IT Brief US - Technology news for CIOs & IT decision-makers
Story image

Commvault Cloud secures GovRAMP Authorised High impact status

Today

Commvault has announced that its Commvault Cloud platform has received GovRAMP Authorised status for cyber resilience SaaS solutions.

This achievement adds to Commvault's credentials, making it the only vendor in the cyber resilience sector holding GovRAMP Authorised status at a High impact level, as well as FedRAMP High and FIPS 140-3 validation, for public sector customers.

GovRAMP, formerly known as StateRAMP, provides a standardised process for evaluating the security of cloud products and services used by US state and local governments and educational institutions.

The programme uses three verified statuses—Ready, Provisionally Authorised, and Authorised—reflecting increasing phases of review, with Authorised signifying the highest level of scrutiny and compliance based on NIST 800-53 Rev.5 controls.

Achieving Authorised status at a High impact level means that Commvault Cloud has met the strictest requirements for security and risk management. Commvault underwent detailed third-party assessment and review by the GovRAMP Programme Management Office to attain this recognition.

The company is now the exclusive provider of cyber resilience holding concurrent GovRAMP Authorised at High impact, FedRAMP High Authorised, and FIPS 140-3 validated status for its SaaS offerings. The combination aims to support federal, state, local and educational entities in managing sensitive data and strengthening security postures.

Michael Carroll, Area Vice President at Commvault, highlighted the context for this development with reference to the current cyber threat landscape facing public sector organisations.

Carroll stated, "We're proud to achieve GovRAMP Authorization, especially when nearly all ransomware attacks (99%) on SLED organizations target backups, underscoring the critical need for cyber resilience. Being the only vendor to secure GovRAMP Authorized at a High impact level, FedRAMP High, and FIPS 140-3 authorizations demonstrates our unique ability to support the most rigorous security demands of public sector organizations as they accelerate cloud transformations and bolster cyber resilience."

The authorisation is intended to offer several advantages for state, local, and educational (SLED) organisations adopting Commvault Cloud.

These include enhanced security standards to mitigate breaches and unauthorised access, assurance of regulatory compliance, increased organisational trust, streamlined procurement for agencies requiring GovRAMP Authorised solutions, and flexibility to implement advanced secure cloud technologies.

Public sector customers have voiced support for Commvault's security focus. Phillip Winder, Chief of Information Technology at State of Delaware Department of Corrections, shared his experience: "Commvault's cutting-edge solutions have bolstered our cyber resilience capabilities and set a new standard for innovation."

"Advanced threat detection and rapid response capabilities help ensure that our critical operations remain uninterrupted, even in the face of sophisticated cyberattacks."

Winder further commented on operational improvements, saying, "With Commvault, we've been able to fortify our cyber defenses and streamline our incident response processes. The continuous monitoring and advanced data security features have been instrumental in preventing disruptions to our operations, allowing us to focus on our core mission."

For SLED organisations in the United States, Commvault Cloud's GovRAMP Authorised status is currently available.

The recognition is expected to simplify security verification and procurement processes for government and education customers requiring validated SaaS solutions that meet the highest compliance standards.

GovRAMP serves as a standard authority on cloud security for US state and local governments. Its aim is to empower agencies and vendors to confidently navigate the complexities of cloud security through standard procedures and comprehensive assessments.

Commvault continues to focus its efforts on providing cyber resilience and data protection solutions for a broad spectrum of public sector organisations, following the requirements and recommendations of both national security frameworks and its clientele.

Follow us on:
Follow us on LinkedIn Follow us on X
Share on:
Share on LinkedIn Share on X