Lawmakers push DOJ to investigate China Initiative after engineer’s mistrial

Democratic lawmakers urged the Department of Justice to investigate FBI misconduct under an initiative for prosecuting people stealing trade secrets, hacking or spying for China, in a letter published last week.

The note specifically asks DOJ Inspector General Michael Horowitz to look into the failed prosecution of Anming Hu, a former engineering professor at the University of Tennessee, who was fired after FBI agents told his employer he was suspected of stealing government secrets for the Chinese military.

Hu was the first person prosecuted under the Trump administration’s China Initiative, the methods of which are being questioned after a jury deadlocked in his trial June 16 — following testimony from the investigating FBI agent that he spent 21 months surveilling Hu but doesn’t believe he was ever a spy, reported the Knoxville News Sentinel.

“As members of the House Judiciary Committee, we are deeply troubled by the alleged misconduct of the [FBI] in the unsuccessful prosecution of University of Tennessee at Knoxville associate professor Anming Hu,” reads the letter. “The FBI allegedly falsely accused professor Hu of being a Chinese spy; falsely implicated professor Hu as an operative for the Chinese military; and used false information to put professor Hu on the federal no-fly list — among a number of other actions.”

Reps. Ted Lieu, Calif., Mondaire Jones, N.Y., and Pramila Jayapal, Wash., want Horowitz to determine if the China Initiative pressures personnel at DOJ, which includes the FBI, into racially and ethnically profiling people.

During his testimony, FBI Agent Kujtim Sadiku couldn’t recall who tipped him off Hu might be a spy and said he’d encouraged Hu to attend a symposium in China and report back on security concerns, reported the News Sentinel.

When Hu refused, FBI surveillance began, Hu’s bosses were informed and he was ultimately charged, not with espionage, but fraud for concealing his affiliation with Beijing University of Technology while receiving NASA funding — an accusation Hu denies.

Chinese universities are considered to be incorporated under Chinese law. As such, U.S. laws that prevent high-ranking federal employees from working for Chinese companies can also prevent them from working at Chinese universities.

The letter asks Horowitz to investigate whether false information was used against Hu and whether false accusations were made. It also calls for clarification over whether the Department of Justice was aware of concerns over false accusations, and whether racial or ethnic profiling occurred.

In the missive, lawmakers also seek to determine whether the decision to open an investigation was based on adequate facts and whether the China initiative pressures DOJ personnel into profiling people.

The Department of Justice did not respond to a request for comment.

Navy looks to onboard 472,000 users to new virtual environment by end of September

Now that the Department of Defense has transitioned away from its temporary virtual collaboration environment developed to support remote work during the pandemic, the Navy has launched its own more secure long-term solution and is working to onboard hundreds of thousands of sailors and Marines to the new platform.

Called Flank Speed, the new virtual collaboration environment is built around Microsoft Office 365 cloud software — much like the DOD’s now-retired Commercial Virtual Remote (CVR) environment launched in the early days of COVID-19 telework — but with added security, Mike Galbraith, Navy’s chief digital innovation officer, said Tuesday at VMware’s Public Sector Innovation Summit, produced by FedScoop.

The CVR environment, which was taken offline June 15, “was a godsend, but it wasn’t perfect. If it was perfect, we’d still be using it,” Galbraith said, explaining that CVR was only authorized for data transmission at the IL2 level for any information cleared for public release. The Department of the Navy‘s Navy-Marine Corps Intranet (NMCI) instance of Office 365 will also expire Oct. 1.

Flank Speed falls under the larger DOD365 cloud collaboration platform being rolled out across the department and is authorized up to IL5, accomodating controlled unclassified information that may deal with national security systems. The environment will offer access to Microsoft Teams, a terabyte of OneDrive cloud storage, and access to Microsoft 365’s Excel, Word, OneNote, and PowerPoint.

“It’s secured. It is cloud-based, like CVR. But in a very secure and defendable place where CVR had a couple of holes,” Galbraith said, later emphasizing the importance of “weaving that thread of security through everything — securing our data, securing our devices, securing our networks and our transport.”

He also called Flank Speed a “catalyst for our zero-trust architecture, which is built into that network and transport model that we have designed.”

Galbraith said it’s called Flank Speed — based on the Navy term for a ship’s maximum speed and given as an order to escape danger — because “we are moving very quickly” to give some 472,000 users access to the platform before the close of fiscal 2021.

The Navy began transitioning users to the new environment June 1, selecting an initial set of “260,000 current users of CVR and NMCI O365” who have begun moving over first, according to a release. As network performance gets better over time, more users will be gradually added.

Moving to CVR last year was “bumpy,” Galbraith said, and moving to Flank Speed will be no different.

“There’s some cultural change that’s going on,” he said. “So very similar to CVR where it was bumpy to begin with, our Flank Speed implementation in the Department of Navy, it’s going to be a little bumpy as well as we migrate users in a phased way, as we migrate and bring technical capabilities into that environment a piece at a time. And it’s happening very quickly, with every day new capabilities being added by the team.”

Robin Carnahan confirmed to lead GSA

Robin Carnahan,  was confirmed by the Senate as Administrator of the General Services Administration Wednesday afternoon.

She was confirmed by voice vote, meaning there was not a final tally of yeas or nays on her nomination.

Carnahan founded and led the state and local government practice at 18FGSA‘s tech consultancy, from 2016 to 2020, having previously been Missouri’s secretary of state. She also co-founded the State Software Collaborative as a fellow at Georgetown University’s Beeck Center.

When she was at GSA during the Obama administration, Carnahan helped state and local governments improve their digital services while cutting costs. Her practice taught non-technical officials about IT risk management, procurement and modernization projects.

As Missouri’s secretary of state Carnahan modernized online services for hundreds of thousands of customers related to both elections and securities. A Democrat, she also ran for one of Missouri’s Senate seats in 2010 but lost to Republican Roy Blunt.

Commenting on her appointment, Carnahan said: “I am grateful for the support of the Senate, and I am honored to serve as the next Administrator of GSA.

“GSA is at the heart of creating a government that effectively delivers for the people and taxpayers, and I am committed to doing all I can to support that important mission.”

Dynamic information sharing depends on deploying the right automation

Rob Smallwood is vice president for digital modernization and enterprise IT at General Dynamics Information Technology.

automation

Rob Smallwood, VP, Digital Modernization and Enterprise IT, GDIT

It’s hard to argue against the urgent need for modernizing federal IT systems. What’s often lost in the discussion, however, are the practical considerations of modernizing, given the sheer complexity inherent in managing so many legacy applications across today’s on-premises and cloud environments.

Add to that having to maintain the government’s stringent security requirements; the need to work within multiple security domains; and the challenges of ensuring that data can be accessed safely and at scale anywhere in the world.

That’s why it’s essential for agencies to take a closer look at the power of integrating and automating a combination of state-of-the-art technologies, to handle the astronomical cross-domain workloads that our nation depends on now and in the future. Automating classified cross-domain IT on common infrastructures, for example, would better enable the U.S. to collaborate across security domains, and with our foreign mission partners at previously unrealized scale and efficiency.

That said, the actual work of implementing automation across today’s patch-worked IT systems remains anything but automatic — especially in government and defense circles.

The reasons are as varied as they are familiar. Government policies, acquisition regulations and security demands — on top of an endless sprawl of siloed systems — have buried government IT engineering and maintenance teams under layers upon layers of complexity. As a result, implementing IT automation effectively and securely remains immensely complicated, requiring enormous technical skill and experience to integrate solutions across a wide range of commercial and customized platforms.

Those challenges are increasing as on-premises and cloud-based systems not only become more interconnected, but also more dynamically driven.

Take the Department of Defense, for example, which has committed to establishing a Joint All-Domain Command and Control (JADC2) platform, aimed at gathering and analyzing data from across all domains (sea, air, land, cyber and space) and distributing that information back to those who need it, where and when they need it.

One of the distinct challenges in that endeavor revolves around automating IT services capable of sharing information with our coalition and mission partners. Dynamically provisioning secure and classified IT capabilities across so many security boundaries — and ensuring those capabilities are executed reliably at the “speed of need” — requires mapping out a vast array of digital checkpoints before automating.

Compounding matters are government acquisition rules that historically slow down modernization efforts to a pace some some would describe as the “speed of the policy.” As a consequence, it remains difficult for agencies and their contractors to take advantage of emerging technologies — and the tools to integrate them. The reality is, the rigidity of contract regulations tend to leave little room to anticipate new technology developments coming onto the market, or an avenue to fold them into an existing program.

A better approach

So how can we set up better scenarios so that more and more IT workloads and provisions can be automated within the confines of a single contract?

One way is to transfer the risk of responsibility and the implementation of modernized IT capabilities more fully onto the backs of qualified contractors, using outcome-focused managed IT services model with fixed-priced contracts, much like today’s cloud computing models.

That helps agencies avoid the inevitable traps of cost-plus contracts, which, because of their long runways, routinely lead to technology build-outs that are already out of date by the time they’re turned on— and tend to cost more than expected. Properly structured contracts effectively alleviate the need for agencies to commit to technologies that inevitably become outmoded.

Transferring the burden of risk and liability to experienced contractors it not only incentivizes contractors to innovate more rapidly; it also facilitates automating IT services — and the benefits that automation brings — more quickly.

Those benefits can be immense. Secure automation helps to provision, operate, and sustain critical IT services automatically and dynamically. That in turn speeds up the ability to process, store, analyze and share information that drive and support enterprise missions.

Given the sprawling complexity of government IT systems, the security and regulatory rules that govern them, and the risks inherent in modernizing them, it makes increasing economic sense to partner with contractors deeply familiar with those rules and risks. But agencies should also look for partners with proven experience in assessing the larger, enterprise-wide operating picture across all silos and seams.

That means, for instance, choosing contractors capable of grasping the most complicated operational scenario that an agency might face, and then solve backwards from there. As importantly, you want partners who know how to transition legacy infrastructures and have the ability to field new capabilities and services at the same time.

One of the most extreme scenarios GDIT has tackled, for instance, is how to automate managed services for sharing information of different military classification levels with coalition partners. The task involved not only automating the nation’s most stringent security requirements, but also doing so across some of the most diverse IT environments that exist around the world.

Agencies also need to consider contractors familiar with delivering services on a global scale — while also adapting them to specialized environments. GDIT, for instance, has delivered large swaths of enterprise IT services on defense programs, ranging from the U.S. Battlefield Information Collection and Exploitation System Extended (US BICES-X) to milCloud 2.0, which connects competitively priced, highly secure cloud service offerings to DoD networks. MilCloud 2.0 provides turnkey, high-performance cloud solutions that enable DoD agencies and partners to manage big workloads across different security classifications in ways that commercial providers can’t match.

President Biden recently stated, “America’s alliances are our greatest asset.”  Our ability to connect to them in cyberspace continues to be critical to that alliance. Connecting these governments together in a more automated fashion will remains an ongoing and essential task. Choosing an experienced partner who knows what that looks like, and has the necessary talent and skills, is a key step to getting to the speed of need.

Learn more how GDIT is helping defense and civilian agencies capitalize on the power of IT automation.

Hyten signs new requirements to ensure military services make data accessible

Gen. John Hyten, the vice chair of the joint chiefs of staff and head of the Joint Requirements Oversight Council, has signed four new strategic directives that mandate all U.S. military services to make data accessible for all their weapons and platforms.

The new directives are based off recent “Data Decrees” signed by the Deputy Secretary Kathleen Hicks in May, which give specific advice on data management and call on senior leaders to use the DOD’s Advana platform as a central repository for data analysis that is used to support decision making.

The latest requirements are intended to support the development artificial intelligence systems within the DOD, which require access to vast datasets in order to learn new capabilities. In the private sector, tech giants such as Amazon, Apple and Microsoft have long relied on access to such pools of data for the development of AI-supported search functions such as Alexa and Siri.

“Thee simple requirement will be from this day forward all data form the Department of Defense … will be accessible. period. It has to be that way, there can be no other alternative,” Hyten said.

“Services will have to build their systems to meet that requirement,” he added.

Hyten said that without interoperable and accessible data, further dreams like implementing artificial intelligence can’t become a reality.

Hyten also urged the department to adopt enterprise cloud computing capabilities. Not mentioning the stalled Joint Enterprise Defense Infrastructure (JEDI) by name, Hyten said that without a “real cloud” the DOD won’t be able to use and store all of the newly interoperable and accessible data.

Once the DOD has large, accessible data sets and the cloud capabilities to turn that data in to intelligence, networking together operations across the domains of air, land, sea, space and cyberspace operations will be the new means the DOD thinks about deterrence.

“That will create a deterrent that is nearly as powerful as our nuclear deterrent,” Hyten, who used to lead Strategic Command which controls the U.S. nuclear arsenal, said.

House lawmakers propose $50M for Technology Modernization Fund in 2022

House Democrats published a draft bill Wednesday that would allocate just $50 million to the Technology Modernization Fund during fiscal 2022.

The legislation, which was proposed by lawmakers on the House Appropriations Committee, would provide the TMF with one-tenth of the $500 million requested for the 2022 budget last month by the Biden administration, which also called for $9.8 billion to support civilian cybersecurity programs across government. However, it’s double the sum deposited in the fund in recent appropriations cycles.

TMF earlier this year received a $1 billion emergency injection as part of the American Rescue Plan Act after widespread lobbying by lawmakers and tech advocates for nearly a year. Federal agencies have drawn on the TMF to support long-term technology modernization, including DHS, which has applied for money from the fund to support at least four projects.

Budget funding requests are determined by lawmakers on the House and Senate appropriations committees. It is relatively unusual for House lawmakers to advocate for a sharp reduction in requested funds.

The legislation also provides funding of $34 million for the U.S. Treasury to cover a range of measures including technology modernization, and it also would approve a separate $132 million funding pool for the enhancement of cybersecurity systems at the department.

If enacted, it will also provide the Treasury’s CIO with $4 million to cover administrative expenses incurred while making cybersecurity improvements.

The draft legislation also outlines provisions for the IRS to receive $305 million for necessary expenses relating to business systems modernization.

Under the proposal, the Office of Management and Budget would receive $10.4 million for technology and the Office of Personnel Management would get $8.8 million for IT modernization and trust fund federal financial system migration or modernization.

The draft bill also would approve a budget for the newly created role of National Cyber Director, providing $15 million in funding for the position for the fiscal year.

GSA creates $2.1B contract for NOAA’s IT

The General Services Administration has created a $2.1 billion contract that will allow the National Oceanic and Atmospheric Administration to buy IT tools and services from small businesses faster.

Launched as a 10-year, multiple-award blanket purchase agreement off of GSA‘s Multiple Award Schedule (MAS), the NOAA Mission IT Services (NMITS) contract covers application administration, enterprise and cloud computing, cybersecurity and information assurance.

The contract is part of a broader effort by GSA to standardize requirements, thereby streamlining governmentwide acquisition, through its MAS program.

“NOAA’s missions are vitally dependent on IT services,” Zachary Goldstein, chief information officer at NOAA, said in an announcement Wednesday. “With the award of NMITS, NOAA can more rapidly access highly qualified private sector talent, a key to cost-effectively operating and modernizing our information management environment, and advance our service to the American people.”

NMITS consists of five base years and a five-year option period and will be administered by NOAA’s Office of the CIO and other NOAA offices.

GSA’s MAS covers more than 7.5 million IT products and services from more than 4,600 pre-vetted suppliers and is available to federal, state, local and tribal agencies. By streamlining IT acquisition under a single category on the contract, it has reduced buying cycles by up to 50%, GSA says.

“These types of solutions make it easier and allow our partners to focus on their mission instead of acquisition while helping speed up their procurements,” said Laura Stanton, assistant commissioner of IT Category at GSA. “We pride ourselves on close agency partnerships like this, and we are thrilled to support NOAA with its complex IT needs.”

DHS applied for TMF funding for 4 projects, CIO Hysen says

The Department of Homeland Security has applied for Technology Modernization Fund money to support four of its modernization projects, CIO Eric Hysen said Tuesday.

Hysen intends to make the department an “active user” of the TMF, which recently got a $1 billion injection under the Biden administration’s American Rescue Plan Act, he said at the Professional Services Council’s Federal Acquisition Conference.

DHS‘s four projects run the gamut, from improving the processing of immigrants at the southern border and making “the experience of going through an airport easier, more seamless, and more secure,” Hysen said, to modernizing how DHS components work with data in conjunction with the department’s new Office of the Chief Data Officer and better sharing threat information with state and local law enforcement.

Hysen said DHS is approaching the TMF now differently than it has in the past by looking to apply modernization across the department, rather than focusing only on single components. Customs and Border Protection, a DHS component, won a $15 million TMF award last July to continue modernization of its Automated Commercial System, a mainframe platform that runs on  3.9 million lines of COBOL code to track, control, and process everything imported into the U.S.

“[W]hat we’re trying to do very deliberately is not just use the TMF as an opportunity to look at our big list of unfunded modernization programs that we just need one vendor, we already have a whole plan for, but really to look at common problems and challenges across the department and set up systems and structures that will allow us to move together because we think we can get a lot more done if we modernize in common, aligned ways across DHS components and systems,” he said.

To be clear, Hysen said, he’s not advocating for DHS to build single systems “to rule them all.” Rather, he said, “we want to address these issues holistically from the experience up from the perspective of the people that are depending on DHS, whether those be immigrants, travelers, state and local law enforcement officers, and using the TMF as a way to move to move forward together across different parts of the department.”

Since the $1 billion injection into the fund, the board that leads the TMF award process has introduced a more flexible model for agencies to repay those investments. The board is also prioritizing selecting and funding projects “that cut across agencies, address immediate security gaps, and improve the public’s ability to access government services.”

Zero trust and the cyber EO

Hysen described President Biden’s recent cybersecurity executive order as “one of if not the most ambitious attempts to lay out a new framework for federal cybersecurity ever.”

That order calls for federal agencies to modernize their cybersecurity, namely through the adoption of a zero-trust architecture. Hysen said while that’s the right direction to move in, it’s important to keep in mind that “zero trust is not something we’re going to buy and turn on one day.”

“[I]t’s easy to think about this as, ‘Oh, just buy your zero trust product, turn it on on your network, and then everything will be great,'” Hysen said. “And that is in no way what we’re talking about. When we think about zero trust, we think about, in many ways, a fundamental rethinking of our security architecture, away from this outdated model of perimeter defense — that we can build a wall around our network and everything inside is safe, everything outside is unsafe — and that we have to be securing every system, every server, every endpoint and our data as it moves within our network and outside of it. And that’s going to require a lot of time; this is not going to be something that we do overnight.”

DHS has a zero-trust working group led by its CTO “that’s working across our components to look at different approaches,” Hysen said, adding that the department is working in three-to-four-month sprints to deliver new pieces of the security architecture iteratively. First up, he said, is conditional access and rights management.

“I expect [zero trust] to be something that will only become more important over time, and will be important that we really do this as a marathon…because it is such a fundamental rethinking of our security architecture,” Hysen said.

AWS urges Supreme Court to reject Oracle JEDI review petition

Amazon Web Services has filed a brief with the U.S. Supreme Court urging it to reject an earlier petition by Oracle to renew its challenge to the Pentagon’s $10 billion Joint Enterprise Defense Infrastructure (JEDI) contract.

In a filing on June 18, the web hosting giant says Oracle’s case should not be heard because it relies on the contention that personal conflicts of interest with Department of Defense employees affected the outcome of the case.

“The alleged personal conflicts of interest (which concern the actions of DoD employees, not the actions of AWS) are highly fact-bound and had no effect on Oracle’s exclusion from the competitive range,” Amazon said in its filing to the court.

Oracle in January sought a review of the U.S. Court of Appeals for the Federal Circuit’s decision to uphold lower court rulings, which found it didn’t meet basic security requirements necessary to be considered for the contract. It represented the latest salvo in Oracle’s challenge to the contract, which was first launched in late 2018 alleging that DOD’s decision to award the contract to a single vendor was illegal.

Oracle also raised questions around conflicts of interest involving DOD employees involved in the procurement who went on to take jobs with Amazon — even though Amazon would ultimately lose its bid for JEDI.

In its latest submission to the court, Amazon argues that even if the court were to decide that officials involved in the contract procurement process were open to influence, it would not impact the outcome of the case because Oracle did not meet the basic gate security criteria for the contract.

“Specifically, DoD found that Oracle’s proposal failed to satisfy Gate 1.1, and Oracle conceded that it failed to satisfy Gate 1.2 ‘at the time of proposal,” AWS said in its Supreme Court brief.

AWS argues that it is not the appropriate venue for hearing such allegations because they are “intensely fact-based” and have no clear bearing on the contract’s outcome.

The filing of the brief is the latest step in the long-running dispute, and comes amid continued uncertainty over JEDI.

On Monday, Deputy Secretary of Defense Kathleen Hicks said the DOD could take a new direction on the contract by next month, and that it was “actively looking at [its] options”.

Earlier this month, a Court of Federal Claims judge granted AWS’s requested timeline for hearings in separate litigation objecting to DOD’s award of JEDI to Microsoft. The web hosting giant continues to seek the disclosure of additional internal communications from the Department of Defense, including emails and Slack messages.

This follows a decision in April by the same court to stop the government from dismissing AWS’s allegations of political interference. The DOD in January sent an “information paper” to Congress explaining the potential impacts if the case continued for an extended period.

AWS and Oracle did not immediately respond to a request for comment. A DOD spokesperson declined to comment.

Industry matters when assessing cyber risk to the defense industrial base

Manufacturing and research and development companies — not simply small and medium-sized businesses (SMBs) — bear the highest risk of cyberattacks within the defense industrial base, according to a BlueVoyant report released Tuesday.

The New York City-based cybersecurity company independently analyzed available third-party data from a sample of 300 small and medium-sized defense contractors and found industry mattered more than size in determining cyberattack risk. Smaller businesses remained more susceptible within their industries.

BlueVoyant’s report comes after a string of successful cyberattacks that targeted SMBs and raised the question of whether they, with their limited defenses, offer easiest access to the supply chain. The answer is more nuanced.

“Not only are R&D firms vulnerable, they are particularly attractive to attackers,” reads the report. “R&D firms work on cutting-edge products, develop valuable IP, and often create and sell software and tech that become components in larger and more important systems making them attractive as points of entry for malicious insertion or IP theft.”

More than half of the SMBs assessed had unsecured ports critically vulnerable to potential ransomware attacks, while 48% had those and other severe vulnerabilities, like outdated software or operating systems, rendering them “high risk.”

Nearly 20% of the SMBs had multiple vulnerabilities and showed evidence of threat targeting, while 7% deemed “critical risk” had been compromised in some way.

BlueVoyant found 28% of the firms would likely fail to meet the most basic, level 1 Cybersecurity Maturity Model Certification requirements. That statistic is more troubling with nation-state adversaries and cybercriminals proving increasingly adept at finding the weakest link within supply chains and when exploitable weaknesses abound among SMBs.

Roughly 300,000 companies directly contract with the Department of Defense, and its CMMC requires “significant investment” in new controls from SMBs with limited budgets and technical expertise, according to the report.

Meanwhile, contract primes and other large companies are under “enormous pressure” to reduce the attack surface of their supply chains, without full visibility into the network security of the subcontractors they’re responsible for, according to the report. The financial and logistical costs of designating subcontractors to CMMC tiers and ensuring their compliance isn’t cheap, especially when one business’ tier may vary contract to contract — causing some primes to force their subcontractors to level up.

While BlueVoyant had no way of determining firms’ cybersecurity maturity in line with CMMC compliance, it did recommend companies use continuous cyber monitoring to secure their supply chains. More than six months after the announcements of the F5 and Microsoft Exchange vulnerabilities, nine companies that were either small manufacturers or large R&D companies still hadn’t addressed them due, in part, to reliance on point-in-time compliance assessments.

Most vulnerabilities SMBs had were tied to email security protocols or else unsupported software, suggesting a lack of patching policies and continuous monitoring, according to the report.

Primes should further focus on addressing issues with high-risk subcontractors based on industry and then size, BlueVoyant recommended.

The company believes predictive risk analysis of SMBs is ultimately possible but said a sample size larger than 300 businesses is needed.