NASA’s cloud push is motivated by data constraints

Editor’s Note: This story has been updated with information on the first missions to use the DAPHNE service, the clouds that are part of the project and a timeframe for mission launches.


NASA’s move to the cloud is in large part to accommodate the data it’s receiving from space and accelerate resulting innovations, rather than simply migrate applications to a more secure environment.

The agency operates satellite ground stations worldwide that are part of its IT footprint, and its Data Acquisition Processing and Handling Network Environment (DAPHNE) project aims to connect them to commercial clouds.

NASA has spent billions of dollars to date trying to address the growing challenge of transmitting data from next-generation satellites and overseas ground stations to make scientific discoveries, and the global scale of many cloud providers is hard to replicate.

“We’re going to be beaming back data from space and transporting it back to the United States via the cloud network,” said Joe Foster, cloud computing program manager at the Goddard Space Flight Center, during a recent ATARC event. “It’s saved us money, in terms of investing in infrastructure, and it’s allowed us to refocus those dollars into things like upgrading the actual satellite antennae themselves.”

The first missions to adopt the DAPHNE service will be the NASA-Indian Space Research Organization (ISRO) Synthetic Aperture Radar (NISAR), being codeveloped to monitor Earth hazards and environmental change, and the Plankton, Aerosol, Cloud, Ocean Ecosystem (PACE), a satellite that will help understand how the ocean and atmosphere exchange carbon dioxide. NISAR will produce 41 terabits of earth science data per day — which for comparison would take thousands of cellphones to hold — and PACE 4 terabits per day.

DAPHNE will allow that data to be processed at a fraction of the price, with cloud costs dependent upon each mission’s data volume. Exactly how missions will use DAPHNE depends on their launch schedule, which has shifted due to the COVID-19 pandemic.

NASA onboarded several commercial cloud services with which it’s growing operational maturity. Although DAPHNE currently only uses Amazon Web Services, it’s designed to be interoperable among various cloud service providers whose services will be used depending on mission requirements.

DAPHNE is part of the Near Space Network Initiative for Ka-Band Advancement (NIKA), which has a readiness review scheduled for the fall in advance of mission launches. Future missions that will also use DAPHNE include the Nancy Grace Roman Space Telescope, as well as the Spectro-Photometer for the History of the Universe, Epoch of Reionization, and Ices Explorer (SPHEREx).

NASA is also part of an open-source project, Pangeo, a managed Jupyter hub and data-science platform designed to be deployed in any cloud environment. Along with the National Oceanic and Atmospheric Administration and U.S. Geological Survey, the agency is using Pangeo to store machine-learning algorithms performing earth science.

In recent years, Goddard has placed legacy microscopes and other instruments with firmware too old to be upgraded in a Secure Lab Enclave, but data from those devices can still be analyzed in the cloud.

“We basically firewall off and put on a private network all of these legacy pieces of equipment that can’t get upgraded anymore,” Foster said. “That doesn’t mean that you can’t take telemetry data or files off of the piece of equipment and try to run diagnostics or things like that in a more modern cloud environment.”

NASA is standing up cloud-enabled projects at a faster rate because by departing from its old, contract-task order approach, which took as long as six months. Now projects are launched in 45 minutes, and the agency wants to replicate the National Geospatial-Intelligence Agency’s authority to operate (ATO)-in-day effort, where core services are approved at the enterprise level.

While NASA’s cloud platform is currently only accredited at a FISMA Moderate level because its science is largely public-facing, the agency is in the process of creating a FISMA High enclave for more sensitive data dealing with flight and launch capabilities and human space exploration. The enclave is part of NASA’s effort to implement the recent cybersecurity executive order and move from legacy, on-premise systems to a zero-trust, cloud-based model, and the Technology Modernization Fund could cover the cost.

“With the new executive order we wrote a proposal to the TMF [Board] to upgrade and create a FISMA High enclave,” Foster said.

Dataset demands and remote leadership among top challenges for CDOs during pandemic

The volume of demands for coronavirus-related datasets and communicating with staff in a remote environment were among the biggest challenges faced by chief data officers during the pandemic, C-suite advisers told FedScoop.

According to consultants and nonprofits canvassed, the responsibilities of CDOs expanded as the COVID-19 pandemic spread across the U.S. during early 2020, to include leading the flexible use of previously untapped data and working to establish a culture in which experimental data dashboards were used to help coordinate teleworking staff.

CDOs were also presented with the harder-to-grasp challenge of influencing department culture from behind their computer screen.

“[W]hile the role of the CDO was always important, the pandemic has highlighted just how important having a chief data officer managing and governing data across the federal agencies really is in practice,” said Nick Hart, president of the Data Foundation, a nonprofit that works closely with CDOs.

Hart continued: “[E]verything [during the pandemic] was happening at lightning speed, we were no longer in a position to wait a year for new data collection that could be linked to other government data sources, or even private-sector data sources.”

Agencies pulled together datasets at extraordinary speed to launch programs, such as the separate Department of Health and Human Services’ Protect Public Data Hub and Centers for Disease Control and Prevention COVID Data Tracker. Speaking at an event earlier this year, Kevin Duvall, acting chief data officer at the Department for Health and Human Services, described the challenge, saying the agency got “more comfortable” with datasets and the quality of data over time.

CDOs at pace had to consider a raft of ethical concerns, including how datasets might be used by lawmakers – and the way in which publication of such data might be viewed by teams internally.

“Collaboration between data visualization staff and software engineering teams really only happens if there is trust and knowledge that if any data is put out there [staff] will have the chance to validate it,” Grant Thornton public sector manager Tracy Jones told FedScoop.

“Other agencies I work at have very public-facing websites and public-facing data, and there are concerns on that front: Do agencies want to put data out there that constituents and policymakers at a higher level are going to be looking at?” Jones added.

Under a data ethics framework published in late 2020 as part of the Federal Data Strategy, agency data leaders are expected to understand and disclose any known limitations, defects, or biases — a challenge that CDOs had to embrace while working to respond to huge demands from their agency leaders and lawmakers.

According to Jones, one of the only ways to overcome internal concerns between teams over the publication of datasets is to foster a high level of communication. “You always want to understand: What is this data, how is it going to be used?”

In addition, the advocate role of the CDO — the ability to take staff on a journey towards the more effective deployment of data — also came under pressure during the pandemic, according to Jeff Lawton, Grant Thornton’s lead for enterprise information management solutions.

“I think that COVID has essentially hamstrung their ability to some degree, where they can’t use the full power of their charisma, their charm — because that’s part of the CDO position to get people to do something I want them to do that they are not normally doing,” he said.

On top of this, data leaders across federal agencies over the last 18 months have had to lead experiments with new datasets to help move staff to an all-telework environment during the height of the pandemic.

Speaking with FedScoop, one consultant described a rise in demands for more creative analytics from data leaders to afford more insight into exactly how staff were working outside the office. CDOs have had to lead the charge on the internal use of metrics, where it is efficient and makes sense within the teleworking environment.

“[We saw] a shift towards really trying to understand productivity…beyond maybe just the simple timecard entry. What are the ways that we can pull data to validate that we’ve all been productive in this engagement,” said JD Walter, a former HHS modernization adviser who is now executive vice president of solution optimization and execution at Golden Key Group.

Above all, however, Lawton added that one of the biggest determining factors in the success of a CDO — during the pandemic but also more widely in their role — has been attitude. He described the enthusiasm of one current, successful CIO as “infectious.”

“When we asked her what she wanted to have achieved in a year’s time, she said ‘I want people to have fun working on data governance,” Lawton said. “Who doesn’t want to be part of that group, which has that positive energy.”

Voting is now open for the FedScoop 50

IRS partners with Code for America to launch child tax credit portal

Digital tech nonprofit Code for America is developing a new online system for the Internal Revenue Service to allow families to claim child tax rebates and other tax benefits more easily.

Called GetCTC, the platform is intended to increase access to both the Advance Child Tax Credit and the Recovery Rebate Credit for low- and no-income users.

The technology partnership is part of a governmentwide effort announced last week by the IRS to enroll eligible families in the CTC.

IRS Deputy Secretary Wally Adeyemo said: “We want every eligible family to have access to the advance child tax credit, which is why we will continue our outreach efforts to drive enrollment as our children return to school.”

David Newville, Code for America senior program director for tax benefits, said the portal is in its final stages of development.

“GetCTC will be a mobile-friendly online portal, available in Spanish too, that will make accessing the CTC simple. We will continue to work to make sure that every family in our nation gets the tax benefits that belong to them,” Newville said.

The California nonprofit was founded in 2009 and works with the federal and state agencies to improve the design of civic technology.

Staff at the organization are currently in talks with management over the formal recognition of a union for employees. Leaders at the nonprofit last week told FedScoop they are open to talks with employee representatives about the issue.

How Arizona saved $40 billion in payouts on fraudulent unemployment claims

The COVID-19 pandemic caused an enormous spike in unemployment insurance claims across the country. But the complexity and financial enticement of these programs attracted a high volume of fraud attempts on state coffers. 

A new report, produced by ID.me, details how states partnered with private sector organizations to analyze millions of claims received and implement modern identity authentication tools to reduce fraud payouts. 

cybersecurity

Read the full report.

“As early as May 2020, a Nigerian fraud ring dubbed ‘Scattered Canary’ reportedly siphoned hundreds of millions of dollars from the state of Washington before the coordinated attack was identified,” said the report.

“As fraudsters began to target new states, the Arizona Department of Economic Security (DES) saw a massive rise in claimants. There were 77,063 initial [pandemic unemployment assistance (PUA)] applications filed during the week ending May 16, 2020. That weekly number had risen to 266,674 by July 25. Initial applications for PUA peaked at 570,409 for the week ending October 10.”

By September 2020, a number of states partnered with ID.me — including Florida, Georgia and Nevada — to successfully verified tens of thousands of legitimate claimants and diminish fraud instances. About this time is when Arizona’s DES reached out to ID.me to initiate a pilot program that they hoped would help them determine fraud instances for the state.

“By October, the results of the pilot program in Arizona showed great success. ID.me contributed to a dramatic reduction in the number of claims, from a record high of nearly 570,400 claims filed in the week ending October 10, to just 6,700 the week ending November 14 — representing a 98.8% decrease in new claims filed,” shared the report.

By implementing ID.me’s identity verification tool, DES estimates savings from payouts on fraudulent PUA claims for the State of Arizona upwards of $40 billion.

Read more about how states are improving citizen benefits programs and reducing fraud through modern identity verification tools. 

This article was produced by Scoop News Group for, and sponsored by, ID.me.

GSA seeks fresh expertise to help improve transparency around IT spending

The General Services Administration is interested in contracting personnel capable of providing better information on federal IT spending through data analysis, according to a request for information (RFI) issued Thursday.

IT experts sought would support GSA‘s category management, technology business management (TBM), data center optimization and acquisition efforts.

Within GSA the Office of Government-wide Policy’s TBM Program Management Office (PMO) works to improve transparency around IT spending and management data, although the agency envisions any contract that comes out of the RFI benefitting multiple PMOs, Federal Executive Councils and government initiatives.

“Congress and taxpayers have long pressed for better information about how federal IT dollars are spent and managed,” reads the RFI. “Using industry best practices, the federal government has an opportunity to run IT like a business by leveraging authoritative data to make data-driven decisions and analyze tradeoffs between cost, quality and value.”

Also involved with the RFI are the OGP Data Center and Cloud Optimization Initiative PMO, Federal Acquisition Services IT Management Vendor Management Office and potentially other projects identified in the President’s Management Agenda or Cross-Agency Priority Goals.

GSA wants to know if there are interested companies in six support areas:

  • program and project management support,
  • customer assistance services and related support services,
  • strategic planning,
  • data analytics,
  • training, and
  • services in support of the Executive Councils.

Customer assistance support will include specialized IT subject matter, communications and outreach, and website content management work, while the Executive Councils seek technology and process improvement pilots.

Interested companies have until Aug. 19 to submit questions about the RFI and Aug. 31 to respond.

Raytheon awarded $960M communications systems support contract

Raytheon Technologies has won a $960 million contract from the Air Force‘s Nuclear Weapons Center to provide software and hardware that will support the unit’s secure satellite-based communications systems.

The contract is for 10 years, and is structured as an indefinite-delivery, indefinite-quantity contract. Raytheon will work on the Advanced Extremely High Frequency(AEHF) system, which is a communication network reserved for the military’s highest priority information. The network is supposedly “secure, protected, and jam-resistant,” the Air Force states in its description of the system. 

“AEHF enables the Department of Defense to control tactical and strategic forces through all levels of conflict and supports the attainment of space superiority for the joint force,” according to the Air Force.

It is a sole-source acquisition contract, and Space Force will contribute $1.35 million in fiscal 2021 procurement funds to the contract cost. Other work done as part of the procurement will include “contractor logistics support, terminal depot activation, terminal hardware/software procurement and studies associated with support of the AEHF-T systems.”

The contract was awarded from Hanscom Air Force Base.

State Department IT investments lack central oversight, IG report finds

The State Department still doesn’t route all bureau and office IT procurements to its chief information office for approval, despite establishing a process to approve contracts, according to its Office of Inspector General.

OIG performed an audit of the department’s process for selecting and approving IT investments and found the Bureau of Information Resource Management could do more to centralize oversight and avoid duplicative purchases. The State Department spent $2.5 billion on IT in fiscal 2019.

The audit was a follow-up to a March 2016 report that found the State Department lacked a “defined process” that met Office of Management and Budget requirements, although five of OIG’s seven recommendations have since been closed.

“Until additional actions are taken, IRM will not be able to fully identify duplicative systems and related cost-saving opportunities, optimize its IT investments, or promote shared services,” reads the follow-up report released Wednesday.

OIG recommended IRM conduct a benchmark assessment of the agency’s IT portfolio to find duplicative systems — despite mitigating duplication by creating a process for comparing investment requests — and then implement a strategy to combine, implement or replace such systems.

Despite adopting OMB guidance and updating internal policy on recording IT investment in a portfolio management system, iMatrix, IRM needs a way to review reorganizations, OIG recommended.

IRM verbally concurred with OIG’s recommendations in a July 15 meeting.

OIG further recommended the Bureau of Administration identify IT-related acquisitions of $10,000 or more, a finding it agreed with.

IRM failed to make substantial progress on two OIG recommendations from the 2016 report. The bureau still hasn’t reviewed the IT investment methods of all bureaus of enforced the requirement that they and other State Department offices avoid duplication.

“These actions are needed to improve accountability and to further identify and avoid duplicative IT investments,” reads the report.

DHS conducting initial assessment for CMMC-like cyber compliance regime

The Department of Homeland Security has launched a “pathfinder assessment” to examine whether it should implement a new contractor cyber compliance program similar to the Department of Defense’s Cybersecurity Maturity Model Certification (CMMC).

DHS officials have previously expressed their interest in possibly implementing a similar program to improve the protection of sensitive information stored on contractor networks. CMMC mandates DOD contractors verify their compliance with one of five tiers of a compliance regime, instead of simply self-reporting their adherence to requirements. Private sector contractors have often been vulnerable to attackers seeking access to sensitive information, a weakness programs like CMMC are trying to address.

“Our end goal is to have a means of ensuring a contractor has key cybersecurity and cyber hygiene practices in place as a condition for contract award,” DHS CIO Eric Hysen said in a notice posted to SAM.gov Aug. 10. “As an immediate first step, DHS is conducting a pathfinder assessment to establish a path forward.”

It is unclear what exactly the “pathfinder assessment” is looking at, but the notice from the CIO states that DHS has been watching CMMC very closely and is looking to learn from its implementation. It is not the first time the DHS CIO has signaled interest in monitoring CMMC.

“We’re looking very closely at [the Department of Defense]’s Cybersecurity Maturity Model Certification, or CMMC, and looking to pilot that approach within our vendor base as well,” Hysen said during the April IT Modernization Summit presented by FedScoop.

While DHS might be looking closely at CMMC, it has not communicated with the third-party organization conducting much of its implementation. The CMMC Accreditation Body oversees the accreditation of the cyber assessors and the ecosystem of consultants and trainers that will work in the space. Its CEO, Matthew Travis is barred from communicating with DHS as he recently left the department as the No. 2 at the Cybersecurity and Infrastructure Security Agency (CISA).

“[T]he AB has not been in touch with DHS as Matthew Travis is currently restricted from doing so due to ethics restrictions,” a CMMC AB spokesperson told FedScoop.

CMMC has been praised for its ambition to verify cyber practices in contractors, but has faced implementation roadblocks. Small businesses working with DOD also worry it could raise costs to both meet the cyber standards and pay for the consultants and assessors needed to pass the test.

Katie Arrington, who at the time led the CMMC effort in DOD, said in April 2020 that she had met with DHS leaders about implementing CMMC.

The General Services Administration (GSA) has also taken notice of CMMC and implementing some of its requirements in government-wide contracting vehicles since DOD is a large consumer of the services GSA procures.

DHS did not respond to a request for comment.

DOD IG warns military staff to remove sensitive information from tech in Afghanistan withdrawal

The Department of Defense’s oversight body has warned military personnel they must wipe sensitive health and medical data from technology being returned as part of the U.S. withdrawal from Afghanistan.

In a report, the Inspector General (IG) reiterated rules that state all personally identifiable information must be removed from equipment including medical equipment, laptops and cell phones.

According to the IG, this is crucial both to prevent civilian and military records such as health and service records from falling into the wrong hands. The oversight body said also that officers must keep accurate records of technology that is returned as part of the withdrawal process.

In prior audits of military base equipment in Afghanistan, the IG found that the protocol for clearing information from equipment was not always being followed. In one case a device used to protect soldiers from improvised explosive devices was left showing sensitive location data.

“Unless equipment is properly processed by unit personnel before turning it into redistribution property assistance team personnel, there is a risk of theft and compromise of sensitive information,” the report said.

In May, DOD officials acknowledged that some U.S. military equipment could end up in the hands of Taliban fighters, but said military planners were using the time left until the pullout is complete to minimize the threat.

In February last year, the U.S. and the Taliban signed a conditional agreement to remove all U.S. forces from Afghanistan by April 2021. The military mission is set to conclude on August 31.