Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
No Result
View All Result
Home Cloud

Pentagon Issues Cloud Security Playbook

by Jane Edwards
March 3, 2025
in Cloud, News
Pentagon Issues Cloud Security Playbook

The Department of Defense has released a playbook designed to help software development managers, mission owners and developers improve the cybersecurity of applications hosted in cloud environments.

Table of Contents

    • You might also like
    • DIU Seeks Prototype Data Fabric to Modernize Space Force Tactical C2
    • NASA’s Wideband Polylingual Terminal Completes Demo
    • Commerce OIG Calls for Changes to NIST Vulnerability Database Management
  • Preparing Organizations for Cloud Adoption
  • Implementing Secure Identity, Credential & Access Management
  • Cloud Security Playbook Volume 2

You might also like

DIU Seeks Prototype Data Fabric to Modernize Space Force Tactical C2

NASA’s Wideband Polylingual Terminal Completes Demo

Commerce OIG Calls for Changes to NIST Vulnerability Database Management

The Cloud Security Playbook, cleared for public release on Feb. 26, seeks to address the most common cloud security vulnerabilities and threats and intends to help mission owners hosting software in the cloud quickly achieve an Authorization to Operate, or ATO.

The document comes in two volumes. The first volume aims to prepare organizations for using a cloud and intends to enable users to understand key concepts, such as the shared responsibility model, the impact level and the requirement of a DOD provisional authorization or ATO for cloud services.

Preparing Organizations for Cloud Adoption

The playbook suggests several actions to prepare an organization for using a cloud, such as setting up a cloud governance team, developing a cloud migration strategy and establishing a budget to implement the cloud migration strategy.

Other measures outlined in the document are developing organizational policies on cloud usage, creating a cloud exit strategy, defining the roles and responsibilities of those who will have cloud access and training the workforce on cloud security.

Implementing Secure Identity, Credential & Access Management

The document calls for the implementation of identity, credential and access management, or ICAM.

Recommended actions under this section include implementing and enforcing the principle of least privilege, or PoLP; implementing PoLP for each cloud resource; requiring phishing-resistant multifactor authentication; using context-based access control policies and review policies prior to deployment and periodically after deployment to identify potential gaps; and considering requiring administrators to access cloud resources using privileged access workstations.

The initial volume also covers other key plays, such as establishing secure network access, deploying with infrastructure as code, using a cloud-native application protection platform, employing defensive cyberspace operations and deploying user and entity behavior analytics.

Cloud Security Playbook Volume 2

The playbook’s second volume addresses ways to secure containers and microservices, defend DevSecOps pipelines, mitigate third-party risks and ensure the security of artificial intelligence systems and application programming interfaces.

To defend DevSecOps pipelines, recommended actions include adopting a zero-trust approach, using encryption with a FIPS 140-2 approved algorithm, minimizing the use of long-term credentials, implementing endpoint detection and response tools and integrating security testing into the pipeline.

Share5Tweet19

Recommended For You

DIU Seeks Prototype Data Fabric to Modernize Space Force Tactical C2

by Miles Jamison
June 2, 2026
Defense Innovation Unit logo. DIU is seeking prototype data fabric to combine Space Force's ground architecture.

DIU is seeking a unified data-sharing environment to replace disconnected Space Force ground systemsThe effort aims to reduce manual command-and-control processes and enhance decision-making speedA new data fabric...

Read moreDetails

NASA’s Wideband Polylingual Terminal Completes Demo

by Jane Edwards
June 2, 2026
Artist's concept of the Polylingual Experimental Terminal. NASA's PexT has completed its technology demonstration.

NASA has completed the Polylingual Experimental Terminal technology demonstrationExtended operations include direct-to-Earth links via SSC SpaceThe 2026 Air and Space Summit on July 30 will explore commercial space...

Read moreDetails

Commerce OIG Calls for Changes to NIST Vulnerability Database Management

by Kristen Smith
June 2, 2026
Commerce Department seal. Commerce's OIG said NIST lacks sustainable processes for managing NVD.

Commerce's OIG said NIST is struggling to manage a growing vulnerability database backlogThe audit has identified planning, processing and coordination gaps affecting National Vulnerability Database operationsNIST is implementing...

Read moreDetails

NSA Selects David Imbordino, Holly Baroody to Lead Cybersecurity Directorate

by Kristen Smith
June 2, 2026
NSA logo. NSA selected David Imbordino and Holly Baroody to lead its Cybersecurity Directorate.

NSA has appointed David Imbordino and Holly Baroody to cyber leadership roles, according to The RecordImbordino brings decades of experience spanning cybersecurity, intelligence and election security missionsThe changes...

Read moreDetails

Ge Bai, Mark Cruz Nominated for Key Health Leadership Roles

by Miles Jamison
June 2, 2026
White House logo. The White House announced that Ge Bai and Mark Cruz have been nominated to key health leadership roles.

Trump has tapped healthcare policy scholar Ge Bai for a senior HHS leadership roleThe Johns Hopkins professor currently serves as HHS' principal deputy assistant secretary for planning and...

Read moreDetails
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Sponsors

About ExecutiveGov

ExecutiveGov, published by Executive Mosaic, is a site dedicated to the news and headlines in the federal government. ExecutiveGov serves as a news source for the hot topics and issues facing federal government departments and agencies such as Gov 2.0, cybersecurity policy, health IT, green IT and national security. We also aim to spotlight various federal government employees and interview key government executives whose impact resonates beyond their agency.

CATEGORIES

  • Acquisition & Procurement
  • Announcements
  • Articles
  • Artificial Intelligence
  • Awards
  • Big Data & Analytics News
  • C4ISR
  • Civilian
  • Cloud
  • Contract Awards
  • Cybersecurity
  • Defense And Intelligence
  • Defense Security Cooperation
  • DHS
  • Digital Modernization
  • DoD
  • Events
  • Executive Moves
  • Executive Spotlights
  • Federal Civilian
  • Financial Reports
  • General News
  • GovCon Expert
  • Government Technology
  • GSA
  • Healthcare IT
  • Industry News
  • Intelligence
  • Legislation
  • M&A Activity
  • National Security
  • News
  • Policy Updates
  • Press Releases
  • Profiles
  • Space
  • Videos
  • Wash100
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Copyright 2026 Executive Mosaic. All Rights Reserved.

No Result
View All Result
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news

Copyright 2026 Executive Mosaic. All Rights Reserved.

Get your free GovCon news!

Get your latest GovCon news and insights. Become a VIP and subscribe to the GovConWire Daily News.

Invalid email address
We promise not to spam you. You can unsubscribe at any time.
Thanks for subscribing!