Department of Defense to address small business concerns as part of CMMC program review

The Department of Defense (DOD) has said it will address concerns that that the Cybersecurity Maturity Model Certification (CMMC) will impose additional costs on small businesses, as part of an ongoing internal review.

A spokesperson on Monday told FedScoop that the agency will “look for avenues” to reduce the cost of the accreditation scheme for small enterprises, while retaining the program’s focus on reducing supply chain risk.

“The CMMC Program Office greatly appreciates the perspectives presented at the hearing and has taken this information seriously.

“CMMC does recognize and understand the concerns of small businesses and fully anticipate the majority of these companies to only require CMMC Level 1 which are the requirements that have been laid out under FAR 52.204-21 released in 2016.”

“During our internal review the program will look for avenues in which to reduce the costs to small businesses while keeping the integrity of the cybersecurity requirements,” the DOD spokesperson said.

Critics of CMMC say it represents an unfair burden for smaller enterprises because they have less money available to spend on compliance costs than larger federal contractors.

The response comes after a House Committee on Small Business subcommittee last Thursday heard from companies that said they are struggling to understand the new compliance regime and worry the costs will run them out of the federal market.

CMMC requires third-party verification of contractor’s compliance to a set of cyber standards that has five tiers. Level one is the lowest level of controls, requiring basic cybersecurity, and level five mandates expensive systems to protect from nation state-backed attacks.

The Department of Defense is also working to provide more official information about its new contractor cybersecurity compliance program, in response to additional complaints from small business about a lack of information and clear communication about the scheme.

In comments to FedScoop, the DOD spokesperson said one component of the review would be to develop a public media campaign to disseminate information about the program.

An internal review of the CMMC accreditation program was ordered by the deputy secretary of defense in March. DOD previously said the review is a policy review typical after changes of administration, and that it will focus on finding ways to improve DOD policies for small business.

The Government Accountability Office is also reviewing the program with an eye toward DOD’s communication with industry and small business impact. That review is expected to last until the fall.

Army gets new head of Network Modernization Cross-Functional Team

The Army’s Network Modernization Cross-Functional Team got a new director this month, the service announced.

Brig. Gen. Jeth Rey will lead a team of engineers and network scientists from across the Army focused on improving the networks the Army uses in battle. The team is a part of Army Futures Command, the newest four-star led command the service stood up to focus on emerging tech and future battlefield weapons.

The team’s first leader Maj. Gen. Peter Gallagher retired from the Army at the end of May.

“All modernization capabilities touch the network,” Rey said in a release announcing his promotion. “The network is the center of gravity, so we need to support them as well.”

The network modernization team’s mission is to focus on modernizing “air-land ad-hoc, mobile tactical communications and data networks” and in support of the broader network modernization happening under the Army CIO’s office and deputy chief of staff to the G-6 — the service’s two lead IT roles.

Rey comes from Central Command, where he was the head of command and control and communications, overseeing the military’s networks throughout the Middle East. One of his most recent assignments was standing down the networks in Afghanistan as the U.S. military prepares to leave after 20 years of conflict in the country.

The cross-functional team has authorities to issue other transaction agreements and other rapid acquisition approaches to experiment with new tech to improve network communications, according to a document summarizing its work.

Cross-functional teams are designed to break down barriers between teams working in the technology modernization ecosystem, from contracting to research and engineering.

House lawmakers consider bipartisan bills to advance tech R&D

Lawmakers in Congress are considering two bills that advocates say would boost the technological dominance of the U.S. and support the semiconductor industry.

Members of the House of Representatives were on Monday set to scrutinize the National Science Foundation for the Future Act and the Department of Energy Science for the Future Act as part of the chamber’s suspension calendar.

The National Science Foundation for the Future Act would compel the NSF to work with the National Academies of Sciences, Engineering and Medicine to assess STEM education for Pre-K-12. Among measures included in the Department of Energy Science for the Future Act is the requirement that the agency coordinate with academia and public and private organizations to advance its scientific computing program.

According to the Semiconductor Industry Association (SIA), the bills, if passed, would strengthen America’s economy and national security.

Commenting on the bills, SIA CEO John Neuffer said: “The U.S. semiconductor industry relies on these advances as the foundation for creating the technologies of the future.”

“The research initiatives authorized by this legislation will generate advances in a range of scientific fields and build the pipeline of talent needed to enhance U.S. technology competitiveness,” he added.

The lobbying chief also advocated for the inclusion of $52 billion in public funding for semiconductor research, design and manufacturing in the new legislation.

Both bills are being considered after Senate lawmakers earlier this month introduced bipartisan legislation known as the Facilitating American-Built Semiconductors (FABS) Act, which would establish an investment tax credit for domestic semiconductor manufacturing.

NASA awards $2.5B enterprise IT contract to Leidos

NASA awarded a $2.5 billion contract for enterprise IT and telecommunications services to Leidos, the agency announced Friday.

The 10-year Advanced Enterprise Global IT Solutions (AEGIS) contract covers cloud and data center solutions across all NASA centers and facilities.

AEGIS replaces the NASA Integrated Communications Services (NICS) contract and will ensure that wide-area and local-area network infrastructure connects seamlessly and securely.

NASA’s Office of the Chief Information Officer manages the contract and will use it to support the agency’s collaboration tools, emergency and early warning systems, telephones, cable and radio systems to further aeronautics, space exploration, scientific research and technology development.

Both fixed price and indefinite-delivery, indefinite-quantity services are offered through AEGIS, which takes effect Sept. 1.

Leidos already does a significant amount of work with NASA around IT systems design.

What SolarWinds revealed about the gaps in enterprise IT security

Federal agencies have taken significant steps to fortify their IT environments over the past couple of years. But as the latest cycle of security breaches and ransomware attacks have made abundantly clear, cybercriminals are only growing more sophisticated and persistent.

One global cybersecurity leader that successfully sidestepped the malicious impact of the SolarWinds software supply chain attack and is helping government agencies adopt zero trust strategies is Palo Alto Networks.

In this exclusive interview, FedScoop talks with Dana Barnes, senior vice president U.S. public sector sales at Palo Alto Networks, about the security giant’s perspective on zero trust, what it learned during the SolarWinds incident, and what security steps government agencies still need to focus on most. 

FedScoop: The White House executive order on cybersecurity put a bright spotlight on the need for agencies to adopt zero trust security practices and modernize their security operations. What impact do you think the EO will have in actually moving agencies from a security compliance mindset to truly embracing zero trust?

SolarWinds

Dana Barnes, Sr. VP, U.S. Public Sector Sales, Palo Alto Networks

Dana Barnes: First, there’s a lot more in that executive order than just zero trust. The EO reinforces a wide range of cybersecurity measures that are already out there. If you think about the FY ‘21 appropriations as an example, there were dollars set aside for cybersecurity. The National Defense Authorization Act also had funding for cybersecurity and tech modernization. And then there was America Rescue Plan Act.  All of these things were driving funding to address the problem long before the EO was released.

Most EOs often don’t have teeth, because there’s no funding tied to them. Here’s a case where the EO is picking up on themes where the federal government has already moved on the funding. So I believe that you’re going to see a significant move by these agencies over the next six months to start to address these issues.

And all you have to do is look at the Colonial Pipeline incident to know how bad things can get quickly, if you haven’t secured your environment. And, as you know it took them some time to get up and running once they fixed everything, so I think you will see federal agencies move more quickly. In fact, we have been receiving hundreds of calls from government in the federal, state and local space to discuss our approaches on zero trust, on threat hunting and securing the network as an offshoot of the President’s executive order.

FedScoop: What did you see from Palo Alto Networks perspective from the SolarWinds incident that could offer useful lessons as agencies begin to implement some of the steps outlined in the executive order?

Barnes: SolarWinds showed that the traditional [cybersecurity] approaches that have been in place are not necessarily going to meet some of the highly sophisticated attacks that we’re seeing now. The things we’re seeing with our customers is they’re confused — they just don’t know where to start. They are fatigued. They’re understaffed. And they’re not necessarily funded to do some of the things that they need to do.

From a Palo Alto Networks perspective, what we now understand and are advising customers is that you have to know what your attack surface actually is. How do the folks who are trying to break into your environment — how do they view you? What we’ve learned is that these bad actors actually analyze the customer; they analyze the network from the internet side of it, and if they can get in, they assess and look at everything.

I’ll give you a prime example. We procured a company called Expanse. They give us the ability to see how our environment touches the outside world. What are those open ports? What are those devices and their vulnerabilities outside in? A lot of federal agencies don’t do as great a job of understanding that. That’s step one.

Once you’ve done that assessment, and you know what your attack surface is, then you have to assess your entire environment. You need to know what problem you’re trying to actually solve. That’s the confusion piece —  where do I start? And then, identify where are the gaps and then you can prioritize and figure out where to go.

That’s a large part of what we do at Palo Alto Networks. It’s not just about the firewall. It’s not just about having a data lake and machine learning and analytics, which are very important. What we want our customers to do is understand what you look like; understand where your risks are; and then we can get into, how do we address the threats?

We can look at your network security, your firewalls, your endpoint protection, at your cloud protection — and see, how do you secure all these different connections to the cloud? What’s my attack surface? How does the enemy view me? And where will they attack?

FedScoop: You mentioned the American Rescue Plan that allocated almost $2 billion towards cybersecurity. That’s on top of nearly $10 billion requested in the President’s upcoming FY 2022 fiscal budget. Given those funding opportunities, what are the biggest issues agencies still face in actually modernizing their security operations?

Barnes: I think it’s a combination of size, complexity, manpower. If you look at some of our largest agencies, they have multiple contracts for cybersecurity going across multiple integrators. We have funding that has been locked and set that dictates what technology can be used. So what you’re going to deploy today isn’t sufficient because the requirements were done four years ago, and it just took that long to get the contract. So that’s a challenge.

Another challenge is you can’t just throw away what you already have. It’s not like Homeland Security can start completely from scratch and build an entire new cyber security structure. You have tools and processes in place, and you have to build upon them and leverage them. So you need approaches that allow you to take advantage of what you have — and weave in new capability — while you’re slowly upgrading those older capabilities. All of those older tools are still generating data. So how do you leverage the older tools? I think that’s where a platform approach is so crucial.

I think one of our strengths is we can come in and leverage what you already have today. We can slowly begin to replace those older things with new things that are fully integrated into what we have. So you can go on this journey, based upon where you are. Some customers have the ability to just start from scratch and go all the way. Other customers have to keep doing what they’re doing and take it step by step.

I would say the last challenges is that senior leaders in government need to become even more engaged in cybersecurity — and better understand the importance of cybersecurity to the overall mission, by asking questions. If you’re a director of an agency, you need to know what’s needed. It’s not just the sole responsibility of the network people and the CIO and CISO. It’s the job of every person in that organization. If leaders at the top don’t understand the urgency at the same level that the CIO and CISO does, agencies will still struggle.

FedScoop:  Given the vast range of security solutions available to agencies, what would be your recommendations for what agencies should focus on most?

Barnes: The first thing is to know what you have and what your current security posture really is. Then you can start deploying things like next generation firewalls, focusing on things like role filtering and enterprise data loss prevention. We would argue that we have some of the best technology in that space.

But then you have to take another step. And this gets into taking anti-ransomware measures. Ransomware is huge right now and the government in particular is a heavy target. So having the ability to leverage behavioral threat analysis is key.

One thing we learned from SolarWinds, using our Cortex XDR capabilities, was that artificial intelligence and machine learning capability was what saved us, because we were able to identify and see abnormalities and behavioral changes that weren’t normally there — and that an analyst who’s inundated with data may have missed. And that’s critical. So that automation piece is key.

From there, you can start to leverage things like data lakes, and the ability to collect all that data and do the analysis.

But we also recommend four critical components to securing your enterprise, starting with having integrated endpoint detection and response (EDR). We also recommend investing in modern security, operations, automation and response (SOAR) platforms — especially at the federal level. Another important security component, or pillar, is having internet operations management in place. And finally agencies need to commit to zero trust architecture and the strategies to achieve them.

I would argue that no one has fully implemented zero trust. People have different flavors and pieces. There are so many parts to your cybersecurity. But understanding where you are right now, what you look like, and what your posture is — that’s the most important thing to focus on first. If you can do that, then you know where to put your resources, you can prioritize, you can do your risk assessments to secure your environment.

We are urging our customers to leverage our experience and capability to give them that visibility into what they didn’t see. Every customer where we’ve leveraged Expanse — it’s really opened their eyes to what bad actors are seeing, and saying things like, “I didn’t realize that I was so at risk here, here and here.” 

Learn more how Palo Alto Networks is helping government organizations to “solar proof” their cybersecurity foundation.

Lawmakers look to create cyber training programs at CISA, VA

Lawmakers want to create cyber training programs at the Cybersecurity and Infrastructure Security Agency and Department of Veterans Affairs to bolster the federal workforce, through legislation introduced Friday.

The Federal Cybersecurity Workforce Expansion Act would launch a registered apprenticeship program at CISA and a veteran training pilot at the VA with costs to be determined.

Recent supply chain attacks like the SolarWinds hack, targeting agencies through a government contractor, underscored the lack of cyber talent at the federal level on down, with more than 500,000 job openings nationally, according to the National Institute of Standards and Technology.

“In order to bolster our cyber defenses and protect our critical infrastructure, we need to increase the number of cybersecurity professionals in the federal government,” said Sen. Maggie Hassan, D-N.H., in a statement. “This bipartisan bill will also help address the workforce challenges in the veteran community by standing up a cyber-training program at the VA to help veterans secure good-paying, stable jobs, and I urge my colleagues to join me in supporting this legislation.”

Hassan, who chairs the Subcommittee on Emerging Threats and Spending Oversight, is cosponsoring the bill with Sen. John Cornyn, R-Texas.

Should the bill become law, CISA would have two years to establish at least one apprenticeship program leading to employment at the agency or a company contributing to national cybersecurity and mostly funded by an contract, grant or cooperative agreement with the agency. The program must also meet CISA’s cyber work role needs and be registered with the Department of Labor’s Office of Apprenticeship or a similar state agency.

DOL, NIST, the Pentagon, National Science Foundation, and Office of Personnel Management would be expected to share resources with CISA, which may issue grants or cooperative agreements to companies or other entities to execute the program.

CISA would also need to report to Congress on the results of the program, including continued employment rate, every two years, as well as submit annual performance reports.

Under the act, the VA would have one year to create a pilot program providing cyber training using virtual platforms, hands-on skills labs and assessments, and federal work opportunities. Graduates would receive cyber credentials.

The program is expected to align with NIST’s National Initiative for Cybersecurity Education (NICE) Workforce Framework, and the VA would work with the Pentagon, Department of Homeland Security, DOL and OPM to make it a reality. Veterans and retiring active duty military personnel would be eligible.

A 2019 report from the Government Accountability Office examined the shortage of federal cyber talent. In May 2021, DHS announced a 60-day sprint to hire 200 cyber employees — 100 of them at CISA.

DOD may be underestimating risk in major IT systems, GAO report finds

The Department of Defense could be taking an overly optimistic approach to assessing cyber risk on several of its IT programs, according to the Government Accountability Office.

In a report published on Wednesday, the oversight agency said it had found at least 10 instances in major business IT programs audited, where independent assessments conducted by the DOD underestimated the level of cybersecurity risk.

The office has recommended that the DOD review how it conducts risk assessments across its IT system and warned that until it does so the department’s oversight of programs could be proving over-optimistic.

IT programs that the GAO says should be classified as having elevated risk levels include the DOD’s defense travel system, enterprise accounting and management system, logistics chain management systems, and the Marine Corps’ global combat support system.

GAO’s review also found challenges in DOD’s implementation of agile software practices. Among the concerns raised by the report were the inability of the department to hire the requisite staff and to manage the technical environments that are needed for agile software development.

The department has been trying to update its software practices to include agile development, which follows the principle of iterating and quickly updating code, and replaces the traditional waterfall method of IT development.

Former GSA chief acquisition officer Salmoiraghi joins HR consultancy

Jessica Salmoiraghi has joined human resources consultancy firm Golden Key Group as a vice president.

In her new role she will be responsible for leading shared and managed services at the company. She moves to the private sector after previously working at the General Services Administration as chief acquisition officer, a role that she left in January this year.

Salmoiraghi joined GSA in 2018 as associate administrator at the Office of Governmentwide Policy and chief acquisition officer. Before this, she was the director of federal agencies and international programs at the American Council of Engineering Companies.

The GSA has recently welcomed a new Administrator Robin Carnahan, who on Wednesday was confirmed in the role by Senate lawmakers by a voice vote.

Commenting on Salmoiraghi’s appointment, Golden Key Group CEO Gretchen McCracken said: “Jessica’s recent experience at GSA will be crucial to GKG’s growth as we expand our Shared and Managed Services practice in support of our federal clients.”

GSA, along with the Office of Personnel Management and the White House COVID-19 Response Team, has helped lead the Safer Federal Workforce Task Force, which is shaping the policies of federal agencies for getting staff back to the office.

Rep. Hice calls on IGs to assess telework’s impact on agency performance

Rep. Jody Hice, R-Ga., has called on inspectors general to assess the impact of remote working on federal agencies’ missions and the performance of their employees.

In a statement Thursday, Hice said it was “clear” that the increase in the number of federal employees working from home had contributed to delays, inefficiencies, and declines in performance.

“I’m calling on inspectors general to investigate the overall impact telework had on our federal agencies during this pandemic and report back to Congress so we can accurately assess how to move forward before rushing into foolhardy reforms,” the lawmaker said.

The congressman has written to the inspectors general of 10 agencies, including the departments of Defense, Justice and Homeland Security, asking them to look into the impact of mass telework over the past 16 months. Hice is a ranking member on the Subcommittee on Government Operations, which is part of the House Committee on Oversight and Reform.

Agencies across the federal government have been given a July 19 deadline by which they must finalize plans to get staff back into the office, a process that is being overseen by the White House-backed Safer Federal Workforce Task Force.

However, according to new guidance issued as part of the return-to-office program earlier this month, agencies have been instructed to consider embracing a more virtual workforce.

A joint memorandum sent by the Office of Management and Budget, the Office of Personnel Management and the General Services Administration said that such a move should be taken “where possible and appropriate.”

Pentagon installs Garstka as acting CISO for acquisition and sustainment

Former U.S. Air Force officer and long-time cybersecurity specialist John Garstka has taken up the role of acting CISO for acquisition and sustainment at the Department of Defense, FedScoop has learned.

In the new post, Garstka will be responsible for leading the integration of security and cyber efforts within the Office of the Under Secretary of Defense and work to ensure security within the department’s technology supply chain. According to sources, he takes over the role on an interim basis from Katie Arrington.

Garstka is a Pentagon veteran, having worked in military research and development since 1984, including over a decade within the space division of the U.S. Air Force. Since 2012, he has held leadership roles within the Office of the CISO at the DOD, most recently as director of cyber programs. Between 2000 and 2002 he was CTO for the Joint Chiefs of Staff.

It is not immediately clear how much of a role Garstka will play in the management of the Cybersecurity Maturity Model Certification Program (CMMC). Recently-installed Deputy Assistant Secretary of Defense for Industrial Policy Jesse Salazar in May told Congress that he now has oversight of CMMC.

One of the core responsibilities of a CISO for acquisition and sustainment at the DOD is to ensure the digital security of weapons systems across the military.

Services have struggled with cybersecurity risks within the defense supply chain. In 2019, a landmark report by the Department of the Navy found that the service had failed to account for the fact that defense companies it contracts with would be aggressively targeted by foreign hackers for their valuable data.

The DOD, in response, has ramped up its implementation of measures such as the CMMC program.

In November last year, the Department of Defense appointed Dave McKeown, a long-time government IT and security official, as chief information security officer. He replaced former CISO Jack Wilmer, who departed in July to lead a private security company.

The DOD declined to comment.