DrupalCon Denver 2012: BUILDING AND SECURING GOVERNMENT DRUPAL SITES IN THE CLOUD
About this talk
This session focuses on the accreditation process for federal information systems, highlighting the compliance standards FISMA for non-DoD agencies, DIACAP for DoD, and FedRAMP for cloud service providers. The speaker reviews the current landscape of US government compliance and shares insights from experiences working with federal customers to obtain accreditation for Drupal-based sites hosted in commercial clouds. Case studies include the Defense Security Cooperation Agency, which is seeking DIACAP accreditation, and a non-DoD government organization that achieved FISMA certification. Key topics addressed include the challenges of building compliant sites, required certifications, security testing and management, FedRAMP requirements for Drupal, and the translation of NIST standards to international frameworks like ISO.