerabilities from diverse cyber threats. Businesses are encouraged to adopt cloud solutions for data storage to mitigate physical risks, while also ensuring ongoing employee engagement and training to combat the prevalent risks posed by negligence and third-party vendors. The process of establishing a robust infosec program includes setting clear objectives, planning for compliance with standards like ISO/IEC 27001, and maintaining dynamic, evolving security protocols that adapt to technological advancements and emerging threats.
Apr 20, 2021 1,110 words in the original blog post.
An information security policy is a critical framework for businesses to safeguard their data against threats like ransomware, which occurs every 14 seconds, by establishing a comprehensive set of rules and procedures applicable across all users and networks within an organization. This policy, essential for maintaining consumer trust and protecting against potential financial losses, should be practical, enforceable, and flexible enough to accommodate various departments' needs while ensuring compliance with privacy regulations like GDPR and HIPAA. The policy should encompass elements such as a defined purpose, audience and scope, information security objectives, authority and access control policies, data classification, data support operations, security awareness, and personnel responsibilities. Best practices include making the policy adaptable to technological changes, ensuring coordination between departments, developing a security incident response plan, and implementing acceptable use policies to prevent data breaches and maintain regulatory compliance.
Apr 19, 2021 1,197 words in the original blog post.
Information security and compliance are essential for safeguarding an organization's data and financial stability by managing risks and meeting industry standards. Information security focuses on protecting data through technical, physical, and administrative controls that ensure confidentiality, integrity, and availability, collectively known as the CIA triad. Compliance, on the other hand, involves adhering to external standards set by third parties, such as regulatory frameworks and contractual obligations, to mitigate legal and financial risks. While security is an ongoing effort to shield against technical threats, compliance is achieved when a company meets predefined standards, though it must be continuously maintained. Both disciplines are interdependent, as a robust security system requires compliance to validate its efficacy, while compliance relies on security measures to fulfill its requirements. By integrating both, organizations can enhance their protective strategies, reassure clients of data safety, and avoid regulatory penalties. Various frameworks, such as SOX, NIST, PCI-DSS, ISO standards, and HIPAA, guide companies in aligning their practices with industry-specific compliance requirements. Box's platform exemplifies a comprehensive approach to managing security and compliance, offering tools for data governance and risk management across multiple sectors.
Apr 19, 2021 2,877 words in the original blog post.
Developing an information security program for an organization involves safeguarding company content from unauthorized access, modification, or deletion while ensuring appropriate access for authorized users. This process is guided by the three core principles of the CIA triad—confidentiality, integrity, and availability—which serve as benchmarks for data handling during transmission and at rest. Confidentiality ensures that only authorized individuals can access content, integrity maintains data accuracy and consistency, and availability guarantees that authorized users can easily access necessary information. Implementing various controls, such as authentication, access control, encryption, and file versioning, helps balance these principles and protect content, whether stored on-premises or in the cloud. Box's Content Cloud platform offers solutions like encryption, authentication tools, and content classification to uphold these principles, while also complying with regulations such as GDPR, FINRA, HIPAA, and GxP.
Apr 16, 2021 1,212 words in the original blog post.
Performing security risk assessments is essential for protecting a company's sensitive information and ensuring compliance with regulations like GDPR and ISO 27001. These assessments help organizations evaluate potential risks and vulnerabilities, prioritize the most pressing threats, and implement measures to mitigate them. By understanding and addressing risks, companies can prevent costly data breaches, maintain customer trust, and improve interdepartmental communication. Risk assessments require investment but can ultimately save money by avoiding significant financial losses from breaches. They involve identifying assets, vulnerabilities, and threats, assessing their likelihood and impact, and developing controls to manage risks. The results guide decision-makers in enhancing security measures, such as employee training and system upgrades, to protect critical business information. Additionally, tools like Box Shield offer solutions to reduce risk and protect content seamlessly within business operations.
Apr 13, 2021 1,281 words in the original blog post.