Hacker News new | past | comments | ask | show | jobs | submit login

Do you work with OpenAI models via FedRAMP GGC High Azure? If so I would love to hear more about your experience.





No, but have heard many rumors they are eyeing their own IL4 environment (apparently Azure has been a bad partner and is months behind on models)

I personally just warn customers that it cannot technically handle CUI or higher, can't say that it stops them


I ask, because according to MS...

"GPT-4o is now available as part of Azure OpenAI Service for Azure Government and included as part of this latest FedRAMP High and DoD IL4/IL5 Authorization."

...we have everything setup in Azure but are weary to start using with CUI. Our DoD contacts think it's good to go, but nobody wants to go on record as giving the go-ahead.

https://devblogs.microsoft.com/azuregov/azure-openai-fedramp...

https://learn.microsoft.com/en-us/azure/azure-government/com...


Ah by “it” I meant OpenAI commercial. Azure OpenAI can handle CUI Basic.

They also have a deployment on SIPR rated for secret.

Anything higher, you need a special key but AWS Bedrock has Claude up on C2S.

That being said both Azure OpenAI and AWS Bedrock suck for many reasons and they will by default extend your system boundary (meaning you need to extend your ATO). Also, for CUI, it has the P-ATO from JAB, not many agency specific ATOs, which means you will probably need to submit it thru your agency sponsor.


Gotcha. We happen to be on government Azure as a contractor, which took years to secure (and one reason our execs want to be beyond sure everything is locked down)

Have they given a reason for being hesitant? The whole point of IL4+ is that they handle CUI (and higher). The whole point of services provided for these levels is that they meet the requirements.

The following is required from the company using a provisionally authorized vendor service:

* organization required to perform a Risk Assessment (is this standardized?)

* organization must issue an Authority to Operate (ATO) (example? to whom?) to use it for CUI as the data owner.

* organization must ensure data is encrypted properly both at rest and in transit (is plain text typed into a chat window encrypted at rest?).

* organization must ensure the system is documented in a System Security Plan (SSP) (example?).

* organization must get approval from government sponsor of each project to use CUI with AI tools

I am the one pushing for adoption, but don't have the time or FedRAMP/DISA expertise, and our FSO/CISO would rather we just not.


I'd be interested to hear if that's even possible.

GCCH is typically 6-12 months behind in feature set.


See my comment above.



Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: