Cloud Access Point
A Cloud Access Point (CAP) is a security capability that connects the Department of Defense's internal network to commercial cloud services while protecting that network from threats originating in the cloud. It handles the connection between DoD networks and the cloud provider and provides boundary protection so that traffic can be monitored and filtered. In most DoD implementations, the CAP is a required part of the architecture for hosting mission systems in a commercial cloud.
Within the DoD Secure Cloud Computing Architecture (SCCA), a Cloud Access Point (CAP) is the capability that connects the Defense Information Systems Network (DISN) or NIPRNet to a commercial Cloud Service Offering (CSO), performing interface translations necessary for CSO compatibility and providing boundary protection of the DISN. According to the referenced evidence, CAP variants include the Boundary CAP (BCAP) and the Internal CAP (ICAP), among others; the BCAP is intended to protect the DISN from attacks originating in the cloud environment and performs functions such as intrusion detection. Note that ICAP in this context denotes 'Internal Cloud Access Point,' not an 'Internet CAP.' Practitioners should treat the CAP as one element of a broader secure cloud architecture and confirm the current authoritative definitions, variants, and connection requirements against the applicable revision of the DISN Connection Process Guide and DoD Cloud Computing SRG, as terminology and requirements may change across revisions.
Why it matters
The Cloud Access Point matters because it is the enforced boundary between the Department of Defense's internal networks and the commercial cloud services where mission systems increasingly run. Without a controlled point of connection, traffic moving between the DISN or NIPRNet and a commercial Cloud Service Offering would not be consistently monitored, filtered, or defended against threats originating in the cloud environment. The CAP concept exists so that DoD can adopt commercial cloud while still protecting the internal network it connects to, which is why it is generally a required element of the architecture for hosting DoD mission systems in a commercial cloud.
For practitioners, the CAP is a reminder that using an authorized commercial cloud is not the same as being connected to it securely. A Cloud Service Offering may carry a FedRAMP or DoD provisional authorization, but connecting that offering to the DISN generally still requires meeting DoD boundary-protection and connection requirements, of which the CAP is one part. Treating a cloud authorization as if it automatically satisfies DoD connection requirements is a common mistake; the CAP is where those DoD-specific network protection obligations are enforced.
Because the CAP is only one element of a broader secure cloud architecture, and because DoD terminology, variants, and connection requirements change across revisions, readers should confirm current details against the applicable revision of the DISN Connection Process Guide and the DoD Cloud Computing SRG rather than relying on any single description as permanent.
Who it's relevant to
Inside CAP
Common questions
Answers to the questions practitioners most commonly ask about CAP.