Skip to content

Commit 4a182be

Browse files
authored
Merge pull request #196 from cloud-gov/2025-08-29_security_content_fixes
Improvements to security language to increase accuracy
2 parents d5c7ca7 + ec5fbf0 commit 4a182be

2 files changed

Lines changed: 26 additions & 35 deletions

File tree

src/data/pages/home.yaml

Lines changed: 5 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,6 @@
11
title: Faster, easier, and more secure digital services for government agencies
22
description: A platform-as-a-service built for government. Deploy secure, compliant sites and apps without managing infrastructure.
33

4-
54
hero:
65
heading: "Faster, easier, and built for government from the start"
76
intro: |
@@ -69,19 +68,14 @@ mandatesHandled:
6968
art: "compliance-alt"
7069
color: "primary-vivid"
7170
intro: |
72-
Cloud.gov is already FedRAMP Authorized (Moderate), so your agency can reuse our compliance package. That means on day one, you can check these off your list:
71+
Cloud.gov is already FedRAMP Authorized (Moderate), so your agency can reuse our compliance package. That means on day one, your **platform layer** already meets these mandates:
7372
content: |
74-
- Built-in continuous monitoring, monthly vulnerability scans, POA&M updates, incident reporting, and annual assessments that satisfy key **FY 2025 FISMA CIO metrics under OMB M-25-04**.
75-
76-
- Integrated platform patching, automated backups, centralized logging, and incident alerting mapped to **NIST 800-53 Rev. 5 control families like SI, AU, and CM**.
77-
73+
- Continuous monitoring, monthly vulnerability scans, POA&M updates, incident reporting, and annual assessments — all performed for the **platform itself**, satisfying key FY 2025 FISMA CIO metrics under OMB M-25-04.
74+
- Platform patching, automated backups, centralized logging, and incident alerting mapped to **NIST 800-53 Rev. 5 control families like SI, AU, and CM**.
7875
- Encrypted, isolated networking between containers with short-lived credentials and granular access policies — aligned with **EO 14028 and CISA’s Zero Trust Maturity Model**.
7976
80-
- **FIPS 140-2** compliant environment with cryptographic modules validated against **FIPS 140-3**.
81-
82-
83-
buttons:
84-
# TODO add links
77+
buttons:
78+
# TODO add links
8579
- label: "More about compliance"
8680
url: "security"
8781
outro: |

src/data/pages/security.yaml

Lines changed: 21 additions & 24 deletions
Original file line numberDiff line numberDiff line change
@@ -7,73 +7,70 @@ hero:
77
We handle the infrastructure. You focus on your application.
88
99
content: |
10-
When you build on Cloud.gov, **you inherit hundreds of security and operational controls** from our FedRAMP-authorized platform—reducing the time, effort, and risk required to achieve an ATO.
10+
When you build on Cloud.gov, **you inherit hundreds of security and operational controls** from our FedRAMP-authorized (Moderate) platform. That means less time, less effort, and lower risk in getting your Authority to Operate (ATO).
1111
1212
art: "compliance"
1313

1414
g2g:
15-
heading: "Zero-trust infrastructure that meets every government expectation"
16-
intro: "Cloud.gov provides you with a FIPS 140-2 compliant environment designed for U.S. federal workloads, where we can offer top-requested security features like:"
15+
heading: "Zero-trust infrastructure that meets government expectations"
16+
intro: "Cloud.gov provides you with a secure environment designed for U.S. federal workloads, where we can offer top-requested security features like:"
1717
align: "center"
1818
color: "primary-vivid"
1919
items:
2020
- heading: "Supply-chain hardening"
21-
text: "100% of our images are built using pre-scanned, signed, and reproducible buildpacks."
21+
text: "Our images are built using pre-scanned and reproducible buildpacks."
2222
icon: "verified_user"
2323
- heading: "Per-app isolation"
24-
text: "Every container runs in its own trust zone with mutual encryption enforced on every route."
24+
text: "Every container runs in its own trust zone with mutual encryption protecting every route."
2525
icon: "safety_divider"
2626
- heading: "Least privilege strategy"
27-
text: "We deny service-to-service access by default and grant it only through explicit policies."
27+
text: "We deny service-to-service access unless your policies explicitly allow it."
2828
icon: "do_not_touch"
2929

3030
launchNow:
3131
heading: "Launch securely now, not next quarter"
3232
art: "compliance-alt"
3333
intro: |
34-
Skip months of security configuration. Our multi-availability zone platform includes enterprise-level protections designed to meet the most stringent federal requirements.
35-
36-
content: |
37-
When you run your FISMA Low or Moderate system on Cloud.gov, you automatically inherit coverage for more than 300 of the NIST 800-53 Rev 5 controls. That means on day one, you can check these off your list:
34+
Skip months of security configuration. Our multi-availability zone platform includes enterprise-level protections designed to meet the most stringent federal requirements.
35+
36+
content: |
37+
When you run your FISMA Low or Moderate system on Cloud.gov, you automatically inherit coverage for more than 155 of the NIST 800-53 Rev 5 controls. That means on day one, you can check these off your list:
3838
3939
checks: true
4040
items:
41-
- heading: Advanced anti-malware protection
42-
- heading: Comprehensive network security controls
41+
- heading: Comprehensive network security controls
4342
- heading: Proactive, immediate event alerting
44-
- heading: Intelligent web application firewall (WAF) rules
43+
- heading: Intelligent web application firewall (WAF) rules
4544
- heading: Searchable application logging
46-
- heading: Elastic infrastructure scaling for sudden traffic surges
47-
- heading: Continuous monitoring that meets every 2025 FISMA metric for OMB M-25-04
48-
- heading: A completely “Zero Trust” model that satisfies Executive Order 14028
49-
- heading: Cryptographic modules that are validated against the FIPS 140-3 Standard
45+
- heading: Elastic infrastructure scaling for traffic surges
46+
- heading: Continuous monitoring aligned with OMB M-25-04 and 2025 FISMA metrics
47+
- heading: A “Zero Trust” model that aligns with Executive Order 14028
5048
- heading: Physical and environmental protections (PE family)
5149
- heading: Network and boundary controls (SC-7, AC-17)
5250
- heading: Platform patching, backups, and system monitoring (SI, AU, CM families)
53-
- heading: A FIPS 140-2 compliant environment
51+
5452
outro: |
5553
You don’t have to set up your own platform team to meet federal compliance requirements. **We’re already operating one for you.**
5654
57-
5855
AtoMedia:
5956
heading: "Designed for the way government launches software"
6057
intro: "Cloud.gov’s shared responsibility model gives federal teams a head start, whether you’re seeking a new ATO or reauthorizing an existing system. With Cloud.gov’s position, context, and expertise inside government, we understand firsthand what’s hard for agency customers."
6158
items:
6259
- heading: "Guided security support with our in-house experts"
63-
text: "We work directly with your security and compliance staff to provide system diagrams and boundary documentation, walk your team through inherited control mappings, and even **provide boilerplate text and evidence** for your System Security Plan (SSP) and Security Impact Assessments (SIA)."
60+
text: "Cloud.gov is built for self-service—our documentation and tooling give your team what they need to move quickly and independently. But you’re not on your own: our in-house experts are available to point you to the right resources and answer your security and compliance questions."
6461
mediaComponent: "Illustration-ATO"
6562
button:
6663
label: "Check us out on the FedRAMP marketplace"
6764
url: "https://marketplace.fedramp.gov/products/F1607067912"
65+
6866
- heading: "We do more, so you do less"
6967
text: "Cloud.gov isn’t just _technically_ compliant—it’s built with the realities of federal security in mind. We’ve supported dozens of agencies through audits, ATOs, and reauthorizations, and we’ve shaped our platform and docs around what teams actually need to succeed."
7068
mediaComponent: "Illustration-Security"
7169
button:
72-
label: "Review our compliance docs on Connect.gov"
73-
url: "https://www.connect.gov/"
70+
label: "Explore our compliance documentation"
71+
url: "https://docs.cloud.gov/platform/compliance/"
7472
color: "primary-dark"
7573

76-
7774
yourMissionOurInfra:
7875
heading: "Your mission, our infrastructure"
7976
intro: "Employees and contractors can focus on developing mission-critical applications, leaving server infrastructure management to us. We support the platform—you own the application. That means you’re in control of things like:"
@@ -93,4 +90,4 @@ approachIds:
9390

9491
offeringIds:
9592
- apps
96-
- pages
93+
- pages

0 commit comments

Comments
 (0)