A new memo from the Defense Department clarifies who is accountable for ensuring the security of cloud services at the FedRAMP moderate level.\nThe latest document provides guidance on a clause within the Defense Federal Acquisition Regulation Supplement regarding the application of FedRAMP moderate to cloud services being used by contractors for storing and processing covered defense information.\n\u201cOne of the things that we learned in the early days of cloud was there was a lot of finger-pointing going on when something bad would happen. Let\u2019s say a vulnerability would be found, or a zero-day event happened, there was this confusion around, \u2018Is that the cloud service provider\u2019s responsibility? Is that a contractor\u2019s responsibility? Is that the government\u2019s responsibility or somebody else? Who really is responsible?\u2019\u201d Raj Iyer, ServiceNow\u2019s global head of public sector and a former chief information officer of the Army, told Federal News Network.\nLearn more about your ad choices. Visit podcastchoices.com/adchoices