AWS becomes the first cloud provider cleared for NATO Restricted work across the alliance

Amazon Web Services has become the first cloud service provider to gain approval to handle NATO-restricted information in all of the alliance’s member states, and the path to this approval went not through NATO’s own offices but through Madrid.

AWS has documented its compliance with D32, the NATO technical directive that defines the security requirements for handling NATO Restricted (NR) information in the public cloud, and the Spanish National Cryptologic Center (CCN) has assessed its services against that directive.

NATO then approved the findings and made them available to all its allies. AWS states that approved services may now be used to construct NR-capable systems in any of its regions located in NATO countries, and it has 15 such regions, seven of which are in mainland Europe.

A second clearance was obtained as a result of the Spanish phase, as AWS stated that both the CCN and the National Security Office (ONS), which are part of Spain’s National Intelligence Center (CNI), had also given their approval for the AWS Europe (Spain) region to handle information classified as “Difusión Limitada” (DL), which is Spain’s equivalent of NATO Restricted.

The data centers for that region are located in Aragón.

It involved several certification stages. AWS had already obtained the Spain National Security Scheme (ENS) certification at the highest “High” level, and 28 of its security services and features, such as those for EC2 computing and S3 storage, had been approved in the CCN’s catalog of approved security products.

Furthermore, the company satisfied the specific requirements for DL information as specified in the CCN-STIC-004 policy and by the ONS, which required a security evaluation of its data centers.

The approval applies only to AWS’s part of the arrangement, not to its customers; public-sector and defense organizations accredited in Spain can now run DL and NR workloads in the Spanish region.

Yet, they must still have their own systems operating on that infrastructure, accredited in accordance with the same CCN-STIC-004 policy and ONS requirements.

Since NATO assigns NR accreditation to the member countries as well as to its Communications and Information Agency (NCIA), each government continues to manage its own national process.

The company says the alliance-wide approval provides them with a common, previously assessed security baseline and a faster path through that process, thereby reducing the time and cost of compliance.

“Strengthening NATO’s ability to securely leverage commercial technology is key to build a more resilient and agile Alliance. 

The availability of commercial products that meet NATO’s security requirements expands the technology options available for the Alliance and supports our ability to adopt modern technologies while maintaining the security and resilience on which our operations depend,” said Dylan Browne, general manager, NATO Communications and Information Agency (NCIA).

The clearance applies throughout the Alliance; the paperwork needed by each government that wishes to use it stays the property of that government.

Original source AWS becomes the first cloud provider cleared for NATO Restricted work across the alliance

Back to home