Federal Cloud Computing, Second Edition: The Definitive Guide for Cloud Service Providers
暫譯: 聯邦雲端運算(第二版):雲端服務提供者的權威指南
Matthew Metheny
- 出版商: Syngress Media
- 出版日期: 2017-01-19
- 售價: $2,710
- 貴賓價: 9.5 折 $2,575
- 語言: 英文
- 頁數: 536
- 裝訂: Paperback
- ISBN: 0128097108
- ISBN-13: 9780128097106
-
相關分類:
雲端運算
海外代購書籍(需單獨結帳)
相關主題
商品描述
Federal Cloud Computing: The Definitive Guide for Cloud Service Providers, Second Edition offers an in-depth look at topics surrounding federal cloud computing within the federal government, including the Federal Cloud Computing Strategy, Cloud Computing Standards, Security and Privacy, and Security Automation.
You will learn the basics of the NIST risk management framework (RMF) with a specific focus on cloud computing environments, all aspects of the Federal Risk and Authorization Management Program (FedRAMP) process, and steps for cost-effectively implementing the Assessment and Authorization (A&A) process, as well as strategies for implementing Continuous Monitoring, enabling the Cloud Service Provider to address the FedRAMP requirement on an ongoing basis.
This updated edition will cover the latest changes to FedRAMP program, including clarifying guidance on the paths for Cloud Service Providers to achieve FedRAMP compliance, an expanded discussion of the new FedRAMP Security Control, which is based on the NIST SP 800-53 Revision 4, and maintaining FedRAMP compliance through Continuous Monitoring. Further, a new chapter has been added on the FedRAMP requirements for Vulnerability Scanning and Penetration Testing.
- Provides a common understanding of the federal requirements as they apply to cloud computing
- Offers a targeted and cost-effective approach for applying the National Institute of Standards and Technology (NIST) Risk Management Framework (RMF)
- Features both technical and non-technical perspectives of the Federal Assessment and Authorization (A&A) process that speaks across the organization
商品描述(中文翻譯)
《聯邦雲端運算:雲端服務提供者的權威指南,第二版》深入探討了聯邦政府內部與聯邦雲端運算相關的主題,包括聯邦雲端運算策略、雲端運算標準、安全性與隱私,以及安全自動化。
您將學習NIST風險管理框架(RMF)的基本概念,特別針對雲端運算環境,聯邦風險與授權管理計畫(FedRAMP)流程的各個方面,以及以具成本效益的方式實施評估與授權(A&A)流程的步驟,還有實施持續監控的策略,使雲端服務提供者能夠持續滿足FedRAMP的要求。
本次更新的版本將涵蓋FedRAMP計畫的最新變更,包括針對雲端服務提供者達成FedRAMP合規性的路徑的指導說明,擴展了基於NIST SP 800-53修訂版4的新FedRAMP安全控制的討論,以及通過持續監控維持FedRAMP合規性。此外,新增了一章關於FedRAMP對漏洞掃描和滲透測試的要求。
- 提供對聯邦要求在雲端運算中應用的共同理解
- 提供針對性且具成本效益的方法來應用國家標準與技術研究所(NIST)風險管理框架(RMF)
- 涉及聯邦評估與授權(A&A)流程的技術與非技術觀點,能夠跨組織溝通