U.S. flag

An official website of the United States government

Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock () or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Breadcrumb

Audit of NARA’s Adoption and Management of Cloud Computing

Report Information

Date Issued
Report Number
17-AUD-08
Report Type
Audit
Description
This audit evaluated NARA’s cloud computing environment and determine whether NARA was properly prepared to manage its transition to cloud computing services and meet OMB’s goals of a “Cloud First” policy.
Joint Report
No
Agency Wide
No (location specific)
Questioned Costs
$0
Funds for Better Use
$0

Recommendations

The NARA CIO, acting as the centralized authority for NARA’s cloud computing program, should take the lead and collaborate with business areas such as Acquisitions and General Counsel, to develop, approve, and implement comprehensive policies and...

The NARA CIO should complete and document a review of existing IT systems for cloud compatibility.

The NARA CIO should update the Enterprise Cloud Strategy with clearly defined roles and responsibilities, and develop and implement a written plan to execute the strategy.

The NARA CIO should conduct and document a risk assessment specific to NARA’s implementation of cloud computing in coordination with NARA's Chief Risk Officer.

The NARA CIO should establish and approve a centralized reporting point for cloud computing inventory and develop, implement and communicate a written mechanism to standardize tracking cloud computing inventory across NARA’s business area lines.

The NARA CIO should coordinate with necessary business areas including Acquisitions and General Counsel to develop, approve, and implement its written cloud provisioning guidelines.

The NARA CIO should coordinate with necessary business areas including Acquisitions and General Counsel to develop, approve, and implement its IT Security Contractual Requirements in addition to a method to monitor and enforce the use of the standards.

The NARA CIO, in conjunction with Acquisitions and General Counsel should develop, approve, and implement written standards for centralized maintenance and standardized monitoring of service level agreements and formally communicate the requirement to...

The NARA CIO should coordinate with the Chief Acquisitions Officer, and General Counsel to establish a working group to evaluate and monitor recommendations and best practices for cloud computing procurement in order to improve the content and...