NASA seeks cybersecurity and privacy enterprise support
NASA wants contract personnel to provide cybersecurity and privacy enterprise solutions and services (CyPrESS) in support of all its centers and facilities, according to a request for proposals (RFP).
The contract will consist of a single award for an indefinite-delivery, indefinite-quantity contract of solutions and services over a nine-year period.
NASA‘s IT Procurement Office issued the RFP on behalf of its Office of the CIO in June.
The cost-plus-award fee (CPAF) contract covers CPAF and firm-fixed-price task orders, with the latter being phased in over a 60-day period at the outset.
A top-secret facilities clearance is required.
NASA anticipates making its award Nov. 8 and beginning core work on Feb. 1, 2022.
CMMC assessment requirements could be changing, potentially raising costs for some
The cost of some Cybersecurity Maturity Model Certification assessments could soon increase as the Department of Defense considers introducing new requirements, four people familiar with the matter told FedScoop.
DOD and the CMMC Accreditation Body are working to finalize requirements that could mandate having more experienced — and expensive — assessors conduct the needed tests of contractor networks that transmit controlled unclassified information. In effect, it could raise the price for some assessments as the per-hour cost of provisional assessors is higher than the original plan.
“Anything that is going to drive up the costs … is going to be detrimental to the small business community,” Michael Dunbar, a small business owner who recently testified before Congress on behalf of the small business trade association HUBZone Contractors National Trade Council, said in an interview.
CMMC requires third-party verification that all DOD contractors meet one of five levels of security established under the rule. DOD has maintained the majority of contractors will only need to meet level one, with least number of security controls.
While the proposed requirement is not finalized and would only apply to CMMC level three assessments for companies that handle the department’s controlled unclassified information, it is part of a growing list of ideas that the DOD CMMC Program Management Office is generating that several people familiar with the process worry will negatively impact the program’s cost and timely implementation.
Two people directly familiar with the process described it as DOD throwing out ideas without fully thinking through the effects, adding that the final requirements have not been published because DOD continues to add to them.
Under the changes, for an assessment at level three, Certified Third Party Assessor Organizations (C3PAOs) would need to hire four full-time provisional assessors. It was previously understood that these authorized assessment companies would only need to hire one assessor and three “registered practitioners” — entry-level assessors that do not meet the standards needed to become an assessor — to conduct a level three assessment.
To be eligible to be an assessor for level three assessments, an applicant needs at least four years of cyber or IT experience and to pass through on levels one and two first, according to the CMMC Accreditation Body’s website, which manages the ecosystem.
The proposed change to requiring four assessors has already been communicated to at least one of the first C3PAOs that will be doing level three assessments. Other potential changes include having quality control employees and new standards for the assessors be imposed on organizations.
“It’s my understanding that they are moving away from having the provisional assessors and registered practitioners and just having provisional assessors doing assessments,” Justin Padilla, CMMC lead at Kratos, said in an interview.
Padilla sees it less as an issue around costs or quality but as another reduction in the supply of resources necessary to implement the CMMC program. With 300,000 contractors eventually needing assessments at one of the five levels, and now even fewer people eligible to conduct level three assessments, the possibility of a demand crunch is growing.
“It’s more of a limited resource issue,” Padilla said, adding that Kratos has been lucky to have a few employees be selected to take the provisional training.
The DOD and the CMMC Accreditation Body did not return a request for comment.
GAO encourages agencies to improve forensic algorithm standards in new report
Agencies and Congress should consider improving standards, training and transparency around forensic algorithms to help analysts better use them in criminal investigations, according to a Government Accountability Office technology assessment released Tuesday.
GAO found such algorithms strengthen forensic analysis by improving the speed and objectivity of investigations, but their usefulness is limited by the human error and cognitive bias introduced by analysts.
The tech assessment comes two months after GAO released a report describing how the forensic algorithms used by federal law enforcement work and one week after the watchdog warned more than a dozen agencies using facial recognition, one of three primary forensic algorithms, couldn’t account for which systems they use — increasing public distrust of the technology.
“Policymakers could support the development and implementation of standards and policies related to law enforcement testing, procurement, and use to improve consistency and reduce the risk of misuse,” reads the assessment. “This could help address the challenges we identified related to human involvement, public confidence, and interpreting and communicating results.”
While both the National Institute of Standards and Technology and the Organization of Scientific Area Committees for Forensic Science (OSAC), are already developing standards for forensic algorithms, a new federal forensic oversight body may be in order. The other option is assigning a greater role to NIST and other agencies, according to GAO.
The three primary forensic algorithms are: latent print, facial recognition and probabilistic genotyping.
Both latent print and facial recognition search larger databases faster and more consistently than analysts, but poor quality prints reduce the accuracy of the former and human involvement introduces errors with the latter. Agencies further struggle to test and procure the most accurate facial recognition algorithms and find ones with minimal performance differences across demographic groups.
Meanwhile probabilistic genotyping helps analysts evaluate a wider variety of DNA evidence, that may have multiple contributors or be partially degraded, and compare it with samples from persons of interest. But evaluating such algorithms’ performance is complex, and there are no standards for interpreting or communicating the results.
Developing standards around the appropriate use of algorithms will reduce improper use if data quality is addressed and improve confidence in their use by enforcing consistency across law enforcement agencies, as well as streamlining testing and performance in the case of facial recognition, according to GAO.
The challenge will be implementing standards across all levels of government because agencies and localities may not want to confirm. The cost of procuring and maintaining algorithms could also rise, and researching and testing standards is already resource-intensive, according to GAO.
GAO also suggested agencies and Congress consider increasing algorithm training for analysts and investigators, which would reduce human error and improve cognitive bias. A certification process could reduce improper use at federal and non-federal labs.
The challenge would be developing and distributing training materials and determining what agencies are in charge of a certification process, according to GAO.
Lastly GAO suggested increasing transparency to improve trust by providing more information on algorithm testing results, data sources, use and investigations. Better comparative results could even help other agencies select better algorithms.
GAO foresees developers potentially resisting release of proprietary algorithm information, and the sharing of data sources could create privacy risks.
The watchdog agency made it clear that nothing suggested in its assessment constituted a formal recommendation, and no legal changes were proposed in the report to the House Science Committee leadership and Rep. Mark Takano, D-Calif.
DISA launches broadband satellite contract worth $980M
The Defense Information Systems Agency is soliciting bids for a contractor to service a 10-year commercial broadband satellite program.
The contract has a ceiling of up to $979.8 million and is structured as an indefinite-delivery, indefinite-quantity contract, against which the agency intends to award firm-fixed-price task orders.
According to documents filed on Sam.gov, the new contract is intended to augment government-owned and operated telecommunications systems and to provide additional redundancy to meet critical mission requirements. It will be structured as a three-year base period, three two-year option periods, and another final option period.
It will replace an existing contract that provides connectivity between Navy and Military Sealift Command (MSC) ships and Navy designated points of presence.
The government expects to award a single contract from the bid process.
Booz Allen civil business chief lays out strategy post-Liberty IT acquisition
Booz Allen Hamilton’s head of civil business has said that fulfilling existing contracts with the Department of Veterans Affairs is the consulting company’s “number one” job following its acquisition of technology provider Liberty, but that the deal presents growth opportunities for the federal contracting giant in other areas of government.
Kristine Martin Anderson spoke to FedScoop after Booz Allen last month closed its $725 million acquisition of Liberty IT Solutions, which has a $2 billion order backlog and specializes in working on healthcare-related digital technology missions for federal agencies.
“In the civilian space, we have been — for a few years — pushing further and further into technology around transformation of the citizen experience,” said Martin Anderson, who is executive vice president at Booz Allen and leads the company’s civil business. “Job number one is to do that work for VA, but then second to that, with their advancements around low code-no code and API development, we obviously see throughout our business in civil that they will help us scale.”
The VA is among the company’s largest clients, and Liberty is currently one of 24 sub-contractors supporting the rollout of the VA’s $10 billion electronic health record modernization program. Following the acquisition, which was funded by a combination of cash and debt, Liberty IT will be a wholly-owned subsidiary of Booz Allen.
Liberty IT Solutions specializes in the provision of low-code and no-code solutions for federal agencies and has a special relationship with Salesforce, which the company says enables projects to be undertaken quickly.
Martin Anderson explained that following the acquisition, the two companies are working to integrate their systems to allow Booz to offer its digital cyber and AI systems to Liberty clients also.
The executive noted also that Booz Allen Hamilton operates as a single P&L balance sheet, and that Liberty’s resources in the future could be deployed across other business areas including defense and intelligence.
“The appeal of the approach Liberty takes with Salesforce and low-code, no-code solutions is speed. With a traditional IT project, you might spend 18 months getting to the initial operating capability,” she said. “With the low-code, no-code platforms, you can see progress within 90-100 days, so I certainly think the market that has developed from low-code, no-code – while it won’t be everything – will continue to accelerate, and we’re going to see, with agile, and DevSecOps, and cloud.”
Responding to questions about potential further acquisitions within Booz Allen’s public sector division, Martin Anderson said the company is always looking for organizations with aligning strategy and culture, “at the right price.”
Commenting more broadly on the challenges for federal contractors that can accompany an administration change, Martin Anderson said Booz Allen tries to remain focused on missions where demand for services will always be required.
“On the one hand, you could say we are aligned well for the priorities of the Biden administration – and it’s true, we are – there are areas, key missions in civil we are focused on, that are also areas where there is still interest in this administration,” she said. “But we really do try to focus on the enduring missions. What are those missions where the government must provide the service no matter what?”
VA giving ‘insufficient’ training on electronic health records, IG warns
The Department of Veterans Affairs is not giving sufficient training to medical staff on the new electronic health records systems it is rolling out across the country, the inspector general found in a new report.
The lack of training has stopped clinicians from using the system in the ways it was designed, the report shows. The new IT system is a part of the VA’s $16 billion electronic health records modernization program first launched in the Mann-Grandstaff facility in Spokane, Washington. The rollout has been plagued by a range of issues, from several delays due to training issue and warnings of weak testing. The program was paused while it underwent a “strategic review” by the new secretary.
In a separate report, the IG found that VA underestimated the costs associated with upgrading the IT infrastructure that will support the new EHR system, by as much as $2.5 billion. Cost overruns could bring additional Congressional scrutiny to a program already under lawmaker’s microscopes.
“During this review, the OIG found that VA OEHRM failed in that the approved curriculum had significant deficiencies in training content, training delivery, and its ability to assess the efficacy of the training delivered,” the report states.
The training software provided to staff does not closely resemble the final product being rolled out, the IG found. The discrepancy on its own would have caused confusion even if the training went smoothly, but its execution was botched by assigning users to training that didn’t fit their jobs. The training was focused on specific tasks and not on the wide-ranging clinical scenarios staff at Mann-Grandstaff have to respond to, processes called “workflows,” in the report.
“Facility staff reported an absence of workflow training content and associated reference materials that prevented them from not only understanding how to apply what little they had learned to their daily work, but also prevented a basic understanding of the meaning behind workflow processes,” the report stated.
The report found that leaders at the facility coined the term “button-ology” to refer to training as it only provided information on what button to push and now how to use the tech in real world scenarios.
The inefficient training has led staffers to have a lack of trust in the system, a survey included in the report found. A majority of users said they do not feel they can navigate the applications, access patient information or easily share it, or that they have the ability to document patient care in the new system. Only 5% of users responded positively to all four questions, the survey result said.
“Overall, the survey results showed that after training and two to three months of new EHR use, only a small percent of facility users reported facile use with EHR core functions,” the report states.
The training issues come as more reports of cost over runs question if the VA will need to ask for more money to support the system’s nation-wide roll out. The IT infrastructure upgrades for EHR system was initially projected to cost $4.3 billion, which could be as much as $2.5 billion short.
One of the challenges in understanding how much the EHR system will cost is that the money is split between general Office of IT infrastructure upgrades and those specific to the EHR system. The VA is required to file reports to Congress on the costs associated with the EHR program,
“[T]here were inadequate procedures for determining if a cost-estimate update is needed in the office’s congressionally mandated reports,” the report states.
Another recent report pointed to similar issues on the physical infrastructure cost estimates. The secretary also noted in recent congressional testimony that costs might increase if the VA needs to surge additional resources to each medical facility that gets the EHR system as the department had to do at Mann-Grandstaff.
“It does appear to be requiring a lot more people on the target in Spokane,” he told the House Veterans Affairs’ committee in March.
Experts urge OMB to ensure agencies budget for evidence-based policymaking
The Office of Management and Budget should ensure agencies budget for evidence-based policymaking in their fiscal 2023 requests to Congress to address national crises, said members of the evidence-building community Wednesday.
Agencies can use set-aside authorities, working capital funds and recaptured unobligated balances to implement OMB‘s June memo, which outlined a process for developing learning agendas and annual evaluation plans.
While the Foundations for Evidence-Based Policymaking Act established critical leadership positions and activities to facilitate a culture of evidence, it amounted to an unfunded mandate that only applied to the 24 CFO Act agencies and still has guidance outstanding. OMB’s latest memo applies to all agencies and establishes evaluation as a “central function” of government, on par with budgeting and human resources, but doesn’t fully address the “long-underfunded” evidence-building community, said Nick Hart, president of the Data Foundation, during an event it hosted.
“Having just issued this memo saying agencies need resources, I might even lean in here and say it’s incumbent on OMB to make sure that’s part of budget requests that are sent to Congress,” Hart said. “It’s also incumbent on Congress, having authorized the Evidence Act, to ensure agencies have the resources to make it real.”
The Evidence Act required agencies to appoint a chief data officer, evaluation officer and statistical official, but the teams of the latter two are often small or nonexistent and under-resourced. For that reason they need to strengthen collaboration with each other, which OMB’s memo doesn’t address, said Melissa Chu, deputy director of the Committee on National Statistics at the National Academies and a former Department of Veterans Affairs and Census Bureau staffer.
Statistical agencies can help evaluation offices by determining what data is useful, promoting data stewardship and scientific integrity, providing technical assistance for quantitative efforts, and strategizing around evidence use. Collaboration is especially important because the Evidence Act directs statistical agencies to expand data access for evidence building, but Phase 3 guidance hasn’t been released by OMB — nor has Phase 2 guidance for the OPEN Government Data Act.
“There is an entire [Evidence Act] title around data governance and open data, for which there is not currently guidance,” Hart said. “There is an entire title around confidential data, protection of statistical information for which the regulations and guidance have not yet been issued, so if we want the ecosystem to succeed, we also need to keep those pieces moving along as well.”
Meanwhile evaluation offices can help boost the social and policy relevance of statistical agencies, Chu said.
OMB did not respond to a request for comment by publication time.
While CDOs, evaluation officers and statistical officials serve as the pillars of evidence building, they may lack the expertise needed to form partnerships for additional resources. For that, additional team members are needed to address stakeholder engagement and also equity, said Lisa Aponte-Soto, a board member at the American Evaluation Association.
“One thing I would caution is there seems to be a lot of intentionality around providing clarity in operationalizing certain terminology but not around diversity and equity,” Aponte-Soto said. “And I would like more clarity around that.”
DOD budget request includes 8% IT spending boost — Govini
The Department of Defense requested a 7.8% increase in its fiscal 2022 budget for IT, according to new analysis from data science company Govini.
According to the company, the increase comes mostly from the “general IT” spending subcategory, which would get an 8.4% boost to $5.6 billion, and “enterprise comms,” where spending rose by 23% to $2.3 billion. In total, the department requested $34.8 billion for IT, according to the analysis of the president’s budget request and other data published as part of Govini’s 8th annual “Federal Scorecard.”
Govini uses propriety machine learning to churn through massive data sets to inform its budget crunching. The 88-page document compares multiple years of DOD budget requests that outline different administrations’ defense spending against their stated priorities.
“I would’ve dearly loved to have this type of information readily available to me,” Bob Work, former deputy secretary of defense in the Obama administration and chairman of Govini’s board, said during a media roundtable unveiling the report. During his tenure, Work was a key strategist in developing the department’s new thinking on technology like artificial intelligence, and he said that the report showed progress in increasing AI spending.
For now, the fiscal 2022 budget request that the report analyzes is just that: a budget request that Congress still needs to approve before money can actually flow to the DOD. It does, however, serve as a blueprint for the budget and shows where the administration wants to put money. Lawmakers have criticized DOD’s own budget request summary on its IT spending, saying it was vague and lacked consistency in what counted as cyber and IT spending.
In the IT and Command, Control, Communications, Computers, Intelligence, Surveillance and Reconnaissance (C4ISR) budget breakdown, other categories of increase include naval tactical comms by 2.8% to $2.6 billion, medical IT by 6.9% to $2.2 billion and an “other” category by 12.5% to $18.3 billion. SONAR, ground tactical comms and ISR sensors all decreased.
Jim Mitre, chief strategy officer at Govini, said that the increases continue a trend from the previous year that shows the importance of IT in war.
“The future character of warfare will be defined more by information than by hardware,” he said.
Inside DOD’s JEDI replacement, the Joint Warfighter Cloud Capability
After years of pursuing a single-vendor model for its general-purpose, enterprise cloud under the Joint Enterprise Defense Infrastructure (JEDI) acquisition and failing to move it into operation, the Department of Defense announced this week it will pivot to a multi-vendor enterprise cloud acquisition called the Joint Warfighter Cloud Capability (JWCC), issuing a presoliciation notice to industry.
While details of the forthcoming JWCC are limited for now, DOD acting CIO John Sherman revealed some key changes for the procurement. The department will look to issue multiple direct awards with cloud service providers and is also intending to seek proposals from JEDI-winner Microsoft and its main competitor Amazon. Several years down the road, DOD will also pursue a “larger, full-and-open” multi-cloud procurement.
Sherman said the new program will “fill our urgent unmet requirements for a multi-vendor enterprise cloud spanning the entire department in all three security levels, with availability from [the Continental U.S.] to the tactical edge at scale. JWCC will enable us to fulfill the promise of transformational activities such as Joint All-Domain Command and Control, or JADC2, and the Artificial Intelligence and Data Acceleration or AIDA initiative.”
While the continued protests of JEDI undoubtedly impacted DOD’s decision to cancel the beleaguered contract Tuesday, Sherman said even if it had gone into operation as intended after award, “we would have been having this multi-cloud discussion right about now anyway” due to the evolving needs of the department.
Though the DOD has a variety of existing vehicles to work with each of these cloud providers in place, like milCloud 2.0 and others, Sherman said there is “nothing to the extent and reach that the enterprise capability we’re seeking to acquire from this will provide through JWCC — truly from the headquarters to the tactical edge in all three security levels at scale.”
Where JEDI was a potential 10-year, $10 billion contract with an open competition, JWCC will be a maximum five-year vehicle worth multiple billions. The new contract also differs in that only those providers that the DOD believes meet its requirements will receive “direct” solicitations to submit proposals for contracts. While Sherman said Amazon and Microsoft both qualify, he clarified that they will not automatically be awarded anything; rather, they will be asked to submit proposals.
Each cloud provider will need to be able to offer services at the unclassified, secret and top-secret security levels, with parity across each of those levels. On top of that, the procurement’s basic requirements call for integrated cross-domain solutions, global availability including at the tactical edge and enhanced cybersecurity controls.
On the topic of price, that will be determined later in the procurement, Sherman said, emphasizing that people shouldn’t get fixated on a certain figure.
Over the next several months, the DOD will conduct market research and industry outreach to confirm its plans for the procurement and the companies that qualify to submit proposals, launching a final solicitation by mid-October, Sherman said. The hope is to issue final awards by “about April 2022.”
“Over the next roughly three months, we will conduct this additional research and direct engagements with other U.S. hyperscale cloud service providers or CSPs to ensure our assessments are accurate and based on the company’s latest information,” he said, noting that the department will be in close touch with other providers like IBM, Google and Oracle to see if they qualify to participate. “If we determine that additional vendors can also meet our requirements, then we will extend solicitations to them as well.”
Asked for his thoughts if there may be companies left out that may inevitably protest, forcing the JWCC acquisition to drag out like JEDI did, Sherman said if a provider is interested in participating, he and his team will be working with them to “hear fully their company’s capabilities.
“We’re going to be asking for artifacts and engagement to ensure that if they’re able to meet the level we need, that we get all that information and keep that door open through October,” he said. “That’s how we’re going to approach this. And whereas we can never control for every factor, our openness of this is going to be critical on that point.”
The direct awards with the providers will be indefinite-delivery, indefinite-quantity contracts that span a three-year base period and two optional years.
“We believe this contract period is both appropriately brief for a direct award but long enough for us to start to leverage the new enterprise capabilities as we fully develop our longer-term plan,” Sherman said.
Based on the timeline, as soon as 2025, the department could then move into a full-and-open competition that would follow on this initial acquisition, if the department deems it’s ready, Sherman said. “Once the second year of this direct award phase starts, roughly in 2023, for the next two years, we’re going to be working on the scoping and other activities to get ready for that larger, full-and-open competition.”
While the DOD Office of the CIO has ultimate oversight of the acquisition strategy, the Cloud Computing Program Officer within the Defense Information Systems Agency will lead the management and operation of any activities under JWCC and integration among providers.
Former Air Force procurement leader Roper named CEO of drone firm Volansi
Former Air Force Assistant Secretary for Acquisition, Technology and Logistics, Will Roper, has been named CEO of a drone company that specializes in medium-sized autonomous drones.
Roper will lead Volansi, which makes autonomous drones that can carry medium- and heavy-sized payloads. While in the Department of Defense, he was one of the biggest public advocates for the adopting of military technology, often saying that it was critical for services to work more closely with the private sector.
“The company’s [vertical take-off and landing] designs are well-suited for a range of commercial and military applications,” Roper said in a release about his new job. “It felt like a natural fit for me to bring my industry knowledge as well as operations and logistics experience to help create disruptive solutions for the transportation of medium to heavy weight payloads. It’s an exciting opportunity.”
Roper had said autonomous drones would be a critical part of the Air Force’s future operations when he was leading the service’s procurement efforts. He spearheaded a drone program called “Skyborg” and others that incorporated the tech.
“Attracting Dr. Roper, first to our Board of Directors and now as CEO, will help us surpass even our most ambitious goals,” founding CEO Hannan Parvizian said in the release. Parvizian will move to be chief technology officer upon Roper’s joining.