GSA / GSA/fedramp

Response to Acquisitions RFI Provided by Quality Information Partners, Inc.

Open
#5 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
No language data
Stars
19
Forks
15
PR merge metrics
No merged PRs in 30d

Description

## Question/Comment on FedRamp RFI Directory

## Name and Affiliation
Ryan Heitz, Director of Technology (Quality Information Partners, Inc. - Communications & Content, Data Management & Standards, and Cloud Application Support)

## Cloud Services

## Cloud Security

## FedRAMP PMO
Example contract language:
Vendor must provide access to an IaaS hosted by an established cloud services provider that can demonstrate past performance with federal government clients that meets or exceeds FISMA requirements for information systems categorized as FIPS-199 defined Moderate and complies with the Federal Risk and Authorization Management Process (FedRAMP) requirements.
The contract language above has provided a very workable framework for us and our customers to delineate responsibilities between vendor and federal agency. The vendor is responsible for ensuring the cloud service provider (CSP) has completed the FedRAMP process and all the cloud services being delivered to the federal customer are accredited at the appropriate FISMA rating. The federal agency is responsible for the accreditation of their own system.

## Additional Question/Comment
Based on our experience reselling more than $2.5 million in cloud services to the government over the past 5 years, we believe some requirements for “GSA Schedule 70 for Cloud” (SIN 132-40 Cloud Services) put small businesses at a competitive disadvantage. As a small business which is highly rated by our government customer, we have still found it difficult to obtain a “letter of supply” from a major cloud service provider (CSP), which is a necessary step toward getting onto “GSA Schedule 70 for Cloud”. Based on our specific experiences with CSPs, we have observed practices which appear to favor large businesses, at the expense of otherwise well-qualified small businesses. For example, CSPs may require a reseller to have a minimum number of federal customers and a minimum revenue threshold. These CSP-applied qualifiers are an obstacle to us pursuing more cloud business with our government customers. We feel CSPs should improve their selection process to consider all partners with proven experience as government resellers who demonstrate expertise in cloud cost management, infrastructure as a service, and security. If GSA and major CSPs could make a deliberate effort to include small cloud system integrators in “Schedule 70 for Cloud”, it would be a significant step toward fostering competition and innovation. Cloud has been touted as “the great equalizer” for small businesses. It is our hope that GSA and CSPs can work together to make the acquisition process for cloud services and meeting FedRAMP requirements more equitable.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.