Accurate, Focused Research on Law, Technology and Knowledge Discovery Since 2002

DoD Needs an Effective Process to Identify Cloud Computing Service Contracts

Audit – DoD Needs an Effective Process to Identify Cloud Computing Service Contracts, DODIG-2016-038, December 28, 2015.

  • “Objective – Our objective was to determine whether selected DoD Components performed a cost-benefit analysis before acquiring cloud computing services. In addition, we were to identify whether those DoD Components achieved actual savings as a result of adopting cloud services. Due to the limited number of cloud computing service contracts identified, we could not provide a sufficient answer to our announced objective. However, we addressed the need for a standardized cloud computing definition and an integrated repository for cloud computing service contract information to help determine whether DoD is effectively using cloud computing services.
  • Finding – DoD did not maintain a comprehensive list of cloud computing service contracts. This occurred because the DoD Chief Information Officer (CIO) did not establish a standard, Department-wide definition for cloud computing and did not develop an integrated repository that could provide detailed information to identify cloud computing service contracts. As a result, DoD cannot measure the effectiveness of the DoD cloud computing initiative. Specifically, DoD cannot determine whether it achieves actual cost savings or benefits from adopting cloud computing services. In addition, without knowing what data DoD Components place on the cloud, DoD may not effectively identify and monitor cloud computing security risks.
  • Recommendations –We recommend that the DoD CIO: issue guidance to either establish a standard, Department-wide cloud computing definition or clarify the National Institute of Standards and Technology definition to consistently identify DoD Component cloud computing service contracts; and establish an integrated repository that provides detailed information to identify DoD cloud computing service contracts after Recommendation 1.a of this report is completed.”

 

Sorry, comments are closed for this post.