GAO denies Salient’s protest of US Patent Office’s $2B IT contracts
The Government Accountability Office denied Salient CRGT’s protest of five contracts worth $2 billion awarded by the U.S. Patent and Trademark Office for IT modernization, in a legal decision released Monday.
Salient contended USPTO‘s analysis of proposals didn’t align with the Business-Oriented Software Solutions (BOSS) solicitation’s evaluation scheme, which based awards on the highest technically rated proposals with “fair and reasonable” prices.
GAO found USPTO’s comparative analysis and awards to Booz Allen Hamilton, Halvik Corporation, RIVA Solutions, Science Applications International Corporation (SAIC), and Steampunk Inc. were “reasonable, adequately documented and consistent” with the solicitation.
“Salient does not identify, and our review of the record does not find, any distinguishing aspect of either Salient’s or Booz Allen’s proposal that the agency failed to consider,” reads GAO’s decision made July 21. “We deny this ground of protest.”
BOSS primarily sought agile development teams for modernization and maintenance of USPTO IT, and five 10-year, indefinite-delivery, indefinite quantity contracts were awarded — three to small businesses. After technical rating and pricing, criteria were ranked as follows: small business participation, technical approach, past performance, and program management and staffing approach.
After selecting three small business proposals, USPTO found SAIC’s higher technically rated than Salient’s and selected them along with Booz Allen as the highest technically rated non-small business proposals.
Salient protested USPTO’s analysis on the grounds the agency weighted past performance and program management and staffing approach — areas where the large businesses received “superior” ratings to Salient’s “satisfactory” ones — more heavily. SAIC’s overall rating was inflated as a result, Salient argued.
“The agency contends that it properly found SAIC’s proposal to be higher technically rated than Salient’s because the relative benefits identified in SAIC’s proposal under the most important factor, small business participation, as well as under the past performance factor, and the program management and staffing approach factor, outweighed the relative benefits identified in Salient’s technical approach,” reads the decision.
USPTO evaluated the small business participation and subcontracting plans of large business offerers Booz Allen and SAIC. SAIC proposed 36% of contract work would be done by small businesses, compared to Salient’s 27%, leading GAO to side with USPTO’s decision.
Salient also protested the award to Booz Allen on the grounds the company’s proposal was unreasonably found higher technically rated that SAIC’s, during a comparative analysis of just those two proposals.
Booz Allen proposed the worst small business participation of the three companies, which Salient felt meant they’d win out in a comparative analysis between the two. But GAO agreed the advantages of Booz Allen’s technical approach outweighed participation shortcomings.
Booz Allen, SAIC and Salient did not respond to a request for comment.
DOD considering marketplace for smaller cloud vendors as follow-on to JEDI replacement
The Department of Defense will look at setting up a marketplace for smaller cloud vendors as a “follow-on” contract to the eventual Joint Warfighter Cloud Capability (JWCC) acquisition.
Research about the potential launch of such a marketplace will take place after JWCC has been awarded, and is not expected to begin until April 2023.
Details of the JWCC were made public last month, after the DOD announced it was canceling the JEDI contract, following a nearly-two year acrimonious bid dispute of the contract’s initial award to Microsoft.
Danielle Metz, deputy CIO for information enterprise at the DOD, revealed details of the future program earlier this week to a virtual audience at a Potomac Officers Club conference.
“It will not be exclusive to the five U.S.-based hyperscale cloud service providers, but it will be available to anyone, any integrator or cloud service provider, that can meet the department’s requirements,” Metz said.
JWCC, on the other hand, will only be open to the largest “hyperscale” cloud providers, like Amazon Web Services and Microsoft, whose cloud systems are capable of offering secret and top-secret cloud environments
The goal of opening up to more service providers is to be able to provide services that fit across the department’s many mission areas. The idea of a marketplace was teased by acting CIO John Sherman when the JWCC was first announced.
Metz added that she expects by the time market research begins, the DOD will be much more “cloud fluent” and industry will have new technical innovations to offer.
Correction: Aug 11, 2021. This article was updated to clarify that the proposed marketplace will be a separate follow-on contract, rather than a part of the JWCC procurement itself.
Senators propose AI training for federal acquisition workforce
A bipartisan duo of senators introduced a bill that would increase the federal acquisition workforce’s understanding of artificial intelligence by creating a training program for them on the risks and benefits of the technology.
The AI Training for the Acquisition Workforce Act would give the Office of Management and Budget and General Services Administration a year to stand up the program if passed.
Sens. Gary Peters, D-Mich., and Rob Portman, R-Ohio, proposed the legislation, part of a broader push by lawmakers to ensure the U.S. leads foreign competitors like China in the emerging sector while doing so ethically.
“We need a federal acquisition workforce that understands AI, how it works, how it can help the government run better, and the ways we can fix the problems with AI systems so those procurement professionals can know they are buying the right AI systems for the government,” Portman said in the announcement.
The training program would cover AI science, system features, risks like discrimination and privacy violations, and risk mitigations. Contracting officers would be taught how to procure trustworthy AI and the latest national security trends pertaining to the technology.
OMB would be expected to update the program once every two years with new information.
The bill lays out an interactive program taught by technologists and other public- and private-sector experts and would require OMB to track workforce participation.
Code for America management say they are open to union recognition talks
Senior leaders at civic technology nonprofit Code for America have indicated they are open to talks over potential union recognition.
Sources speaking to FedScoop said management responded to a request for dialogue sent by organizers late Friday, which could pave the way for voluntary recognition of the representative group.
In a statement to this publication, a spokesperson said that Code for America is working with staff and organizers from the Office and Professional Employees International Union to understand the process.
“We are continuing to learn more about their efforts and look forward to building upon continued inclusive efforts to ensure that Code for America is a great place to work,” said the statement. “We are also committed to ensuring that our actions are consistent with our legal obligations under the National Labor Relations Act, and that we also respect the rights of all of our employees under the law.”
The California nonprofit was founded in 2009 and works with the federal government and state agencies to improve the design of civic technology. It is currently working on federal government tech projects relating to safety net benefits and earned income tax credits.
Under U.S. labor law, an employer can choose to recognize a union voluntarily, or can insist on a secret-ballot election held by the National Labor Relations Board.
Code for America employees last week revealed plans to unionize with the Office and Professional Employees International Union (OPEIU) Local 1010. So far, 62 people at the organization have signed union authorization cards, which is understood to represent about 77% of its workforce.
One source speaking to this publication described the reception of demands from management as “prompt and optimistic.”
Among the concerns of Code for America staff seeking to unionize are recent plans to adjust the salary of new employees who work remotely away from the organization’s California headquarters. Other concerns include the availability of mental health support and diversity, equity and inclusion measures.
Employees inside the federal government and the wider technology sector have received a boost from the prioritization of rights to collective action under the Biden administration.
As part of its budget proposals, the administration in January proposed a pay raise for employees and said it would encourage union activity and collective bargaining.
A spokesperson for Code for America added that prior to the request for union recognition, the organization had raised salaries across the board by about 10% to 20% and that it continually benchmarks benefits it offers against those of other companies and nonprofit organizations.
DIU seeks tech to help fight GPS spoofing
The Defense Innovation Unit is searching for commercial tech that could help the military locate disruptions in satellite-based systems like the Global Positioning System (GPS).
Global navigation satellite system (GNSS) manipulation or “spoofing” has become increasingly low-cost with high-stakes impacts on both defense and commercial interests. DIU wants a solution that uses analytics to search through commercially available data to find spoofed and disrupted signals, it wrote in a recent solicitation.
“The entire world is dependent on GNSS or GNSS-based systems, yet the GPS architecture and its users are vulnerable to denial and manipulation by adversarial actors,” DIU wrote.
Spoofing is an interference to the signal or data transmission in GPS. Devices used to disrupt that signal can be as cheap as $250 and as small as a cellphone.
Threats to satellite-based communications systems like GPS include operations that have enabled narcotics trafficking, unapproved operation of autonomous vehicles, illegal fishing and piracy, according to DIU. Signal jamming by nation-states also poses a threat to military communications in battle. This is of great importance as the Department of Defense has been creating new concepts of operations that more heavily rely on communications and data links.
DIU, the DOD’s Silicon Valley outpost, was established to find commercial solutions to thorny defense challenges such as GPS spoofing. In this specific case, it seeks solutions that can ingest a mix of data, including terrestrial, space-based and others, that could help ferret out false signals. DIU wrote it has no preference on what data the system uses, just that it be able to use multiple types.
Cybersecurity in a shrinking world
On the very first day that former FBI agent Eric O’Neill was assigned to go undercover to investigate the most notorious cyber spy in U.S. history, the target of that investigation looked at O’Neill and said something remarkable.
“So, O’Neill, have you ever heard of something called Hanssen’s law?” the man asked. O’Neill responded that he did not recall studying such a law at the FBI Academy in Quantico.
The man sitting across the table looked back at O’Neill and began to explain Hanssen’s law. “The spy,” he said, “is always in the worst possible place.”
O’Neill could neither believe what he was hearing nor where the conversation was taking place. He was sitting across from Robert Philip Hanssen, one of the most damaging FBI cyber insiders in history, and they were talking as colleagues in the information assurance division within FBI headquarters. O’Neill maintained his poker face and asked Hanssen what he meant.
“That spy is that person with the access to information and the wherewithal to use that information to sell it to those who will do the most damage with it. And that Eric,” Hanssen said to O’Neill, “is what we in the FBI as counterintelligence agents, are tasked to do. Find that spy. Hunt them wherever they are.”
Speaking at the 2021 Public Sector Innovation Summit sponsored by VMware, O’Neill — now National Security Strategist at VMware and author of Gray Day: My Undercover Mission to Expose America’s First Cyber Spy — acknowledged that Hanssen’s words were very prescient.
(Watch O’Neill’s full presentation here.)
The FBI’s most sobering discovery had to do with Hanssen’s use of the Bureau’s own IT infrastructure. To their dismay, the FBI found that Hanssen had used his authorized access to the Bureau’s Automated Case Support system and his knowledge of computers to monitor the FBI investigation that was trying to find him.
At the heart of the ACS system, which first came online in 1995, is the Electronic Case File (ECF). The ECF contains all of the Bureau’s internal communications relating to ongoing investigations and programs. Subsequent investigation of Hanssen’s use of the ECF system showed that he routinely searched the system using search terms directly related to the investigation that was aimed at uncovering his identity.
Hanssen compromised thousands of pages of classified documents detailing the most sensitive intelligence collection programs in the U.S. intelligence community. Among the most damaging disclosures concerned the details of a tunnel that had been dug beneath the Soviet embassy in Washington and outfitted with high-tech listening devices that were monitored by the FBI and the National Security Agency.
It was the exchange with Hanssen and the lessons learned from the investigation that would begin the evolution of O’Neill’s own thinking about cybersecurity and insider threats, which he now shares with government agencies and companies on behalf of VMware.
“As I thought about whether the spy is always in the worst possible place, I realized that the spy is always in the worst possible place for anyone who is breached,” O’Neill said.
Cyberspies are changing the world, according to O’Neill. “There are no hackers, there are only spies,” he said. “The true cyberattackers, cyberspies, and cybercriminals are well-resourced, are very knowledgeable and they’re using sophisticated computer equipment…to get at the data that is the currency of our lives. And as the world gets smaller, cyberattacks are simply growing.”
Pandemic 3.0 – Reopening Our World
O’Neill refers to the massive shift in how people work — from pre-pandemic to pandemic-era remote work and now the post-pandemic reopening — as Pandemic 3.0. Cyberspace has become more hostile, said O’Neill. Destructive attacks have increased 118%, he said.
“Cyberattacks have quadrupled during the pandemic and foreign spies have been targeting everything, in particular COVID-19 research in the healthcare sector,” O’Neill said.
These trends pose a significant challenge for the Pandemic 3.0 world, in which we must find a way for employees to work from any place, on any device, and through any cloud. “Zero trust and endpoint [detection] is critical for remote work,” O’Neill said. “Zero trust is the only way to ensure that everyone accessing your data is authorized.”
The pandemic also forced a massive expansion in cloud investments but when you move to a public cloud “you’re moving to a tough neighborhood,” according to O’Neill. “You may be able to secure your own resources, but you have no control over who’s sharing that environment with you. So you have to prioritize security cloud workloads at every point in the security lifecycle,” he said. “That means security that extends across workloads, containers, and Kubernetes.”
Learn more about “Zero Trust” strategies and how VMware is helping to accelerate public sector innovation.
CACI hires former leader of Army tactical network modernization team
Peter Gallagher, the retired two-star general who previously led the Network Cross-Functional Team at Army Futures Command, is joining defense contractor CACI.
Gallagher will take on the role of senior vice president for national security technology solutions. He retired from the Army in May after a career in military tech, including stints as commander of Network Enterprise Technology Command and the CIO/J6 of Central Command. CACI announced his appointment Monday.
“Pete’s depth of defense mission expertise, including a recent focus on convergence and modernization, and years of special operations experience, will accelerate our success in bringing software enabled technology to enhance, connect, and secure critical systems for our customers,” Todd Probert, CACI president of national security and innovative solutions, said in a statement.
The cross-functional team Gallagher led was charged with improving the Army’s future tactical network. The goal was to modernize how the Army communicates in the field to enable new concepts like multi-domain operations, where data can be shared across different operations. The team consists of a range of experts, including researchers and operators.
The team was involved in some of the Army’s experiments for its Project Convergence, a series of tests on new network configurations and software-enabled weapons. The project is Army’s contribution to the new framework of Joint All Domain Command and Control (JADC2), a military internet-of-things.
CACI is one of the largest military contractors, and its notable recent contract wins include deals on automated testing for Air Force networks and Army talent management systems.
Agencies face hurdles meeting OMB’s deadline to go paperless
Some agencies are having a more challenging time than others investing in the electronic records management (ERM) systems they need to go paperless by the Office of Management and Budget’s deadline of December 31, 2022.
The U.S. Department of Agriculture, for instance, has 29 agencies to contend with and found that, even though one went paperless, the customers it deals with continue to submit paper records.
OMB issued a memo in July 2019 directing the National Archives and Records Administration to stop accepting paper records by the end of 2022, but agencies’ business processes could hinder the transition, even after scanning initial records, if the systems they invest in aren’t long-term solutions.
“We’re using this as an opportunity to not just get paper into a digital form,” said Catherine Cole, with the Directives, Forms and Records Management Branch within USDA, during an ACT-IAC event Thursday. “This is an opportunity to also look at our business processes that will allow us to sustain this moving forward.”
NARA aims to help agencies on that front through a number of different efforts, namely the Federal Electronic Records Modernization Initiative (FERMI), which makes it easier for agencies to acquire electronic records management services and solutions.
Under FERMI, NARA identified high-level business needs for managing electronic records before setting baseline Universal ERM Requirements for agencies and setting specifications for vendors.
NARA is also working with the General Services Administration to improve the ERM system procurement process and help agencies find vendors that meet their needs. Together they created an ERM solutions category, a consolidated GSA schedule where vendors self-certify they meet the Universal ERM Requirements. NARA and GSA also established a special item number (SIN) for physical records under the Multiple Award Schedule.
NARA recently released draft regulations for digitizing permanent records that agencies will eventually transfer over, but their progress toward meeting the December 2022 deadline for going paperless remains unclear.
Agencies perform a Records Management Self-Assessment (RMSA) annually, which contains data on where they see themselves with respect to meeting OMB’s deadline.
But things get murkier when it comes to how that data is being monitored and used to ensure agencies transition to ERM systems on time.
“I’m not aware of any kind of centralized tracking that we’re doing as far as where agencies are,” said Markus Most, electronic records policy analyst with NARA. “That responsibility does sit with the agencies.”
Infrastructure bill amendment includes $2.5B for 5G wireless rollout at military bases
Republican lawmakers have put forward an amendment to the bipartisan infrastructure bill that includes $2.5 billion in funding for the installation of 5G wireless technology at Department of Defense facilities.
Senate Appropriations committee ranking member Richard Shelby, R-Ala., proposed the amendment, which is focused broadly on boosting defense funding. It is supported also by fellow Republican Sens. Jim Inhofe, Okla., Roger Wicker, Miss., Mike Rounds, S.D., and Thom Tillis, N.C.
The amendment was not adopted prior to a vote by Senate lawmakers Sunday evening to end debate over the infrastructure bill. The bill text theoretically could still be altered, however, this is unlikely because it would require cooperation from all 100 senators.
Rolling out secure 5G technology across military installations is a core element of the Department of Defense’s plan to create a joined-up battlefield, in which soldiers and military vehicles have access to real-time data.
The revision would also allocate $3.8 billion for construction at the Department of Energy’s national labs. This includes projects at the National Nuclear Security Administration, the Los Alamos National Laboratory, the Savannah River nuclear facility, and additional projects.
If enacted, it would also add $4 billion across military services and the Pentagon for infrastructure maintenance projects, and set aside another $2 billion for high priority military construction projects.
Lawmakers are expected to take a final vote on the passage of the $1 trillion infrastructure bill this weekend, after the Senate moved through a series of amendments to the legislation on Wednesday.
Negotiators are working on a final iteration of the bill, and Senate majority leader Chuck Schumer, D-N.Y., has called for the chamber to move quickly, as it passes through the final stages of the legislative process.
Speaking at an industry association event last year, the Air Force’s chief of staff, Gen. Charles Q. Brown said the services would “most definitely” need to rework its networks in order to facilitate the rollout of 5G.
Following a Senate cloture vote on Sunday evening, the infrastructure bill is expected to clear the upper chamber either late Monday or early Tuesday.
Unisys ‘doubling down’ on public sector cloud business, CEO says
Unisys is “doubling down” on public sector cloud business and is focused on growing its digital workplace services division, according to CEO Peter Altabef.
Speaking on the company’s second-quarter earnings call, Altabef said the company would compete hard to outgrow market peers and to take market share.
As part of a restructure earlier this year, the company sold its U.S. federal services arm to SAIC and launched two new business segments: Digital Workplace Services and Infrastructure and Cloud services. Its digital workplace arm is focused on consultancy and the sale of communications-as-a-service systems.
Unisys expects the $17 billion public sector cloud services market to grow by about 15% to 18% each year, according to an investor presentation published in January.
During the second quarter of 2021, Unisys swung to an operating profit of $49.3 million compared with a $8.5 million loss in the second quarter of 2020. Within its cloud and infrastructure business segment, revenue grew 9.9% year-over-year to $124.4 million