ISCS-M3-SensitiveData.pdf

The Pentagon (or U.S. Federal Government) recently awarded a colossal cloud computing

contract that might eventually be worth up to $9 billion dollars to 4 companies: Microsoft,

Google, Oracle, and Amazon. The Joint Warfighting Cloud Capability, as it is called, is planned

to be used across all branches of service, for all levels of classified information, and all security

domains. This contract was awarded after a similar contract was awarded to Microsoft, but was

cancelled due to allegations of presidential meddling in the award process. The political issues

have nothing to do with our analyses, so steer clear of those. The new contract was awarded in

Dec 2022.

Now, here we are less than 3 months later… The U.S. Special Operations Command

(USSOCOM) recently leaked 3 TBs of sensitive internal emails via a misconfigured Microsoft

Azure cloud server. The misconfiguration allowed anyone to access this extensive trove of

emails with no uesr ID or password required. Not a hack - since no malicious actor was involved,

but a very unfortunate configuration error. In military parlance, it was a “friendly fire” attack.

Given that these types of issues occur far too frequently in both the government and corporate

sectors:

• Describe at least 3 policies ANY organization should use to ensure data in the

cloud remains private and secure.

• Explain the purpose of each policy you describe.

• Support your arguments with at least 3 external sources total with at least 1

external source for every policy recommendation you make.

• Please describe each policy recommendation in a separate paragraph with a

minimum of 75 words (225 words total)

• Finally do you believe we should be using/storing data with national security

implications in the cloud?

o No external references required for this part, but explain your logic

o A couple of sentences is sufficient

• Provide a bibliography as well

Technical Requirements:

- Your post must include 3 paragraphs (75 words minimum per policy) and be at least 225 words

in total length

- External references are required - a minimum of 3, but be sure to cite all references you use