Google For Governments

CatRambo 0 Tallied Votes 582 Views Share

At today's press conference , Google announced a new version of its Google Apps productivity suite, . The software has been certified as meeting U.S. Government security requirements. Like the Premier version of their suite, the cost is a yearly charge of $50 per user, and includes applications such as Gmail, Google Docs, Google Calendar, and Postini, an e-mail/Web security and archiving service.

The certification is a FISMA-Moderate rating, which can be used for sensitive, but not classified data. FISMA stands for the Federal Information Security Management Act passed in 2002 and applies to all information systems used by federal government agencies. Google Apps for Government is the first cloud-based application suite to receive such certification.

Google hopes to offer government users, including state and local governments, the same benefits other customers receive through cloud computing: automatic updates, no server maintenance worries, and the ability to access data through a range of devices. They cite the ability to draw on Google's security experts for assistance as an additional feature. Dave Girouard, president of Google’s Enterprise division, observed, “Government has an enormous opportunity to leverage the Web as a platform. “IT is a massive part of the government spend each year. It’s where a lot of our tax dollars go. In these days of shrinking budgets and lower tax receipts, cloud computing offers a great opportunity to create a more effective and responsive government.”

Google says that governments are already widely using its software, pointing to customers such as the cities of Los Angeles and Orlando as well as state governments in Kansas and New Mexico. They point to the simplicity and ease-of-use in their features as a major selling point, particularly for cash-strapped governments trying to streamline IT and reduce its cost.

Google will also store mail and calendar data for these customers on United States-based separate servers as an additional security measure. They will be seeking similar certification for their Google Chrome browser.

Dani AI

Generated

Back in 2010 flagged Google’s government-focused offering. The product line and the compliance landscape have both changed since then — Google’s paid collaboration products were rebranded as Google Workspace in 2020, and Google’s public compliance posture (FedRAMP, DoD/CJIS support and related tooling) is now what agencies need to evaluate, not the original product name. (workspace.google.com)

Practical checklist for agencies evaluating a cloud productivity suite today:

  • Confirm the current product/edition and the exact authorization level(s) (FedRAMP Moderate/High, DoD IL) and which services/features are in-scope. Ask for the vendor’s FedRAMP package (SSP/CRM) under NDA. (cloud.google.com)
  • Verify data residency and the technical controls used to enforce it (Data Regions / Assured Workloads or Assured Controls). Confirm support-staff location and personnel vetting for sensitive data. (cloud.google.com)
  • Treat records management and e-discovery as first-order requirements: involve the records officer early, require exportability and legal-hold capability (Vault or equivalent), and include retention and transfer language in contracts per NARA guidance. Plan for offline exports/backups in case of vendor changes. (archives.gov)
  • If your agency handles CJI/CJIS data, require the vendor’s CJIS Implementation materials and any necessary Management Agreement or background-check process for vendor personnel. (cloud.google.com)
  • Run a pilot that tests admin controls, audit/log exports, Vault searches/exports, SSO/MFA, and incident response procedures before a full migration.

A note on legacy Postini-era features: Google integrated Postini capabilities into the Workspace stack over time (archiving/filters -> Vault and native controls), so procurement should verify which legacy features map to present controls and contracts. (cloud.googleblog.com)

Summary: cloud productivity suites can deliver savings and agility, but the procurement checklist must focus on current authorizations, the package’s in-scope boundary, records obligations, and operational controls (identity, retention, exportability). Use the FedRAMP Marketplace and the vendor’s compliance docs to confirm what’s actually authorized before committing sensitive or regulated data. (cloud.google.com)

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.