NSA not sharing information on controversial surveillance system, whistleblower alleges
The National Security Agency never provided its historical legal analyses of its XKeyscore surveillance system, according to a member of the independent oversight board that has been investigating it for the last five years.
Though the Privacy and Civil Liberties Oversight Board asked the NSA for all its prior legal analyses showing XKeyscore system’s data analytics comply with federal law, all it’s received is a 13-page memo from general counsel in 2016.
At more than a decade old, XKeyscore — first flagged by former NSA contractor Edward Snowden in 2013 — is used to search massive internet traffic databases to find and analyze a target’s communications. But the unavoidable, incidental collection of citizens’ personal information raises legal concerns the NSA never proved to PCLOB it considered before launching the system, Travis LeBlanc, a Democratic member of the board appointed by former President Trump, said in an unclassified statement released Tuesday.
“At a general level and on the basis of the documents that have been provided to the board, it is concerning that any surveillance tool would have been conceptualized, coded, implemented, and then executed and routinely used without such a prior written legal analysis,” LeBlanc wrote.
Of PCLOB’s five members, only LeBlanc voted against the release of what he called a “rushed” report on XKeyscore to Congress, the White House and the Office of the Director of National Intelligence in March.
The NSA told PCLOB its 2016 memo was based on legal analyses of XKeyscore conducted prior to the system’s launch — analyses general counsel did not or could not provide. The agency didn’t respond to a request for comment on the number of legal analyses completed or their withholding them from the board, by publication time.
LeBlanc further criticized NSA general counsel for basing its memo on dated case law and failing to update its legal analysis since 2016, despite the agency’s surveillance capabilities continuing to outpace electronic surveillance law.
Commenting on the matter, an NSA spokesperson told FedScoop: “The representation that NSA had not conducted a full legal analysis prior to the Board asking for legal materials in 2014 is not accurate. NSA conducted appropriate legal reviews of NSA’s use of XKEYSCORE. NSA’s Office of General Counsel regularly reviews NSA intelligence programs and capabilities to ensure compliance with the Constitution, laws, and other applicable regulations and policies.”
The NSA did address LeBlanc’s complaint that its analysts weren’t trained to use XKeyscore, or required to, by adopting that recommendation.
NSA’s alleged failure to prove it conducted prior legal analysis wasn’t the only reason LeBlanc took issue with PCLOB releasing a report, which he said “reads more like a book report summary of the XKeyscore program.”
PCLOB didn’t conduct a cost-benefit analysis of the system that accounted for how many people have been impacted, how much data has been collected and analyzed, how that data is shared, how many lives have been saved, or how many terrorist attacks have been stopped, LeBlanc said.
The board also didn’t follow up on reported compliance incidents, a redacted number of which were deemed “questionable intelligence activities” — intelligence community-speak for illegal surveillance or review of a citizen’s communications.
PCLOB didn’t include in its report a recommendation of LeBlanc’s that incidentally intercepted communications be tagged “personal information” in the system.
The board “failed the public” by not seeking to declassify its findings, he said.
LeBlanc also wanted PCLOB to weigh in on the technological and modern electronic surveillance issues XKeyscore raises, given its use of machine learning, autonomous collection of massive datasets and algorithmic analysis of them.
“Whether the public wants it or not, these systems are almost certainly here to stay,” LeBlanc said.
Oracle petitions Supreme Court over $10B JEDI protest
Oracle has filed a new brief with the Supreme Court, calling on it to hear the latest argument in its years-long legal battle against the Joint Enterprise Defense Infrastructure (JEDI) cloud contract.
The tech company hopes to overturn the initial ruling of the U.S. Court of Federal Claims, which identified issues with the $10 billion cloud contract’s award structure but said that potential conflicts of interest had not affected Oracle’s chances or cost it the deal. Oracle then brought its case to a federal appeals court, which also quashed its appeal.
The new brief comes after Amazon earlier this month filed its own arguments in this case as a co-defendant, calling on the Supreme Court to avoid making a decision over the contract because it contained disputes over matters of fact rather than disputes over points of law.
According to Oracle’s lawyers, the appeals court in its prior judgment failed to consider the fact that a criminal conflict of interest “alone” renders a federal contract unenforceable.
“Both of those two errors are mistakes of law, not fact,” Oracle said in its submission to the court.
The cloud computing company argues that the U.S. Court of Appeals made a serious error when it rebuffed an early appeal and kept the contract award intact.
JEDI is a key component of the Department of Defense’s larger enterprise cloud strategy. The contract was first put up for bid in 2018 before DOD awarded it to Microsoft in late 2019, but since then, it’s been largely dormant due to a separate legal protest led by Amazon.
But even before that award, Oracle has been waging an ongoing legal battle. It started in August 2018 with a pre-award bid protest filed to the Government Accountability Office, claiming that the sole-source structure of the award is not justified and arguing in court documents that links between DOD employees and Amazon Web Services had hurt its chances at competing for the contract. After GAO denied the protest, Oracle took its case to the Court of Federal Claims, then the U.S. Court of Appeals, and now its reached the nation’s highest court.
Meanwhile, the DOD has been reassessing what it might do if JEDI is held up much longer in the courts. Earlier this month, Deputy Secretary of Defense Kathleen Hicks said DOD could take a new direction on the contract by next month, and that it was “actively looking at [its] options.”
Previously, a Court of Federal Claims judge granted AWS’s requested timeline for hearings in its separate litigation. The web hosting giant continues to seek the disclosure of additional internal communications from the Department of Defense, including emails and Slack messages.
This followed a decision in April by the same court to stop the government from dismissing AWS’s allegations of political interference, elongating the timeline for a decision in that case. AWS has protested the DOD’s decision to award the deal to Microsoft, alleging that the procurement was influenced by former President Donald Trump, who has publicly criticized Amazon founder and Washington Post owner Jeff Bezos.
AWS and Oracle did not respond to a request for comment.
Better government CX requires leadership plus IT modernization
Juliana Vida, a retired U.S. Naval commander and former deputy CIO at the Pentagon, is Group Vice President and Chief Strategy Advisor for public sector at Splunk.
The nation’s sudden accelerated dependence on government services over the past year cast a huge spotlight on agency IT systems performance. As we all know, some systems held up remarkably well under the strain and others did not.

Juliana Vida, Group Vice President and Chief Strategy Advisor, Public Sector, Splunk.
From the public’s point of view, and over a longer-term perspective, the federal government’s customer experience “remains weak and uneven compared with the private sector,” according to Forrester’s 2020 U.S. Federal Customer Experience Index. The report found that the federal average CX score of 15 key agencies and programs trailed nearly 11 points behind the private sector average and was “lower than any other industry or sector” we studied.
More starkly, “Only 38% of federal customers who used digital-only channels considered the experience emotionally positive,” the report states. While some agencies — notably the National Park Services — scored better than others among some 98,000 adults who interacted with 250 brands measured in the index, overall, federal agencies in aggregate are getting lapped by more user-friendly private sector services.
It doesn’t have to be this way.
True, federal agencies must contend with more rigorous regulatory constraints than their commercial counterparts. Living within unpredictable, single-year budget cycles and abiding by strict consumer data-gathering rules, among other factors, make it hard for most agencies to step on the gas when it comes to improving citizen CX.
Clearly one of the barriers that can, and must, be overcome is the notion that the user experience is “good enough” for government. While officials in the last administration made strides to improve the customer experience and service delivery for federal customers, more needs to be done so those efforts do not continue to languish until agencies and the administration as a whole more fully commit to addressing the concurrent need to modernize federal IT systems.
It’s not that the federal government isn’t investing mightily in its IT systems. Investment remains robust though woefully misplaced. As much as 80% of those IT and cybersecurity funds are funneled into sustaining legacy technology instead of investing in modernized, cloud-based technologies that can deliver continuously updated IT infrastructure and applications – technologies that are both less expensive and more secure.
There are many opportunities for agencies to fast track their CX efforts, by leveraging their data, even as they ramp up their modernization efforts.
It’s relatively easy now, for example, to use a data platform to mine the types of words that customers use when they’re engaging online or contacting an agency by phone or email and determine what they’re looking for, or whether they had a good or bad experience. That intelligence can easily fold into customer service platforms, to deliver more data-driven, real-time insights and improve service delivery over time.
There are also a variety of IT automation and system orchestration tools to speed up backend processes, reduce repetitive administrative tasks and ultimately help employees focus on more valuable ways to support the customer experience. Those same tools can also help agencies identify what internal applications and systems people are really using or not using. If people are using what you’re putting in their hands, that’s a measure of success; and if they’re not, that can tell you where to reallocate your investments.
In the end, though, good customer experience requires a champion with top leadership’s support.
One example that has really impressed me is the work unfolding at the U.S. Air Force under its new Chief Experience Officer, Colt Whittall. He is the first appointee from any military service in this role across the Department of Defense, arguably the world’s largest and most complex organization.
Speaking at a recent federal CX panel discussion, Whittall described, for instance, his approach to measuring IT user satisfaction, beginning with an Air Force IT Pulse survey. The survey asks IT users across the Air Force a few simple questions and uses national language processing to help analyze the results.
He’s also rolling out a monitoring platform that captures system response time and availability data for all of the Air Force’s key applications — in real time and which tracks performance over time. That analysis will help gauge the impact of system upgrades and IT support services as they are deployed across the entire Air Force.
The decision to support remote users during the pandemic — by rolling out hundreds of thousands of VPN connections and cloud-based applications — had a dramatic effect on user satisfaction, with telecommuters registering twice the level of user satisfaction compared to those working primarily on base, he said.
Whittall’s approach to enhance customer experience is pragmatic: “Partnering with commercial technology is the only way to go, because it’s the only kind of capability that’s going to deliver the agility and the speed, and the scalability that’s required to keep us moving forward,” he said in the panel discussion. “Nobody wants to go backwards,” now that they used to a better experience.
The U.S. Air Force’s example illustrates the art of the possible in government. It also highlights how modernization and user experience go hand in hand — and how that in turn, can translate into greater productivity, faster decision making and most importantly, more effective delivery of mission-related services.
Learn more on how Splunk is helping federal agencies modernize for the future.
VA’s McDonough reaffirms commitment to Cerner records management platform
The Department of Veterans Affairs will stick with the existing records management platform that forms the center of its electronic health records (EHR) strategy following a review of its modernization program.
The agency in March launched a 12-week review into the $16 billion program, following the identification of failures including by the Government Accountability Office, which in February recommended that the VA stop work on the program to updates its health IT and scheduling system.
Speaking Wednesday at a press conference, VA secretary Denis McDonough said the department was committed to the Cerner Millennium records management platform, which is provided by health care technology company Cerner. The secretary said it will likely take two further weeks to determine additional changes to the program that will be made following the review,
Cerner is building a cloud-based system for VA that the department says will eventually be interoperable with the DOD’s Military Health System (MHS).
“That’s the coin of the realm,” said McDonough, commenting on the interoperability of the new system.
The next sites to get the system will be a network of hospitals in Columbus, Ohio.
Prior inspector general reports have warned that the VA’s legacy systems and infrastructure may not be able to handle the load of the cloud system and new health IT interfaces.
Langevin takes DOD CIO Sherman to task for ‘unacceptable’ budget justification
The Pentagon wants more than $50 billion for IT and cybersecurity in fiscal 2022, but so far, it hasn’t given Congress a thorough enough justification for that money, according to a top cyber-focused lawmaker.
Rep. Jim Langevin, D-R.I., expressed disappointment Tuesday for the Department of Defense’s lack of specifics in its IT budget request summary for fiscal 2022 — which includes $5.5 billion for cybersecurity and much more for enterprise IT other “cyberspace activities” on top of that. The document gives top-level budget figures for the past and present, but few other programmatic details are shared.
Langevin rebuked acting DOD CIO John Sherman because much of the budget documentation for 2022 is “nearly a carbon copy” from the previous year, equating it to plagiarism. Because of this, DOD’s IT and cyber budget summary document shrank from 30 pages last year to six for fiscal 2022 — “only two of which contain any substance,” the congressman said.
“With all due respect if your office cannot be troubled to put together the necessary materials for this committee’s oversight, how can we trust the stewardship of this critical portfolio?” Langevin, chair of the House Armed Services Cyber, Innovative Technologies, and Information Systems Subcommittee.
He continued: “Without that level of detail, you need to understand, we can’t fulfill our oversight responsibilities; we’re in the dark otherwise,” Langevin said. “That’s unacceptable going forward.”
On top of this, Langevin criticized the department’s seeming lack of understanding of how to define and categorize total cybersecurity spending across its enterprise. For instance, the Navy and Air Force count end-point security differently toward their cybersecurity budgets, he pointed out. That lack of standardization in categorizing IT spending makes putting a top-line number on the DOD’s cybersecurity budget difficult, he said.
“I will own this…we need to do a better job,” Sherman said of the evidence his office presented Congress while pointing to new requirements to restrict some of the materials in the document as controlled unclassified information as part of the reason it shrank.
In addition to agreeing that his office needed to provide Congress more information, Sherman also admitted the issue with how DOD defines and categorizes IT spending — a problem the department perennially has across its budgeting activities. “$5.5 billion for cyber doesn’t indeed represent the totality of cybersecurity for the department,” he said.
Redundancies in the terminology DOD uses for cybersecurity could also create gaps in authorities of that spend, Langevin said, pointing out that DOD uses the terms “operational technology” or “industrial control systems” for the same protection of industrial systems, like air conditioning and elevators.
Langevin has long been a vocal proponent of funding cybersecurity and IT modernization. His subcommittee marks up the section of the defense appropriations bill that grants DOD its IT and cyber funding.
During his testimony, Sherman gave little else away on other hot-button issues, like the Joint Enterprise Defense Infrastructure (JEDI) cloud procurement. He reiterated comments made by Deputy Secretary of Defense Kathleen Hicks that the DOD is in the process of figuring out what it will do next to develop an enterprise cloud solution.
CMMC Accreditation Body board member Edens resigns
A founding member of the accreditation body implementing the Department of Defense‘s new contractor cybersecurity standards resigned Tuesday.
Regan Edens had served on the board of the Cybersecurity Maturity Model Certification Accreditation Body (CMMC-AB) since it was incorporated in January 2020 and led the Standards Working Group, the volunteer entity responsible for establishing CMMC programmatic definitions.
Edens declined to comment. The CMMC-AB confirmed Edens’ resignation in an email to FedScoop.
CMMC is the new program to increase the security of DOD’s supply chain against theft of controlled unclassified information (CUI). It mandates contractors get assessments to test their networks agains a five-tiered model, with the CMMC Accreditation Body being the group to manage the ecosystem of assessors, trainers and others who contractors will need to hire to get certified to continue working with DOD.
Edens’ work on the Standards Working Group focused on foundational issues to the program, including its definition of CUI, the type of sensitive information CMMC is designed to protect.
His resignation comes as the AB transition from being run by a group of volunteers like Edens to having full-time staff take care of the day-to-day operations of the group. The board recently hired a CEO and has on-boarded some full-time staff.
The accreditation program has faced a number of challenges since its rollout, including concerns from the defense industry that it may create an unduly onerous barrier for smaller contractors.
In testimony given to a House Committee on Small Business subcommittee last week, small enterprise leaders also raised concerns about how new requirements are being communicated to businesses.
The DOD has since said that it is addressing concerns over the cost of complying with the scheme for small businesses in an ongoing internal review, and that it will shortly launch a public media campaign to improve communication with industry about the scheme.
Poor coordination hampers HHS cyber threat info sharing with industry
The Department of Health and Human Services doesn’t routinely share cyber threat information with private sector partners because the two centers responsible haven’t formalized coordination, according to the Government Accountability Office.
GAO found the Healthcare Threat Operations Center, an interagency program providing actionable cyber data, didn’t regularly provide threat information to the Health Sector Cybersecurity Coordination Center (HC3) for sharing with industry.
Private sector partners want more actionable threat information from HC3 with cyberattacks on health care organizations on the rise, since the start of the U.S. COVID-19 response in March 2020, putting patient privacy and telehealth services at risk.
“Given the many players involved in cybersecurity management at the department and in supporting the cybersecurity of the [health care and public health] sector, deliberate and well-organized coordination and collaboration are essential to ensure that efforts are successful,” reads GAO’s report released Monday. “Safeguarding federal information systems and those systems supporting our nation’s critical infrastructure has been a longstanding GAO concern.”
HC3 alerts included mitigation strategies but not information from HTOC reports like the Internet Protocol address used by a malicious actor to facilitate an attempted cyberattack.
Neither the HTOC Concept of Operations nor the HC3 Strategic Plan include specific coordination responsibilities, and a senior HTOC official said it rarely shares “appropriate” information with HC3, according to GAO.
HHS‘s chief information security officer told GAO that HTOC and HC3 coordinate information sharing during daily situational awareness meetings, but those meetings are led by the Computer Security Incident Response Center and coordination wasn’t apparent, according to GAO.
GAO recommended HHS’s chief information officer coordinate information sharing between the two centers, but HHS disagreed with the recommendation arguing already “close coordination” takes into account agreements between private-sector partners and stakeholders.
“[D]ue to the high level of fidelity and sensitivity that surround federal intelligence data and the HTOC federal partner cybersecurity operational data, HTOC partners do not share information outside the partnership without the expressed permission and authorization of the originating agency,” wrote Rose Sullivan, acting assistant secretary for legislation at HHS, in the department’s response.
HTOC receives intelligence data from the Department of Homeland Security, open source data, HC3, and subscription-based intelligence sources.
GAO further found HTOC and six other HHS entities it reviewed only partially addressed three cyber collaboration practices: defining and tracking outcomes and accountability, clarifying roles and responsibilities, and documenting and regularly updating guidance and agreements.
GAO recommended HHS’s CIO report on the progress and performance of the HHS CISO Council, Continuous Monitoring and Risk Scoring Working Group, and Cloud Security Working Group, as well as regularly update collaboration agreements between them with approval.
GAO also recommended the Assistant Secretary for Preparedness and Response do the same for the Government Coordinating Council’s Cybersecurity Working Group and HHS Cybersecurity Working Group, as well as update the charter for the Joint Healthcare and Public Health Cybersecurity Working Group for the current fiscal year.
HHS agreed with those recommendations.
Cornelius leaves ADI to join staff of Sen. Gary Peters
Executive director at the Alliance for Digital Innovation, Matthew Cornelius, has left the trade body to take up an advisory role in congress.
He joins the majority staff for Homeland Security and Governmental Affairs Committee chairman Gary Peters, D-MI. Peters also serves on the Senate Commerce, Science, and Transportation Committee and the Senate Armed Services Committee.
Cornelius has led ADI since December 2019, and prior to this worked in several technology-focused roles in government before leading the trade group that focused on modernizing government IT.
His previous jobs included stints at GSA advising the administrator on cybersecurity, at the Office of Management and Budget and the Department of Treasury.
In his new job he will advise on the scrutiny of federal technology programs including the GSA’s Technology Transformation Services.
German government launches $12B fund to finance tech startups
The German government has launched a 10 billion euro ($12 billion) equity fund to support the launch of technology startups in the country.
The state-backed fund was first proposed in August 2020, and is intended to address concerns that entrepreneurs in the country have had to turn to foreign investors because of a lack of domestic venture capital.
In the U.S. government grants for startup businesses are available, yet a small percentage of entrepreneurs take advantage of the funding, which is in part due to the lack of knowledge of these government grants.
The two most prominent awards in the U.S. are The Small Business Innovation Research (SBIR) program and the Small Business Technology Transfer (STTR) Program. Both are designed to help startups engage in research and development, similar to the Future Fund.
Details of the scheme were revealed earlier this year in March. At the time, Germany’s Federal Minister of Finance, Olaf Scholz, said it was “critical” for the country to provide assistant to startups, and said the state had laid the foundation for boosting the VC market in in the country.
Federal Minister for Economic Affairs Peter Altmaier also said at the time that the government would work also with the private sector, and that in total it would raise at least EUR 30 billion ($35.7 billion) in VC support for startups.
“Combined with our existing financial instruments we will be able to provide over EUR 50 billion ($60 billion) in venture capital for startups in the next few years together with private investors.
“This is unique in Europe and is also a significant contribution by international comparison,” said the minister.
Bill to create federal rotational program for cyber experts passes to House floor
The Oversight Committee sent a bill that would create a federal rotational program for private-sector cybersecurity experts to the House floor Tuesday.
An identical version of the Federal Rotational Cyber Workforce Program Act is working its way through the Senate after being reintroduced there and in the House in April and May respectively.
If created, the rotational program would allow senior tech industry workers to ply their trade for the U.S. government for a set period before returning to their original or a similar role in the private sector.
Sens. Gary Peters, D-Mich., and John Hoeven, R-N.D., first proposed the legislation in 2019, but recent, high-profile cyberattacks like the SolarWinds hack have increased the urgency of lawmakers attempting to help agencies recruit and retain top cybersecurity talent.
“While we don’t agree on everything, the severity of the cyber threat has proven so immediate that both conservative Republicans and progressive Democrats came together to support our bill,” said Reps. Ro Khanna, D-Calif., and Nancy Mace, R-S.C., in a joint statement. “As we saw recently with the Colonial Pipeline attack, the cyber threat is real and ever present.”
Khanna and Mace reintroduced the bill in their chamber and thanked Rep. Carolyn Maloney, D-N.Y., who chairs the Oversight Committee, for moving the bill — which they expect House leadership to take up soon.
Agencies would be expected to select rotational positions with integrated cyber missions, with the Office of Personnel Management overseeing the program in coordination with the Chief Human Capital Officers Council, Chief Information Officers Council and Department of Homeland Security. The Government Accountability Office would study a pilot version of the program’s effectiveness, prior to it being scaled up.