Complete Discovery Source Achieves Full-EDRM FedRAMP Certification. It Wasn't Easy
CDS's three-year road to FedRAMP underscores the challenges e-discovery providers will have to navigate when looking to provide cloud services for government clients.
February 13, 2018 at 09:30 AM
5 minute read
Federal agencies are increasingly looking to leverage e-discovery technology to meet their data management needs. But to use these tools on the cloud, such services need to be certified under the Federal Risk and Authorization Management Program (FedRAMP).
For e-discovery providers catering to government clients, this has meant deploying solutions on FedRAMP-certified cloud platforms, such as Amazon Web Services or Microsoft Azure. But not all providers want to outsource their hosting capabilities. Among them is Complete Discovery Source (CDS), which recently announced its achievement of FedRAMP certification.
Matthew Milone, director of federal operations at Complete Discovery Source, said that the company is now certified “for end-to-end management of data in our cloud,” adding that he believes CDS is the first e-discovery company to “own our complete environment.”
To be sure, Veritas Technologies announced in October 2016 that its Veritas Enterprise Vault and Veritas Discovery Accelerator were FedRAMP certified as well. But CDS noted it is the only e-discovery provider to offer a full EDRM “one-stop-shop” e-discovery cloud service that has achieved FedRAMP certification.
Certificiation, however, wasn't easy to obtain. For an e-discovery company, such certification can be a years-long and expensive process, one that requires managing multiple stakeholders and meeting vast security standards. CDS, for example, couldn't have gotten FedRAMP certification if it weren't for its government client, the Pension Benefits Guaranty Corporation (PBGC), which had to sponsor the e-discovery company to be considered by FedRAMP.
To initially work with the PBGC, CDS had to first acquire an authorization to operate (ATO) from FedRAMP. Milone noted that such ATOs are essentially agreements where the federal government accepts “the risks as it is now” from cloud providers, so long as there are no “critical errors in the system where any bad things can happen.” Before granting an ATO, the government looks to see if the cloud provider has “a proven track record of managing the risk and securing the implementation,” and if the security provided is up to the government's needs.
Such approval, however, was only the first step in the process for CDS. “When we got our initial deal with PBGC, it was contingent that we would get FedRAMP certification and that we would work together as team to become FedRAMP certified,” Milone said. “It took about three years for us to get everything settled and done and finalized.”
So why did the certification process take CDS several years? For one, when FedRAMP's Joint Authorization Board (JAB) reviews whether to certify a company, it looks to see whether the company meets an enormous set of security standards. The criteria encompasses “17 categories with about 2,326 security controls,” Milone said.
He explained that some of these categories include topics like “access control, configuration management, and contingency planning if something goes wrong, like incident response plans.” Within these categories, the controls that are looked at can be as specific as the temperature of one's data center to the physical locks on the doors. CDS, therefore, had to create what Milone called a “security bible,” documenting not only the company's security controls, but also the security and access policies its staff would abide by. Such controls and policies had to be verified thoroughly by FedRAMP-approved third party assessment organizations, whose examinations were themselves reviewed by FedRAMP.
The cost of getting up to speed on all required security controls was significant. “For a small company like ours, the biggest expense is the time it took,” Milone said. He noted that in addition to the third party assessment, “you're dealing with the agency stakeholders who sponsor you, and you're dealing with the security consultants you hired who are constantly asking you questions.”
Of course, just by their very nature, e-discovery companies can have a harder time with certain security controls than others. Milone noted that implementing access controls can be a challenge given that “the nature of a service-based e-discovery business is having a lot of people touching the data.”
To tackle this challenge, Milone sought to change the culture of his company, rather than just put in place a new access control technologies. “So instead of just having an access control plan, we have an access control policies and procedures.”
While getting FedRAMP approval was an arduous and expensive process for CDS, the e-discovery company ultimately sees it as one that will help it grow its government client base.
“For a small e-discovery vendor like us, we wanted a leg to stand on, because now we can begin competing with other vendors out there in the government space.”
But ultimately CDS believes that it will be one of many e-discovery companies with FedRAMP certification. Milone noted that those in legal are slow adopters and often wait for a certification, such ISO 27001, to become more widely adopted become jumping on board. It may be only a matter of time then, until FedRAMP certification is a yet another must-have asset for modern e-discovery providers.
This content has been archived. It is available through our partners, LexisNexis® and Bloomberg Law.
To view this content, please continue to their sites.
Not a Lexis Subscriber?
Subscribe Now
Not a Bloomberg Law Subscriber?
Subscribe Now
NOT FOR REPRINT
© 2025 ALM Global, LLC, All Rights Reserved. Request academic re-use from www.copyright.com. All other uses, submit a request to [email protected]. For more information visit Asset & Logo Licensing.
You Might Like
View AllTrending Stories
- 1Goodwin Procter Relocates to Renewable-Powered Office in San Francisco’s Financial District
- 2'Didn't Notice Patient Wasn't Breathing': $13.7M Verdict Against Anesthesiologists
- 3'Astronomical' Interest Rates: $1B Settlement to Resolve Allegations of 'Predatory' Lending Cancels $534M in Small-Business Debts
- 4Senator Plans to Reintroduce Bill to Split 9th Circuit
- 5Law Firms Converge to Defend HIPAA Regulation
Who Got The Work
J. Brugh Lower of Gibbons has entered an appearance for industrial equipment supplier Devco Corporation in a pending trademark infringement lawsuit. The suit, accusing the defendant of selling knock-off Graco products, was filed Dec. 18 in New Jersey District Court by Rivkin Radler on behalf of Graco Inc. and Graco Minnesota. The case, assigned to U.S. District Judge Zahid N. Quraishi, is 3:24-cv-11294, Graco Inc. et al v. Devco Corporation.
Who Got The Work
Rebecca Maller-Stein and Kent A. Yalowitz of Arnold & Porter Kaye Scholer have entered their appearances for Hanaco Venture Capital and its executives, Lior Prosor and David Frankel, in a pending securities lawsuit. The action, filed on Dec. 24 in New York Southern District Court by Zell, Aron & Co. on behalf of Goldeneye Advisors, accuses the defendants of negligently and fraudulently managing the plaintiff's $1 million investment. The case, assigned to U.S. District Judge Vernon S. Broderick, is 1:24-cv-09918, Goldeneye Advisors, LLC v. Hanaco Venture Capital, Ltd. et al.
Who Got The Work
Attorneys from A&O Shearman has stepped in as defense counsel for Toronto-Dominion Bank and other defendants in a pending securities class action. The suit, filed Dec. 11 in New York Southern District Court by Bleichmar Fonti & Auld, accuses the defendants of concealing the bank's 'pervasive' deficiencies in regards to its compliance with the Bank Secrecy Act and the quality of its anti-money laundering controls. The case, assigned to U.S. District Judge Arun Subramanian, is 1:24-cv-09445, Gonzalez v. The Toronto-Dominion Bank et al.
Who Got The Work
Crown Castle International, a Pennsylvania company providing shared communications infrastructure, has turned to Luke D. Wolf of Gordon Rees Scully Mansukhani to fend off a pending breach-of-contract lawsuit. The court action, filed Nov. 25 in Michigan Eastern District Court by Hooper Hathaway PC on behalf of The Town Residences LLC, accuses Crown Castle of failing to transfer approximately $30,000 in utility payments from T-Mobile in breach of a roof-top lease and assignment agreement. The case, assigned to U.S. District Judge Susan K. Declercq, is 2:24-cv-13131, The Town Residences LLC v. T-Mobile US, Inc. et al.
Who Got The Work
Wilfred P. Coronato and Daniel M. Schwartz of McCarter & English have stepped in as defense counsel to Electrolux Home Products Inc. in a pending product liability lawsuit. The court action, filed Nov. 26 in New York Eastern District Court by Poulos Lopiccolo PC and Nagel Rice LLP on behalf of David Stern, alleges that the defendant's refrigerators’ drawers and shelving repeatedly break and fall apart within months after purchase. The case, assigned to U.S. District Judge Joan M. Azrack, is 2:24-cv-08204, Stern v. Electrolux Home Products, Inc.
Featured Firms
Law Offices of Gary Martin Hays & Associates, P.C.
(470) 294-1674
Law Offices of Mark E. Salomone
(857) 444-6468
Smith & Hassler
(713) 739-1250