Advertisement

North Carolina partners with nonprofit GovRamp to improve cloud software security across state agencies

The goal is to make sure companies that sell cloud software to the state meet the same security standards.
Listen to this article
0:00
Learn more. This feature uses an automated voice, which may result in occasional errors in pronunciation, tone, or sentiment.
(Getty Images)

North Carolina is tightening up how it protects government data stored in the cloud, partnering with GovRAMP, a nonprofit organization that helps standardize cloud security for government procurement. The goal is to make sure companies that sell cloud software to the state meet the same security standards.

North Carolina’s Department of Information Technology announced the new partnership Wednesday as part of a broader push to modernize state technology and lower the risk of cyberattacks. Starting in April, cloud vendors working with executive branch agencies will need to meet GovRAMP’s security requirements. The department also plans to make it easier and faster for agencies to buy secure technology, onboard vendors and launch new online services for residents.

“This is about more than compliance. It’s about trust and progress,” NCDIT secretary and state chief information officer Teena Piccione said in a statement about the partnership. “The public expects secure, reliable services. By adopting a consistent approach, we’re not only protecting the state’s digital assets, but we are empowering agencies to more quickly deliver online services for North Carolinians.”

GovRAMP acts like a security seal of approval. It provides state agencies with a cybersecurity framework, based on recommendations by the National Institute of Standards and Technology, and checks whether cloud companies follow strong cybersecurity practices, including independent audits and ongoing monitoring.

Advertisement

State leaders, like Bernice Russell-Bond, North Carolina’s chief information security officer, said the partnership will better protect sensitive information from threats like data breaches and ransomware.

“Cybersecurity is a shared responsibility,” Russell-Bond said Wednesday. “This partnership builds a stronger foundation for resilience and trust, creating an environment where technology can thrive securely and efficiently.”

With this partnership, North Carolina joins more than 23 states — including Arizona, California, Florida, Georgia, Michigan, Texas and Utah — that already use or recognize the nonprofit’s approach to help evaluate cloud providers.

Sophia Fox-Sowell

Written by Sophia Fox-Sowell

Sophia Fox-Sowell reports on artificial intelligence, cybersecurity and government regulation for StateScoop. She was previously a multimedia producer for CNET, where her coverage focused on private sector innovation in food production, climate change and space through podcasts and video content. She earned her bachelor’s in anthropology at Wagner College and master’s in media innovation from Northeastern University.

Latest Podcasts