The United States has taken the lead in the security monitoring of cloud services when the http://www.aliyun.com/zixun/aggregation/79320.html "> countries have begun to study cloud services-related security regulatory policies." The National Institute of Standards and Technology (NIST) has published a series of cloud computing white papers, and NIST's definition of cloud computing has been widely cited and adopted. In the near future, NIST has issued the Federal Information Security Continuous monitoring (ISCM) report, which provides guidance for the planning of internal cloud service security processes and maintains its vigilance against information security, vulnerabilities and threats through continuous monitoring.
The federal Risk and Authorization management plan (FEDRAMP) is an operational guide for U.S. federal agencies to follow in the procurement of cloud services. The plan not only established security requirements, but also monitored the implementation of security measures, such as periodic release of vulnerability Scan reports quarterly. FedRAMP is likely to be the benchmark for U.S. cloud services public contract monitoring.
(Responsible editor: Duqing first)