News

Microsoft Cloud-Based Apps Pass FISMA Scrutiny

Microsoft announced on Wednesday that its cloud-based suite of applications has passed muster for government use per Federal Information Security Management Act (FISMA) standards.

Microsoft's Business Productivity Online Suite for the federal government, or BPOS-Federal, now can be used by government agencies. BPOS-Federal received an "authorization to operate" clearance from the U.S. Department of Agriculture.

"The certification and accreditation has resulted in an official 'Authorization to Operate' (ATO) issued on April 19 by the U.S. Department of Agriculture (USDA) for Microsoft's Business Productivity Online Services-Federal, which includes Exchange Online, SharePoint Online, and Office Communications Online," a Microsoft blog explains.

Government IT systems must meet security certification and accreditation standards specified by the 2002 FISMA law (PDF).  Software products aren't certified as "FISMA-compliant" per se, but the systems running them do have to meet FISMA standards.

Microsoft had received authorization for its datacenters in November based on FISMA requirements. However, it had lacked such authorization for its hosted applications that ran in those datacenters. Now, with the added authorization, the way is cleared for BPOS-Federal applications to be rolled out to 120,000 USDA employees.

Still, a legal tussle could dog Microsoft along the way -- at least in terms of obtaining some government contracts. A lawsuit filed by Google in October against the U.S. Department of Interior alleges that Google was excluded from competitive-bidding contract considerations when Microsoft won a BPOS-Federal contract with that government organization.

Microsoft has since returned fire. Earlier this month, a Microsoft attorney asserted that Google Apps for Government lacks FISMA certification. However, the U.S. General Services Administration (GSA), which issues FISMA certification and accreditation approvals, weighed in, stating that Google Apps Premier was "FISMA compliant in July of 2010" and that Google Apps for Government uses the same controls. The GSA currently is just assessing some added security controls in the Google Apps for Government suite.

Microsoft will update its BPOS line of hosted applications with a new offering called "Office 365," which is currently available for testing as a beta release. Microsoft expects to roll out Office 365 services commercially sometime this summer. After that commercial release, Microsoft plans "to pursue FISMA certification and accreditation for Office 365," according to Microsoft's blog post.

About the Author

Kurt Mackie is senior news producer for the 1105 Enterprise Computing Group.

Featured

  • Google IDs on Azure Active Directory B2B Service Now at 'General Availability'

    Microsoft announced on Wednesday that users of the Google identity and access service can use their personal log-in IDs with the Azure Active Directory B2B service to access resources as "guests."

  • Top 4 Overlooked Features of a Data Backup Strategy

    When it comes to implementing an airtight backup-and-recovery plan, these are the four must-have features that many enterprises nevertheless tend to forget.

  • Microsoft Bolsters Kubernetes with Azure Confidential Computing

    Microsoft on Tuesday announced various developments concerning the use of Kubernetes, an open source container orchestration solution fostered by Google.

  • Windows Will Have Support for Encrypted DNS

    Microsoft announced this week that the Windows operating system already has support for an encrypted Domain Name System option that promises to add greater privacy protections for Internet connections.

comments powered by Disqus

Office 365 Watch

Sign up for our newsletter.

Terms and Privacy Policy consent

I agree to this site's Privacy Policy.