Under C2E, IC’s top challenge is turning cloud competitors into partners

The intelligence community has five cloud providers in place to soon deliver capabilities under its multibillion-dollar Commercial Cloud Enterprise (C2E) contract. But now comes the hard part: incentivizing those companies to work together rather than compete for task orders under the larger contract.

Acting intelligence community CIO Michael Waschull pointed to this dynamic of collaborating competitors as the greatest challenge the IC faces in moving to the C2E multi-cloud contract from single-cloud predecessor, the Commercial Cloud Services (C2S) vehicle.

Last fall, the contract manager CIA awarded the cloud services portion of C2E to AmazonGoogleIBMMicrosoft and Oracle. The new multi-cloud contract will have a 15-year period of performance and be worth “tens of billions” of dollars, according to contracting documents. The contract holders will compete for task orders at various levels of classification, up to the top-secret level.

Waschull told FedScoop “the idea of five different world-class cloud providers, bringing their capabilities, their knowledge, skills, and their capacity to bear on our problems and allowing the components within the IC to pick and choose so we can tailor and devise a best-fit molecule of capabilities, that shows great promise.” However, he said, that’s “if and only if I can overcome the one big obstacle that stands in our way: How do we incentivize collaboration, cooperation, communication, and mutual support between and among what are frankly these five competitors.”

The model is ideal for the IC but runs contrary to the values of the profit-driven private sector.

“By their very nature, they are private sector mission partners, they are motivated by profit, they are motivated by competition,” Waschull said. “We’ve got to instill a core value in that we appreciate collaboration and cooperation, more than we appreciate any single technical provision or any single lowest price.”

He added: “We want best value. We want to promote integration of effort, promote each different competitor understanding not only their product lines but understanding the capabilities and limitations of their competitors’ product lines so that they can work together to come up with the best possible technical and business solution to the government’s needs.”

Waschull, who spent part of his career with the Missile Defense Agency, compares this environment to MDA’s model for the Missile Defense National Team, which brings together leaders in the aerospace sector like Lockheed Martin, Boeing and Raytheon to support the agency’s Ballistic Missile Defense System.

“If we can do here, with our cloud efforts, what they have done there with their missile defense efforts and forgo competition in lieu of cooperation and collaboration, we will be in a great place,” he said.

The Department of Defense stands to learn from the IC’s venture into this multi-cloud model after it recently announced it will go down a similar path, canceling its failed single-vendor cloud acquisition, the Joint Enterprise Defense Infrastructure (JEDI).

To further support such a model, the IC is also planning to bring on a systems integrator through a second, separate contract under C2E to help manage this environment — “providing knowledge, skill and ability to help the government make the best possible choices to devise that best-fit formula for cloud capacity and capability,” Waschull said.

In the past, the IC has had consultants to advise on such IT procurements. But this integrator will be a built-in partner whose “award fees are predicated upon helping us make not only the best technical decisions for the implementation of cloud capacity across our enterprise but to understand the various pricing models from each particular vendor,” Waschull said.

“Understanding volume discounts, understanding the way they compute pricing and knowing it so well that they can advise the government to say between two or three equally competitive technical approaches, from a business perspective, this is the way you want to go,” he said. “Having that kind of incentivized professional analysis to help guide the decisions we’re gonna make, I think is wicked powerful.”

The cloud services portion of the C2E contract and the five providers are working to reach initial operational capability status to begin work. Until the integrator contract is awarded, they are supported by the CIA Cloudworks Program Management Office, said Waschull, who meets with the providers individually and as a group on a monthly basis to discuss challenges, opportunities and their perspectives.

When this multi-cloud capability does come online, the “unity of effort sets the stage, sets the table to take us to the next level,” Waschull said.

“When we look at 21st-century warfighting in a peer competitor environment and the volumes of data coming down from our overhead constellations, being generated locally by artificial intelligence and machine learning applications and being exchanged to competitive advantage between and among IC components, warfighters and others — that is a huge problem set,” he said. “But these building blocks really lend themselves to be able to come up with those creative solutions that will enable us to manage the volume and velocity of the information that we’ve got to move around.”

Waschull concluded: “Having these best of breed cloud contributors in the fight with us, if we can find the magic sauce that gets them to work together, cooperatively and collaboratively, we’re going to be in a far more competitive place than our neighbors that we have to deal with in this 21st-century competition.”

OMB reaffirms commitment to hiring diverse cloud tech talent

The Office of Management and Budget has reaffirmed the Biden Administration’s commitment to hiring cloud technology experts from a more diverse talent pool.

In a statement to FedScoop, an agency official said the administration is focused on developing a new talent pipeline, including through workforce exchange programs and partnerships with educational institutions.

“The federal government recognizes the changing workforce and ever-changing technological landscape and is working to support the IT workforce through reskilling, training, career growth opportunities and worker flexibility in order to recruit and hire the best IT talent,” the official said. “The recent executive order made clear that the administration is committed to cultivating a workforce that reflects our country’s diversity – meaning cloud technology experts are being recruited from a diverse talent pool.”

The comments come after the Biden administration last month signed an executive order that mandates agencies take wide-ranging action to increase diversity equity and inclusion.

The OMB spokesperson added that IT workforce exchange programs between the private sector and federal agencies would be key in developing a new talent pipeline.

Under the recent EO, agencies are required to collect enhanced demographic data about federal employees and advance pay equity among public servants. Government departments will be required to look at new channels for staff recruitment, including through striking partnerships with universities and colleges that historically have served minority communities.

The Office of Personnel Management and OMB are overseeing the implementation of the new directive.

Technology recruitment consultants say that deep relationships with educational institutions and broadening the reach of paid internships are among the best ways for agencies both to increase the diversity of cloud talent and to foster innovation.

“This [recent EO] has to open things up, right from paid internships. Those exists – those paid internships exist with two- and four-year degrees, but the positions are not yet available once they got through that to place them in the long-term,” said Britaini Carroll, principal director of Accenture Federal Services’ Human Capital division.

Carroll added that there may also be a case for agencies in some instances to loosen educational requirements for cloud jobs that do not require the highest levels of technical expertise.

Google to provide Air Force’s maintenance office a cloud ‘ecosystem’

The Air Force‘s Rapid Sustainment Office inked a deal with Google Cloud for an “ecosystem” of technologies that will support maintenance operations.

Through the deal, the Air Force will get will receive an “open, agile, and globally scalable ecosystem” of cloud tech, Google said in a release. Dubbed “Project Lighthouse,” it will support everything from predictive maintenance software to augmented reality.

The company would not disclose how much the deal is worth.

“Our partnership with Google Cloud is a significant milestone for RSO on our journey to adopt Industry 4.0 technologies, when everything is connected, and deliver on our mandate to solve the Air Force’s toughest sustainment challenges,” Nathan Parker, deputy of the program executive office at the Air Force RSO, said in a release. “What we’re building with Google Cloud will accelerate the way we adopt, integrate, and scale technologies for the Air Force. Project Lighthouse is a hardware-flexible, software-driven approach that provides optionality at scale.”

The Rapid Sustainment Office has been pushing to use technology to better maintain aircraft. One high-profile project aims to use artificial intelligence to predict when parts will fail. Other initiatives include work to make digital replicas of aircraft, known as digital twins. Many of the goals rely on cloud storage and compute power.

The technology from Google is still being prototyped and tested, the company said.

“We know that sustainment is one of the biggest and most complex challenges in the military, and we are proud to support the RSO in its mission to modernize the U.S. Air Force,” Mike Daniels, vice president of global public sector at Google Cloud, said in the release.

Energy awards $28M to 5 supercomputing projects

The Department of Energy will give $28 million to five research projects developing software for its supercomputers, the Scientific Discovery Through Advanced Computing (SciDAC) program announced Friday.

The projects DOE selected will develop computational methods, algorithms and software benefitting research into quantum information science and chemical reactions with clean energy applications.

SciDAC brings together interdisciplinary groups of experts to make use of DOE’s high-performance computing resources, and the five teams will partner with one or both of its institutes, FASTMath and RAPIDS2, out of the Lawrence Berkeley and Argonne national laboratories.

“DOE’s national labs are home to some of the world’s fastest supercomputers, and with more advanced software programs we can fully harness the power of these supercomputers to make breakthrough discoveries and solve the world’s hardest to crack problems,” said Secretary of Energy Jennifer Granholm in an announcement. “These investments will help sustain U.S. leadership in science, accelerate basic research in energy, and advance solutions to the nation’s clean energy priorities.”

The five awardees are:

  • California Institute of Technology for its project on traversing the “death valley” separating short and long times in non-equilibrium quantum dynamical simulations of real materials;
  • Florida State University for its project on relativistic quantum dynamics in the non-equilibrium regime;
  • Lawrence Berkeley National Lab for its project on large-scale algorithms and software for modeling chemical reactivity in complex systems;
  • University of California-Santa Barbara for its project on real-time dynamics of driven correlated electrons in quantum materials; and
  • University of California-Riverside for its Data-driven Exascale Control of Optically Driven Excitations (DECODE) project dealing with chemical and material systems.

The projects were chosen through a competitive, peer review process under a DOE Funding Opportunity Announcement open to universities, national labs and other research organizations. DOE has yet to negotiate final project details for the awardees, but $7 million of the total funding has been allocated for fiscal 2021, contingent upon congressional appropriations.

Cyber defense strategies that focus on protecting people

Deborah Watson is the resident CISO at Proofpoint with over 20 years’ experience in security.

Cybercrime has become a profitable business model, as evidenced by recent ransomware payments where criminals continue to perfect low-investment, high-return campaigns. While the majority of attacks start in email, the techniques, tools and procedures cybercriminals use are quickly changing. This rapid evolution makes it increasingly difficult for organization leaders to adapt to changes to the threat landscape in a timely manner.

Deborah Watson, Resident CISO, Proofpoint

One of the techniques we see on the rise is social engineering attacks, where malicious actors gather information about the people within an organization to trick users into making security mistakes. Attitudinally, cybercriminals approach people-centric attacks with as much effort, time and resources as they are devoted to understanding vulnerabilities in enterprise networks. Some emails impersonate colleagues and suppliers, taking advantage of employees who strive to be supportive. Other emails leverage reconnaissance information to emulate standard user interfaces resulting in credential theft.

In a threat environment where criminals are strategically targeting people, federal agency leaders may make many assumptions about who represents the most significant risks within the organization. But those assumptions can be wrong when leaders do not have the complete picture of who is vulnerable, privileged and targeted. And while their ecosystem of security tools monitor network activity, cloud environments and endpoint devices, they may be missing an agency’s most outstanding security and compliance risk — its people.

Human error is still the most significant risk factor

Phishing and credential theft are two primary techniques that attackers use to gain access to an organization. Verizon’s 2021 Data Breach Investigations Report found that 94% of breaches start with attacks targeting people via email, which is now the number one threat vector.

Complicating the situation, hackers have evolved from their emails being blatantly fraudulent, increasing the probability that an employee, with limited time, will evaluate an email before opening an attachment or clicking on a URL. It is true that poorly crafted emails still exist and are broadly distributed, but modern email security solutions generally catch those due to their widespread distribution. Today’s attacks are often narrowly targeted and explicitly crafted to subvert traditional email filters as the probability of detection is reduced by the number of emails sent.

While traditional cybersecurity threats have been built based on a linear kill chain — where reconnaissance of system and software vulnerabilities lead to vulnerabilities allowing access to an organization’s assets — current attack patterns indicate anything but a linear approach and have highlighted that our employees and those within our supply chain are softer targets.

Attackers do their homework targeting people based on data readily available to them. Social networking accounts, for example, allow them to identify common content types for those who are more likely to click on an email based on their specific roles and responsibilities. Once a cybercriminal gets access to the system through a compromised credential or the use of ransomware, they can take their time gathering information about the organization to navigate their way to a part of the architecture where they can launch their exploits.

People-centric approach to security

Many organizations may make qualitative assumptions about how they are being targeted and attacked. One strategy organizations frequently take involves wrapping added security layers around people in the organization — such as executives or high-level finance resources — based on what they believe is true in the absence of intelligence data. However, that strategy can overlook individuals in a wide range of lower-level job functions that frequently offer criminals an easy opening.

A people-centric approach provides agencies the ability to apply risk-based controls because the tools look at data in three key areas:

  • Which job functions within the organization are being targeted?
  • Are these employees vulnerable to different types of attacks?
  • What system and information access privileges do they have?

Instead of treating everybody in the organization the same way, agency security teams can create a more informed picture about their security risks and implement adaptive security controls based on current situational intelligence. Adaptive controls may include using zero-trust application access, browser isolation, step-up and risk-based authentication and targeted security training. Applying adaptive policies can also benefit user monitoring programs, support privacy requirements, minimize data collection and expedite investigations.

Using a platform approach to manage adaptive controls consolidates and correlates policies, intelligence and supports ease of reporting. The result of this approach – increased situational awareness without additional staffing. The workforce efficiency gains allow agency personnel to focus on additional initiatives like those highlighted by the recent White House Executive Order, such as continuous monitoring and compliance.

The growing risk of security threats

Cybercriminals are also getting more organized and functioning more like businesses. In addition to malicious groups creating shared infrastructure, they share information and leverage credential dumps obtained from other security breaches to exploit known visibility gaps. Consequently, agencies need to increase information sharing, control standardization and implement modern security solutions to reduce the risks from the increasing intensity of more targeted attacks.

We work with a global network of customers every day to detect and block advanced threats and compliance risks in more than 2.2 billion emails and 22 million cloud accounts. We see how organizations are getting attacked and which countermeasures are proving most effective. For instance, in the public sector, we can identify which agencies, departments and roles are more targeted than others.

Healthcare organizations, for example, have been increasingly targeted by ransomware attacks both during and following the COVID-19 pandemic response. The aim of those attacks is not so much to disrupt patient care but to extract payment. However, the far-reaching nature of these attacks suggests that criminals could prevent health organizations from providing critical patient care and safety.

Financial institutions and federal regulatory agencies also saw a spike in activity from cybercriminals. Because many of these institutions still use legacy communication systems for transactions, they lost some security visibility and oversight as employees shifted to remote working conditions.

Not surprisingly, cybercriminals saw tremendous opportunities to social engineer account takeovers and infiltrate an entire ecosystem of public and private sector entities that often work closely together.

Another risk factor we see is the number of agencies with underutilized security tools and those who do not take advantage of the complete set of available features. The more security leaders can adapt their security strategies to incorporate a people-centric perspective, the more effective they will become in utilizing the protective controls required to address today’s attacks.

And by working with Proofpoint — with more than a decade’s experience building a global intelligence platform (Proofpoint Nexus), spanning threat protection, information protection and compliance — agencies are equipped to become more secure and protect their people even when they make mistakes.

Learn more about how Proofpoint can help protect federal agencies, and their people, against malicious attackers.

GAO gives 3 priority recommendations to White House on science and tech issues

The White House’s Office of Science and Technology Policy needs to strengthen interagency collaboration around research and development to maximize performance and results, according to the Government Accountability Office.

GAO provided its first-ever priority recommendation letter to OSTP urging the office to work with agencies to establish common outcomes, joint strategies, and roles and responsibilities; address needs using their resources; and develop a way to monitor, evaluate and report results.

OSTP implements GAO’s recommendations at a faster rate than other offices addressing 16 out of 17 recommendations across two fiscal 2017 GAO reports — but 11 recommendations remained open as of June. GAO established three open recommendations as priorities because of OSTP’s “critical role” convening agencies on National Science and Technology Council committees and subcommittees. 

“This mechanism provides a valuable opportunity for agencies to coordinate on implementing an administration’s research and development priorities and to address crosscutting science and technology issues, such as scientific integrity, public access to federally funded research results, reliability of research results, supply chains for critical materials, and others,” reads GAO’s letter. “Strengthening interagency coordination in these areas could help amplify the synergistic effects of related research conducted by different agencies, avoid unnecessary overlapping or duplicative research and development efforts, and facilitate the sharing of lessons learned or coordinating actions to address science and technology issues.”

GAO recommended OSTP, as co-chair of the NSTC Subcommittee on Open Science, coordinate with other co-chairs and participating agencies to implement collaboration practices in November 2019. OSTP initially disagreed with the recommendation but as late as May provided information on its efforts to work with other agencies to increase access to federally funded research results. GAO won’t close its recommendation until OSTP shows it’s attempted to address the practices identified though.

The second priority recommendation dates back to September 2018, when GAO recommended OSTP similarly implement collaboration practices as co-chair of the NSTC Subcommittee on Quantum Information Science. OSTP agreed with the recommendation in that case and took some steps to set goals in key areas as late as May, but GAO won’t close the recommendation until it’s fully addressed.

Lastly GAO recommended OSTP take steps to assess potentially critical minerals as a co-chair of the NSTC Subcommittee on Critical Minerals in September 2016. OSTP didn’t comment at the time but later stated it saw value in analyzing more minerals and non-minerals to inform policy decisions. In May, OSTP stated it was “actively exploring” broadening its focus beyond raw mineral and mineral challenges, but GAO won’t consider its recommendation implemented until there’s a plan for federal coordination addressing the data limitations hindering assessments of potentially critical minerals using a screening process the subcommittee develops.

In all three instances, GAO advised OSTP to consider whether participating agencies agreed to a decision-enforcement process, how leadership can be sustained and if there are documented collaboration agreements in place.

OSTP hasn’t responded to the letter.

Army Research Lab’s new ‘autonomy stack’ speeds up self-driving tech development

The Army Research Lab has begun using its own new “autonomy stack” to speed up the development of its autonomous vehicles program during a one-year sprint.

By owning its autonomy tech stack — all the layers of technology that support applications and development — rather than depending on a contractor for it, ARL now has more control over its Scalable, Adaptive and Resilient Autonomy (SARA) program to improve how robots drive themselves, researchers told FedScoop. Namely, it gave the lab more flexibility to assign research roles to partners to be more deliberate about what groups do and how they use the tech stack to fuse their efforts.

The SARA program kicked off its one-year sprint last year, working with eight collaborators from across the country that each was given a specific part of the complex world of autonomy to engineer new solutions to, instead of putting out broad requests for proposals.

It was “a new and different way of doing business,” Eric Spero, lead for systems engineering for autonomous robotics integration at ARL, said in an interview.

Areas of research that delivered new capabilities range from obstacle classification to navigating narrow passageways. Having the tech stack in-house allowed ARL to be more specific with the tasks it gave to researchers and reduce redundancies, Spero said.

The Army has been chasing the idea of having autonomous ground vehicles to improve the safety of soldiers in battle for years. But so far the Army has missed many of its own timelines for fielding the advanced tech. The SARA program is one of many within the department working on getting AI behind the steering wheel of its vehicles.

With a divide-and-conquer strategy in place for the lab, the eight collaborators were given specific use cases and problems to solve. When they had new code to share, they simply uploaded the software to ARL’s stack, and engineers in the Army could then use it in concert with software from other teams.

“In my mind, the biggest breakthrough is not a technology one … really the biggest innovation is programmatic,” Ethan Stump, artificial intelligence for maneuver and mobility essential research program chief scientist, told FedScoop.

The stack is completely owned by ARL. Most of it was developed in-house, and the roughly 20% that was contracted out is still wholly government-owned. That allows for the greatest amount of flexibility within ARL on how it works with research partners, Stump said.

SARA is not the very first program to utilize this new process, but so far the biggest and most successful. Leaders already have initiated a second yearlong sprint and have designs for a third.

“The strength of the SARA program is that we’re requiring the performers to work with the ARL software,” said Dr. Brett Piekarski, chief scientist of the lab’s Computational and Information Sciences Directorate.

In this case, those partners came from a more broad and diverse group than normal. University and private sector teams from across the country participated, many outside of the usual group the Army works with on autonomy problem sets, Spero said.

“With [the] SARA program, it was a little different, because instead of just putting out a call … it was more of: ‘We would like to invite you into this new collaborative environment,'” Spero said. “Folks became really innovative.”

Edge computing is critical to NASA’s Mars ambitions

Federal employees are producing and consuming data farther from on-premise, physical networks as the workforce becomes more distributed, and no place is that truer than with NASA astronauts in space.

NASA is working with tech companies like IBM to use edge computing to process data closer to the source, namely the International Space Station (ISS).

Edge computing will help NASA decrease the time it takes to analyze data from space, a capability critical to its Artemis program’s efforts to establish a sustainable presence on the moon en route to Mars.

“Edge computing has eliminated the need to move massive data at the International Space Station from a DNA sequencing project,” said Howard Boville, senior vice president of cloud platform at IBM, during Think Gov 2021, produced by FedScoop on Thursday. “Using containerized, analytic code where the data is being produced on ISS has reduced time to get results.”

NASA’s Johnson Space Center used to sequence the DNA of microbes in air, water and surface samples collected by astronauts to ensure they were safe from bacterial and fungal contamination. While the sequencing itself took hours, it would take days or weeks to receive the Petri dish cultures from space.

“It causes a lot of lag time between when the sample is taken and when we know what was in that sample, the microbes that were there,” said Sarah Wallace, microbiologist at Johnson Space Center.

NASA put a handheld DNA sequencer on ISS in 2016 so astronauts could know right away the microbes in their samples. The sequencer was first used in 2017.

A year later NASA developed a new method allowing astronauts to swab any surface for sequencing, eliminating the need for them to culture the organisms prior to testing — thereby protecting them from unnecessary exposure.

The problem remained that ISS’s DNA sequencer generated a lot of data that still needed to be transferred back down to Earth.

“That really is not acceptable as we look toward the moon and Mars,” Wallace said. “So we really need a quicker way.”

Edge computing represents a “paradigm shift,” the infrastructure allowing near real-time analysis, she added.

Live sequencing and analysis is expected “sometime soon,” the next step for Wallace’s team, she said. And one that will pave the way for edge computing’s use addressing other challenges NASA faces as it eyes Mars.

The IC is recruiting for a ‘titan of industry’ to be CIO

The Office of the Director for National Intelligence is actively recruiting to bring on a “titan” of the tech industry to be the next CIO of the intelligence community, the IC’s current acting CIO told FedScoop.

The office is set to issue a job listing soon to bring on a permanent CIO, said Michael Waschull, the IC deputy CIO who’s been acting CIO since January. Waschull said Director of National Intelligence Avril Haines is looking for a “visionary” IT leader who can take the IC’s technology and information environment “to the next level.”

“What we’re looking for is a titan of this industry, we’re looking for a former CEO of a telco, we’re looking for a former CEO of a major information-intensive organization,” he told FedScoop in an interview. The IC is searching for “somebody who is absolutely steeped in the business of cloud and IT and telecommunications and application development and information management and data science. We’re looking for somebody that’s got real gravitas and stature in this space to take us to the next level.”

The IC CIO role is charged with coordinating and integrating IT elements across the intelligence agencies and reports directly to the director of national intelligence.

Whoever comes into the role has the major building blocks in place to do great things, Waschull said, pointing to the intelligence community’s landmark Commercial Cloud Enterprise (C2E) contract and its recent work optimizing networks for connectivity home and abroad.

“What we’re excited about here is the fact that we have set the table, we’ve got all of these capabilities now in place, the building blocks are there,” he said. “And we are seeking a world-class IC CIO from industry with demonstrated knowledge, skills, expertise and experience in setting a vision to take us to the whole next level, frankly. We’re looking for somebody to help us boldly go where the IC has not gone before.”

Upon the hire of a new CIO, Waschull would return to his deputy CIO role. And he’s “proud” to do that going forward “to enable that person to create that vision and to execute that plan of attack that program of work to take us to that next level,” he said.

Waschull took over the acting role when previous IC CIO Matthew Kozma stepped down. Before Kozma, John Sherman was the IC CIO for several years until he was recruited to be deputy CIO of the Department of Defense, where he’s now acting CIO.

DevSecOps is fueling agencies’ cloud migrations

Agencies have increasingly migrated to the cloud to expand their DevSecOps efforts over the last few years, according to federal officials.

Both the Bureau of Information Resource Management within the State Department and the Navy moved to the cloud to automate processes, integrate security into the software development process and deploy updates faster.

The embrace of the cloud as an enabler of DevSecOps and cybersecurity more broadly represents an evolution in agencies’ approaches to the technology.

“Two years ago the biggest driver was ‘my boss told me to,'” said Tom Santucci, director of IT modernization within the Office of Government-wide Policy within the General Services Administration, during an ATARC event. “Now people are starting to see the benefits of this.”

IRM functions as the main provider of IT resources, from infrastructure to messaging, for the State Department, and its Systems Development Division deploys software solutions for any domestic or overseas office with a business need. The bureau moved its previously separate development and production environments to the cloud over the last few years to bridge the two.

Now IRM can not only run up a build agent in the development environment to automate tests or scans but actually create a pipeline to push it to the staging or production environments for users.

“It was possible before the cloud, but it was a larger tactical effort and a larger security effort because you had differences between environments,” said David Vergano, systems development division chief of IRM, during a FedInsider event. “So the cloud backbone is helping to make things smoother, and now we can really try to change how we do things because we have the tooling.”

The department’s other offices come to Vergano with the particular cloud products they want to use, and he advises them to use Federal Risk and Authorization Management Program-certified tools to smooth acquisition and ensure security.

Like IRM, the Naval Information Warfare Systems Command’s (NAVWAR’s) Program Executive Office for Digital and Enterprise Services (PEO Digital) is delivering environments that can be built once and adapted to multiple use cases. Cloud platforms that enable continuous integration/continuous deployment (CI/CD) and DevSecOps make that work easier, but migration isn’t always immediately affordable.

“In [the Department of Defense], nobody has buckets of funding laying around to dump into modernizing their architectures so that everyone in July 2021 can move toward containers and microservices,” said Taryn Gillison, program executive director of the digital platform application services portfolio.

Alternatively, PEO Digital is developing enabling capabilities like Naval Identity Services, infrastructure as code (IaC) and middleware.

If PEO Digital can automate testing and tools for the Navy’s various components, it allows them to shift focus to modernization, Gillison said.

Hurdles remain for NAVWAR, however — namely installation timelines. Gillison said she’s “impatient” to see cloud-to-ship software pushes and other policy changes happen more broadly.

In the prior six to 12 months, 52% of IT executives at public sector organizations said they’d chosen a new cloud provider, according to an Ensono report from June. That number jumped to 85% in the prior 24 months, with 78% of public sector respondents citing security as a concern.

With most public sector organizations managing their cloud environments centrally, a multi-cloud model prevails — largely due to the flexibility it affords agencies, Clint Dean, a vice president at Ensono, told FedScoop.

That jives with DOD canceling its $10 billion Joint Enterprise Defense Infrastructure (JEDI) cloud procurement, citing its intent to launch the multi-cloud, multi-vendor Joint Warfighter Cloud Capability (JWCC) environment.

“As much as Amazon, Microsoft and Google would have us believe, maybe there’s not as much brand loyalty as folks think there is,” Dean said.