Senate committee calls for FISMA to be revamped
The Senate Committee on Homeland Security and Governmental Affairs has identified continued major cybersecurity failings across agencies and is calling for the Federal Information Security Modernization Act (FISMA) to be reformed.
A new report published Tuesday identifies IT security flaws across almost every major U.S. government department, including the failure to secure citizens’ personal and financial data and the inability to keep track of thousands of items of IT equipment.
According to the committee, lawmakers should update FISMA to require federal agencies and contractors to notify the Cybersecurity and Infrastructure Security Agency (CISA) of certain cyber incidents and to amend the definition of “major event” to ensure Congress is notified of breaches quickly.
FISMA was enacted in 2014 to create a requirement that each federal agency develop, document and implement a complete information security plan. It has come under scrutiny following recent hacks, including the SolarWinds attack in late 2020, during which multiple government departments were compromised.
The report recommends also that CISA expand shared offerings to all federal agencies, including enhanced endpoint detection.
Core government departments, including the Social Security Administration, are failing to handle data securely, according to the report.
An audit by the Department of Transportation’s Inspector General found 14,935 IT assets belonging to the department of which it had no record. This included 7,231 mobile devices, 4,824 servers, and 2,880 workstations that were unaccounted for.
The Senate committee’s review highlighted also that many agencies continue to run copies of software on their computer systems that are no longer supported by technology vendors and also flagged the failure of agencies to obtain the required authorities to operate for all of their technology business systems.
The committee’s findings are based on its own analysis, as well as work carried out by the inspectors general of federal agencies during fiscal 2020.
It followed up on an earlier report, issued in 2019, that identified the failure of eight key government agencies to comply with federal cybersecurity standards. According to the latest iteration of the study, seven agencies have made only minimal progress in improving their compliance with the regime, and only one – the Department of Homeland Security – was judged to have employed satisfactory cybersecurity standards during 2020.
Top Navy officer says Project Overmatch work ‘headed in the right direction’
The Navy’s work to execute its portion of the Joint All Domain Command and Control (JADC2) strategy has a way to go, but the service is “headed in the right direction,” according to Adm. Mike Gilday.
Speaking Monday at the Sea-Air-Space conference, the Navy’s most senior officer said the service is in the third cycle of testing new technology this year as part of the program, but that challenges remain.
“We’re very excited about where it’s headed. We’re not satisfied with where we are. We have a way to go before we get to the point where we roll out strike group-wide in 2023,” Gilday said.
The Navy’s section of the JADC2 strategy is known as Project Overmatch, and its goal is to connect data multiple domains of warfare. The senior officer added that he hopes that within a decade ships will have the connectivity to send all of their data over any network in a secure manner.
By having the ability to constantly share data, the hope is military command and control can be assisted by artificial intelligence that can generate more options for commanders orchestrating a multi-domain battle. It’s a tall order for a service beset with cybersecurity challenges and legacy systems the service recently started to modernize.
Rear Adm. Douglas Small, who is leading Project Overmatch, also said his office is still working on the foundational architecture and testing new tech. He said he has enough money and enough cloud computing to work through the technical challenges, but finding ways to actually share data have yet to be discovered.
Small said one of the most challenging aspects of the programs is transferring data across domains, from the air to sea to other parts of warfare. That challenge is augmented by the Navy’s geographic posture, having its ships being disconnected through miles of oceans.
The CNO said Overmatch and the JADC2 framework it follows is a priority for the service. It’s also a priority for other services and the department as a whole, that recently signed a JADC2 strategy. But so far, few enterprise capabilities have materialized beyond some battle management applications on ships.
VA awards Peraton $497M IT infrastructure contract
The Department of Veterans Affairs has awarded Peraton an IT infrastructure contract that could be worth up to $497 million over seven years.
The Virginia-headquartered company will provide infrastructure-as-a-managed service for storage and computing infrastructure facilities across the U.S. and globally.
According to the company, it will deliver an enterprise-scale solution that integrates on-premise infrastructure with the VA’s enterprise cloud architecture.
Under terms of the contract, Peraton will be tasked with supporting up to 220+ petabytes of data, ranging from business operations data to the medical images used in veteran care. It will undertake the contract work at up to 300 VA sites across the continental U.S. and abroad.
Commenting on the award, George Rollins, vice president of VA and defense health at Peraton, said: “This is an incredible win for the team. We look forward to our continued partnership with the VA, and to helping the Department realize the expected benefits from its major modernization initiatives.”
ThunderCat Technology had protested the award of the contract to Perspecta — which was recently acquired by Peraton — earlier this summer but then withdrew its complaint.
Senate infrastructure bill includes $20M for cyber response and recovery
The $1 trillion infrastructure bill would put $20 million in the Cyber Response and Recovery Fund in fiscal 2022 and every year thereafter through fiscal 2027, a bipartisan group of senators revealed Sunday.
The fund supports the Cybersecurity and Infrastructure Security Agency‘s response efforts after the Homeland Security secretary, in consultation with the national cyber director, declares a significant cyber incident at the federal, state, local or tribal level.
Senators want to bolster the fund after significant cyber incidents like the compromise of the SolarWinds Orion software supply chain, which saw multiple federal agencies breached.
CISA can spend the funds on vulnerability assessments, technical incident mitigation, malware analysis, analytic support, threat detection and hunting, and network protections. Funds may also be used for grants or cooperative agreements that update or replace hardware and software or else to contract IT or cyber personnel.
Agencies may be required to reimburse the funds and must report on their use. Meanwhile, CISA must notify the national cyber director of the duration of the significant cyber incident and the reason for and coordination of any allotted funds. The Homeland Security secretary then has 180 to report how the funds were used and their effectiveness mitigating the incident.
The Senate bill would provide CISA an additional $35 million for risk management and stakeholder engagement operations and support, and the new national cyber director office would receive its first $21 million for salaries and expenses until fiscal 2022 appropriations are made.
The Department of Homeland Security Science and Technology Directorate would receive $157.5 million for non-cyber and cyber-related research and develop into critical infrastructure security and resilience, security testing of telecommunications equipment, industrial control systems and open-source software.
Job-coding issues may hinder DOD’s cyber workforce recruitment, IG says
Department of Defense components have not accurately coded jobs for their civilian cybersecurity personnel, limiting the ability to recruit and retain the targeted cybersecurity positions they most need, according to an inspector general report.
While the DOD has followed mandates to issue guidance on coding civilian cybersecurity jobs per the 2015 Federal Cybersecurity Workforce Assessment Act, the application of those codes at the component level has been inconsistent or inaccurate, the IG found in a recent audit.
“As a result, the DoD may be unable to accurately determine the skill set and size of its civilian cyber workforce,” the watchdog said in a report made public Monday. “Without coding all positions (filled and unfilled), the DoD may develop incorrect workforce planning activities, such as recruitment and retention strategies, and incorrectly report on work roles of critical need.”
The report redacted exactly how many of the DOD’s core and non-core cybersecurity positions had coding issues across the three military departments and gave no specifics on how widespread the issues are with other components in the Fourth Estate.
The IG said quality assurance measures would ensure components comply with the DOD’s cyber workforce coding guidance. Though the Army has an automated quality assurance system in place for coding civilian cybersecurity roles, the Navy and Air Force lack full systems to ensure they are meeting the goals of the Pentagon.
The IG concluded the report by recommending the DOD Office of the CIO require components to code filled and unfilled cybersecurity roles in accordance with federal requirements and conduct a feasibility study on issuing a more thorough quality assurance system for proper coding.
Acting CIO John Sherman agreed with those recommendations, clarifying that DOD has required such coding since May 2020 and that as of June 2021, all components have at least primary work roles coded into their manpower and personnel systems.
On the matter of quality assurance, Sherman said the DOD has already conducted a feasibility study on the issue, leading to the department creating a “cyber workforce common data model” on DOD’s Advana data platform to make sure coding is accurate and complete. Using Advana, Sherman said, it will give the DOD “a dashboard view of appropriately configured systems and the corresponding coded populations of filled and unfilled positions and identify systems that are not yet compliant.”
Within the report, the IG acknowledged the DOD’s greater progress taking action “to meet strategic goals for the recruitment and retention programs of its civilian cyber workforce.” Specifically, the department has ramped up use of its Cybersecurity Scholarship Program and its Cyber Information Technology Exchange Program. It has also started work developing a Cyber Aptitude Test and implementing the Cyber Excepted Service framework and enhancements.
Despite such progress, in April, Lt. Gen. Dennis Crall, CIO of the Joint Staff, told the Senate Armed Services Subcommittee on Personnel that he was “concerned about the pace” at which DOD is hiring and training cyber personnel. “I think the divide between the need is growing compared to what we’re able to fulfill. I’m not sure we’re closing the gap, and time is ticking for us to do so.”
Department of Energy expands CyberForce program
The Department of Energy is expanding its CyberForce program by offering year-round competitions, webinars and career resources designed to prepare collegiate students to fill workforce gaps — especially around industrial control systems (ICS) and operational technology (OT).
Argonne National Laboratory leads the program and added two virtual, solo competitions, comprising a Conquer the Hill series, that allows students to hone cyber skills mapped to the National Institute of Standards and Technology‘s National Initiative for Cybersecurity Education (NICE) Workforce Framework.
Argonne launched a Cyber Defense Competition in 2016 to help address the national cyber talent shortage, predicted to reach 1.8 million workers by 2022, which has evolved into a program benefitting not only companies but government as well.
“The National Labs, Department of Energy and all the other federal agencies are obviously equally looking for talent that is interested,” Amanda Joyce, CyberForce program director, told FedScoop. “Bringing students on-site, or even bringing them in virtually, brings awareness to the national lab system.”
Tech giants like Amazon, Microsoft and Google attract the top cyber talent, but students forget DOE keeps the lights on for those companies — literally — and can give them the hands-on training in real-world scenarios involving ICS and OT they lack, Joyce said.
Argonne won’t hold the next in-person, team CyberForce Competition until 2022 because of the Covid-19 pandemic, which is why it started the Conquer the Hill series.
The Reign Edition set for September will be a timed, capture-the-flag event with non-traditional escape room elements that force competitors to think logically.
While the Adventurer Edition, which ran from July 16-18, gave participants 48 hours to complete 160-plus cyber tasks of varying difficulties in a question-and-answer format. University of Central Florida student Cameron Whitehead won.
While Conquer the Hill events try to admit all who register, the CyberForce Competition only allows one team per university to enter. The red-blue, attack-defend competition requires teams to perform daily tasks like examining log files while keeping everything from email to ICS operational, in what is a multi-lab event.
This year the CyberForce program also added a once-a-month webinar series highlighting key cyber topics; a virtual career fair for more than 1,000 students to meet with cyber companies; and is creating a workforce development portal that will report on students’ progress and let them engage with each other and government and industry experts year-round.
The need to have students fill cyber roles defending ICS and OT became more critical after a hacker breached a Florida water treatment plant in February and a ransomware attack on Colonial Pipeline in May, which led the company to shut the pipeline down temporarily and saw people panic-buying gas into scarcity across the Southeast.
“Why we push operational technologies so much is because the technology we’re using is very old,” Joyce said. “”The problem is none of these systems were ever really meant to be on the internet.”
The CyberForce program encourages students to think through the added cyber risks ICS and OT present and consider what constitutes the proper amount of security, how the networks communicate internally and with other networks, and how a hacker might turn them off.
Security isn’t just updates, patches and firewalls when it comes to such systems, Joyce added.
“The problem is that doesn’t work for everything and specifically for our operational technology networks,” she said. “And it takes a unique skillset to really understand that and to figure out that these systems are very sensitive in nature.”
GSA makes awards under ASTRO IDIQ contract
The General Services Administration has awarded over 300 spots to federal contractors across its ASTRO indefinite-delivery, indefinite-quantity vehicle for robotics and unmanned systems.
Awardees include contracting giants Boeing, Booz Allen Hamilton and Leidos, in addition to smaller, veteran-run entities and many others.
ASTRO is a large U.S. government contract vehicle, geared towards the needs of the Department of Defense and the U.S. military. It is understood to have a budget of tens of billions of dollars and no defined ceiling.
Its scope is focused on the operation and maintenance of robotics and unmanned systems, as well as intelligence, surveillance and reconnaissance.
ASTRO is broken out into myriad separate domains, which encompass the majority of the armed services’ technical requirements. ASTRO has 10 pools, or scope areas, for a maximum of 450 contracts.
Contracts issued through the vehicle are intended to support a 10-year ordering period.
Air Force testing microwave weapons to stop drones
The Air Force Research Lab wants to find new ways to stop potential drone attacks. Now it’s turning to microwaves as one possible solution.
The lab wants to create a high-power microwave weapon system that could halt an incoming unmanned aircraft or swarm of small drones. To bring this idea to life, the lab is seeking commercial partners to further prototype tech the lab has already developed. Stopping enemy drone attacks is a problem the military has been eager to solve as commercial unmanned aerial systems (UAS) proliferate on and off the battlefield.
The new program is part of AFRL’s Tactical High-Power Operational Responder (THOR) program that has been testing and developing directed energy for the past two years. Now, the new program dubbed “Mjolnir,” after the hammer Norse god Thor uses, aims to operationalize and advance more capabilities in using directed energy in weapon systems.
“After a successful two-year testing campaign, the AFRL team has learned a lot about the benefits of the technology and how it can be improved,” Amber Anderson, THOR program manager, said in a release.
Directed energy is a new category of tech that uses highly focused energy, often electromagnetic spectrum waves or laser beams, to disable or cause harm to adversaries. They can be used to fool incoming guided missiles or even attack humans by simulated burning sensations. When faced with drones, the weapons could disable a swarm of them without firing a physical bullet or launching a rocket, giving the operators greater stealth.
The tech remains nascent and has yet to be scaled, a problem the Mjolnir team want to solve.
“AFRL’s goal is to create a blueprint for our partners so these systems can be economically produced in large quantities, and to grow a fledgling industry that will become critically important as the U.S. strives to maintain our electromagnetic spectrum superiority,” Adrian Lucero, THOR’s deputy program manager, said.
The DOD recently signed a contract with Anduril Industries for an other type of counter-UAS tech. Their tools use an artificial intelligence-enabled sensing system to detect incoming small aircraft that could pose a risk to a base or other military options. Other options the DOD has looked at include drones that carry large nets to intercept incoming drones.
Treasury CIO Eric Olson to depart
Eric Olson will be leaving his role as CIO of the Treasury Department at the end of July, FedScoop has learned.
It is understood that Olson’s last day with Treasury will be July 31.
Olson officially took over as CIO of Treasury in November 2017. As deputy CIO since 2015, he assumed the role in an acting capacity that July when then-CIO Sonny Bhagowalia took on a detail with the Bureau of Fiscal Services.
He has also served as the department’s CISO, according to the Treasury website.
Before joining Treasury, Olson was at the Department of Justice for 12 years where he held several technology leadership positions, such as the director of service engineering. Earlier in his career, he also spent time in the private sector with Accenture, Verizon and Sprint.
As CIO of Treasury, Olson led and oversaw the department’s $4 billion portfolio of IT systems and services. Recently during his tenure, the department has made a shift in its approach for cloud computing with the TCloud acquisition, which aims to centralize and broker cloud services across the department under a multi-cloud, blanket purchase acquisition with a $1 billion ceiling. A draft solicitation for the procurement went out earlier this month.
Olson was a winner of a FedScoop 50 award in 2020.
Treasury officials did not comment on Olson’s departure.
Internships are ‘primary mechanism’ to expand federal cyber workforce, says Partnership for Public Service CEO
The CEO of the Partnership for Public Service has called for an expansion of cybersecurity internship programs, describing them as the “primary mechanism” for getting new talent into entry-level jobs at federal agencies.
“Our federal government needs to approach talent management as the best private sector organizations do,” said Max Stier, speaking at a congressional hearing on Thursday. “We think our student internship program is our primary mechanism for identifying talent for entry-level [cybersecurity] jobs.”
Thursday’s hearing was hosted as lawmakers debate the most effective way to foster a new generation of cybersecurity experts in government in response to the rise in cyberattacks on critical infrastructure. It follows also a memorandum from the Biden administration yesterday that will create new performance goals for federal agencies.
Converting internships into full-time, fully paid government positions is currently a laborious process and can leave candidates waiting for up to 100 days before receiving a job offer. Roles requiring security clearance often result in a longer delay for potential employees.
Stier said also that more granular metrics should be used to judge the success of departments in recruiting and retaining a broad range of candidates.
“The most senior leadership in government need to hold their teams accountable to make sure these numbers are good,” he said. “If they prioritize it themselves, you will see change.”
Among key challenges for federal agency cyber recruitment is the age of the workforce, which has fewer than 6% of staff under the age of 30.
In a conversation with FedScoop earlier this month, cloud technology experts identified the expansion of internships and partnerships with colleges and other institutions as key ways of tackling a lack of cloud talent.
The Partnership for Public Service is a D.C.-based nonprofit that is focused on improving how government agencies function.