Hyten signs new requirements to ensure military services make data accessible

Gen. John Hyten, the vice chair of the joint chiefs of staff and head of the Joint Requirements Oversight Council, has signed four new strategic directives that mandate all U.S. military services to make data accessible for all their weapons and platforms.

The new directives are based off recent “Data Decrees” signed by the Deputy Secretary Kathleen Hicks in May, which give specific advice on data management and call on senior leaders to use the DOD’s Advana platform as a central repository for data analysis that is used to support decision making.

The latest requirements are intended to support the development artificial intelligence systems within the DOD, which require access to vast datasets in order to learn new capabilities. In the private sector, tech giants such as Amazon, Apple and Microsoft have long relied on access to such pools of data for the development of AI-supported search functions such as Alexa and Siri.

“Thee simple requirement will be from this day forward all data form the Department of Defense … will be accessible. period. It has to be that way, there can be no other alternative,” Hyten said.

“Services will have to build their systems to meet that requirement,” he added.

Hyten said that without interoperable and accessible data, further dreams like implementing artificial intelligence can’t become a reality.

Hyten also urged the department to adopt enterprise cloud computing capabilities. Not mentioning the stalled Joint Enterprise Defense Infrastructure (JEDI) by name, Hyten said that without a “real cloud” the DOD won’t be able to use and store all of the newly interoperable and accessible data.

Once the DOD has large, accessible data sets and the cloud capabilities to turn that data in to intelligence, networking together operations across the domains of air, land, sea, space and cyberspace operations will be the new means the DOD thinks about deterrence.

“That will create a deterrent that is nearly as powerful as our nuclear deterrent,” Hyten, who used to lead Strategic Command which controls the U.S. nuclear arsenal, said.

House lawmakers propose $50M for Technology Modernization Fund in 2022

House Democrats published a draft bill Wednesday that would allocate just $50 million to the Technology Modernization Fund during fiscal 2022.

The legislation, which was proposed by lawmakers on the House Appropriations Committee, would provide the TMF with one-tenth of the $500 million requested for the 2022 budget last month by the Biden administration, which also called for $9.8 billion to support civilian cybersecurity programs across government. However, it’s double the sum deposited in the fund in recent appropriations cycles.

TMF earlier this year received a $1 billion emergency injection as part of the American Rescue Plan Act after widespread lobbying by lawmakers and tech advocates for nearly a year. Federal agencies have drawn on the TMF to support long-term technology modernization, including DHS, which has applied for money from the fund to support at least four projects.

Budget funding requests are determined by lawmakers on the House and Senate appropriations committees. It is relatively unusual for House lawmakers to advocate for a sharp reduction in requested funds.

The legislation also provides funding of $34 million for the U.S. Treasury to cover a range of measures including technology modernization, and it also would approve a separate $132 million funding pool for the enhancement of cybersecurity systems at the department.

If enacted, it will also provide the Treasury’s CIO with $4 million to cover administrative expenses incurred while making cybersecurity improvements.

The draft legislation also outlines provisions for the IRS to receive $305 million for necessary expenses relating to business systems modernization.

Under the proposal, the Office of Management and Budget would receive $10.4 million for technology and the Office of Personnel Management would get $8.8 million for IT modernization and trust fund federal financial system migration or modernization.

The draft bill also would approve a budget for the newly created role of National Cyber Director, providing $15 million in funding for the position for the fiscal year.

GSA creates $2.1B contract for NOAA’s IT

The General Services Administration has created a $2.1 billion contract that will allow the National Oceanic and Atmospheric Administration to buy IT tools and services from small businesses faster.

Launched as a 10-year, multiple-award blanket purchase agreement off of GSA‘s Multiple Award Schedule (MAS), the NOAA Mission IT Services (NMITS) contract covers application administration, enterprise and cloud computing, cybersecurity and information assurance.

The contract is part of a broader effort by GSA to standardize requirements, thereby streamlining governmentwide acquisition, through its MAS program.

“NOAA’s missions are vitally dependent on IT services,” Zachary Goldstein, chief information officer at NOAA, said in an announcement Wednesday. “With the award of NMITS, NOAA can more rapidly access highly qualified private sector talent, a key to cost-effectively operating and modernizing our information management environment, and advance our service to the American people.”

NMITS consists of five base years and a five-year option period and will be administered by NOAA’s Office of the CIO and other NOAA offices.

GSA’s MAS covers more than 7.5 million IT products and services from more than 4,600 pre-vetted suppliers and is available to federal, state, local and tribal agencies. By streamlining IT acquisition under a single category on the contract, it has reduced buying cycles by up to 50%, GSA says.

“These types of solutions make it easier and allow our partners to focus on their mission instead of acquisition while helping speed up their procurements,” said Laura Stanton, assistant commissioner of IT Category at GSA. “We pride ourselves on close agency partnerships like this, and we are thrilled to support NOAA with its complex IT needs.”

DHS applied for TMF funding for 4 projects, CIO Hysen says

The Department of Homeland Security has applied for Technology Modernization Fund money to support four of its modernization projects, CIO Eric Hysen said Tuesday.

Hysen intends to make the department an “active user” of the TMF, which recently got a $1 billion injection under the Biden administration’s American Rescue Plan Act, he said at the Professional Services Council’s Federal Acquisition Conference.

DHS‘s four projects run the gamut, from improving the processing of immigrants at the southern border and making “the experience of going through an airport easier, more seamless, and more secure,” Hysen said, to modernizing how DHS components work with data in conjunction with the department’s new Office of the Chief Data Officer and better sharing threat information with state and local law enforcement.

Hysen said DHS is approaching the TMF now differently than it has in the past by looking to apply modernization across the department, rather than focusing only on single components. Customs and Border Protection, a DHS component, won a $15 million TMF award last July to continue modernization of its Automated Commercial System, a mainframe platform that runs on  3.9 million lines of COBOL code to track, control, and process everything imported into the U.S.

“[W]hat we’re trying to do very deliberately is not just use the TMF as an opportunity to look at our big list of unfunded modernization programs that we just need one vendor, we already have a whole plan for, but really to look at common problems and challenges across the department and set up systems and structures that will allow us to move together because we think we can get a lot more done if we modernize in common, aligned ways across DHS components and systems,” he said.

To be clear, Hysen said, he’s not advocating for DHS to build single systems “to rule them all.” Rather, he said, “we want to address these issues holistically from the experience up from the perspective of the people that are depending on DHS, whether those be immigrants, travelers, state and local law enforcement officers, and using the TMF as a way to move to move forward together across different parts of the department.”

Since the $1 billion injection into the fund, the board that leads the TMF award process has introduced a more flexible model for agencies to repay those investments. The board is also prioritizing selecting and funding projects “that cut across agencies, address immediate security gaps, and improve the public’s ability to access government services.”

Zero trust and the cyber EO

Hysen described President Biden’s recent cybersecurity executive order as “one of if not the most ambitious attempts to lay out a new framework for federal cybersecurity ever.”

That order calls for federal agencies to modernize their cybersecurity, namely through the adoption of a zero-trust architecture. Hysen said while that’s the right direction to move in, it’s important to keep in mind that “zero trust is not something we’re going to buy and turn on one day.”

“[I]t’s easy to think about this as, ‘Oh, just buy your zero trust product, turn it on on your network, and then everything will be great,'” Hysen said. “And that is in no way what we’re talking about. When we think about zero trust, we think about, in many ways, a fundamental rethinking of our security architecture, away from this outdated model of perimeter defense — that we can build a wall around our network and everything inside is safe, everything outside is unsafe — and that we have to be securing every system, every server, every endpoint and our data as it moves within our network and outside of it. And that’s going to require a lot of time; this is not going to be something that we do overnight.”

DHS has a zero-trust working group led by its CTO “that’s working across our components to look at different approaches,” Hysen said, adding that the department is working in three-to-four-month sprints to deliver new pieces of the security architecture iteratively. First up, he said, is conditional access and rights management.

“I expect [zero trust] to be something that will only become more important over time, and will be important that we really do this as a marathon…because it is such a fundamental rethinking of our security architecture,” Hysen said.

AWS urges Supreme Court to reject Oracle JEDI review petition

Amazon Web Services has filed a brief with the U.S. Supreme Court urging it to reject an earlier petition by Oracle to renew its challenge to the Pentagon’s $10 billion Joint Enterprise Defense Infrastructure (JEDI) contract.

In a filing on June 18, the web hosting giant says Oracle’s case should not be heard because it relies on the contention that personal conflicts of interest with Department of Defense employees affected the outcome of the case.

“The alleged personal conflicts of interest (which concern the actions of DoD employees, not the actions of AWS) are highly fact-bound and had no effect on Oracle’s exclusion from the competitive range,” Amazon said in its filing to the court.

Oracle in January sought a review of the U.S. Court of Appeals for the Federal Circuit’s decision to uphold lower court rulings, which found it didn’t meet basic security requirements necessary to be considered for the contract. It represented the latest salvo in Oracle’s challenge to the contract, which was first launched in late 2018 alleging that DOD’s decision to award the contract to a single vendor was illegal.

Oracle also raised questions around conflicts of interest involving DOD employees involved in the procurement who went on to take jobs with Amazon — even though Amazon would ultimately lose its bid for JEDI.

In its latest submission to the court, Amazon argues that even if the court were to decide that officials involved in the contract procurement process were open to influence, it would not impact the outcome of the case because Oracle did not meet the basic gate security criteria for the contract.

“Specifically, DoD found that Oracle’s proposal failed to satisfy Gate 1.1, and Oracle conceded that it failed to satisfy Gate 1.2 ‘at the time of proposal,” AWS said in its Supreme Court brief.

AWS argues that it is not the appropriate venue for hearing such allegations because they are “intensely fact-based” and have no clear bearing on the contract’s outcome.

The filing of the brief is the latest step in the long-running dispute, and comes amid continued uncertainty over JEDI.

On Monday, Deputy Secretary of Defense Kathleen Hicks said the DOD could take a new direction on the contract by next month, and that it was “actively looking at [its] options”.

Earlier this month, a Court of Federal Claims judge granted AWS’s requested timeline for hearings in separate litigation objecting to DOD’s award of JEDI to Microsoft. The web hosting giant continues to seek the disclosure of additional internal communications from the Department of Defense, including emails and Slack messages.

This follows a decision in April by the same court to stop the government from dismissing AWS’s allegations of political interference. The DOD in January sent an “information paper” to Congress explaining the potential impacts if the case continued for an extended period.

AWS and Oracle did not immediately respond to a request for comment. A DOD spokesperson declined to comment.

Industry matters when assessing cyber risk to the defense industrial base

Manufacturing and research and development companies — not simply small and medium-sized businesses (SMBs) — bear the highest risk of cyberattacks within the defense industrial base, according to a BlueVoyant report released Tuesday.

The New York City-based cybersecurity company independently analyzed available third-party data from a sample of 300 small and medium-sized defense contractors and found industry mattered more than size in determining cyberattack risk. Smaller businesses remained more susceptible within their industries.

BlueVoyant’s report comes after a string of successful cyberattacks that targeted SMBs and raised the question of whether they, with their limited defenses, offer easiest access to the supply chain. The answer is more nuanced.

“Not only are R&D firms vulnerable, they are particularly attractive to attackers,” reads the report. “R&D firms work on cutting-edge products, develop valuable IP, and often create and sell software and tech that become components in larger and more important systems making them attractive as points of entry for malicious insertion or IP theft.”

More than half of the SMBs assessed had unsecured ports critically vulnerable to potential ransomware attacks, while 48% had those and other severe vulnerabilities, like outdated software or operating systems, rendering them “high risk.”

Nearly 20% of the SMBs had multiple vulnerabilities and showed evidence of threat targeting, while 7% deemed “critical risk” had been compromised in some way.

BlueVoyant found 28% of the firms would likely fail to meet the most basic, level 1 Cybersecurity Maturity Model Certification requirements. That statistic is more troubling with nation-state adversaries and cybercriminals proving increasingly adept at finding the weakest link within supply chains and when exploitable weaknesses abound among SMBs.

Roughly 300,000 companies directly contract with the Department of Defense, and its CMMC requires “significant investment” in new controls from SMBs with limited budgets and technical expertise, according to the report.

Meanwhile, contract primes and other large companies are under “enormous pressure” to reduce the attack surface of their supply chains, without full visibility into the network security of the subcontractors they’re responsible for, according to the report. The financial and logistical costs of designating subcontractors to CMMC tiers and ensuring their compliance isn’t cheap, especially when one business’ tier may vary contract to contract — causing some primes to force their subcontractors to level up.

While BlueVoyant had no way of determining firms’ cybersecurity maturity in line with CMMC compliance, it did recommend companies use continuous cyber monitoring to secure their supply chains. More than six months after the announcements of the F5 and Microsoft Exchange vulnerabilities, nine companies that were either small manufacturers or large R&D companies still hadn’t addressed them due, in part, to reliance on point-in-time compliance assessments.

Most vulnerabilities SMBs had were tied to email security protocols or else unsupported software, suggesting a lack of patching policies and continuous monitoring, according to the report.

Primes should further focus on addressing issues with high-risk subcontractors based on industry and then size, BlueVoyant recommended.

The company believes predictive risk analysis of SMBs is ultimately possible but said a sample size larger than 300 businesses is needed.

DOD looks to boost cloud capabilities on foreign soil

The Department of Defense is looking for the support of foreign countries to build data centers and cloud computing capabilities outside of the U.S. to boost its global connectivity, according to a new cloud strategy document released in late May.

The challenge is that the DOD needs to have total control of and access to both its data and the computing resources it will use to analyze it, but many foreign countries have laws that allow them as host nations to access any data stored on their soil. According to the department’s new Outside the Continental United States (OCONUS) Cloud Strategy, that would be a problem that requires DOD to negotiate directly with host nations and lean on commercial cloud service providers to keep its data and cloud capabilities private.

“Given the challenges with meeting host nation data control requirements, cloud service providers must make a significant investment to support OCONUS locations,” says the strategy, which was signed by acting CIO John Sherman.

The DOD wants to bring full cloud capabilities to OCONUS locations to enable its modern strategic concept of operations called Joint All Domain Command and Control (JADC2), which relies on having the tech at hand to connect data from across all domains of the battlefield. Without the ability to store, transmit and analyze data, the military is without the core tech needed to support the new capabilities leaders have set as a priority.

“Cloud computing can help solve today’s national defense challenges, but its true potential is to solve tomorrow’s challenges,” the strategy states. “Collaboration across these domains, increasingly enabled by high-tech, software-driven solutions, must occur at the global point of need, at the tactical edge, and at the fight.”

Currently, the DOD manages more than 200 data centers on military bases outside of the U.S. on “status of forces agreements” that allow the military jurisdiction over the tech resources, a DOD spokesperson told FedScoop. DOD policy precludes any sensitive data from being hosted outside of places that the U.S. doesn’t have legal jurisdiction.

“Currently, the Department has limited data center capacity in its OCONUS locations when considering existing workloads, increasing data production, and growing use of commercial cloud services,” the spokesperson said.

The main goals of the new strategy are to provide resilient connectivity for military operations outside of the U.S., increase computing power and get more tech talent out into the field. The three goals all face challenges from the hostile environments for computing to the military’s tech skills gaps.

One workaround the strategy calls for is finding computing tech that has less size, weight and power (SWaP). More nimble compute power would relieve several of the constraints the strategy is contending with, including when the military needs cloud capabilities in areas with weak infrastructure.

“Data needs to be processed close to its source and staged as close to the warfighter as possible to enable data-driven decisions,” the document states.

Other objectives within the strategy include instituting more training for service members and civilians based outside of the U.S. and building out a “Mission Partner Environment” for partnered militaries to link safely into U.S. systems with the right level of access.

Cybersecurity asset management trends point to increasing complexity

Nathan Burke, chief marketing officer at Axonius, has over 15 years of technology and leadership experience. He is passionate about bringing new technologies to solve real cybersecurity problems.

Nathan Burke, Chief Marketing Officer, Axonius

Increasing visibility into government infrastructure remains a key challenge to combat security threats. And though agencies most likely have all the security tools they need, IT leaders still struggle to see how those tools are properly deployed across their networks and devices.

The pandemic and remote work environment certainly accentuated these challenges, but these aren’t the only factors driving visibility and security risks, according to a recent study Axonius commissioned with Enterprise Strategy Group (ESG).

The second annual Cybersecurity Asset Management Trends report surveyed IT and cybersecurity professionals across organizations in North America to understand current asset visibility challenges and trends. According to the findings, 72% of respondents reported that modern IT infrastructure complexity has continued to grow over the past two years.

If you think back 10 to 15 years, most organizations had a pretty standardized set of devices or applications on the network. However, the state of IT environments today raises a lot of questions about what an IT asset is. Is an Amazon storage instance an asset? Or an IoT device? What about ephemeral devices that may live for only an hour?

Organizations have not only increased the types of devices that need to be managed, but the pace of change, which requires almost a more robust and up-to-date asset inventory.

Additionally, with different device types, organizations have also acquired different solutions to manage or secure them. The report findings indicate that on average, organizations depend on eight different tools to pull together asset inventories. And the average asset inventory will take 86 person-hours to generate.

Post-pandemic response presents new opportunities

Though the shift to remote work accentuated complexity and visibility challenges within government IT infrastructure, the preparation for employees to return to the office presents IT leaders with a notable opportunity to get back to the basics of asset management and cyber hygiene.

When federal employees return to the office, they will bring with them devices that either were not managed by agency IT or which have not been updated over the last year. The security risks of these visibility gaps may be striking for agency leaders.

And though it remains to be seen how government agencies will navigate hybrid-work structures, industry trends suggest the demand for remote work capabilities are on the rise. On average, respondents in the survey expect 40% of their organization’s workforce will work remotely after the COVID-19 outbreak is controlled — an increase from 23% prior to the pandemic.

In addition to remote work needs, the rapid development of digital services is making it more difficult for IT to answer simple questions about their assets.

Eight in 10 people in the survey acknowledged facing visibility in gaps in the cloud, up by 10% from last year. Respondents also reported widening visibility gaps with end-user devices (75%) and IoT devices (75%).

The study suggests that IT and business teams are getting applications, cloud services, and devices out to their workforce faster than what security teams can keep up with.

Moving from a reactive to proactive security position

While there is no shortage of security challenges that agencies are facing, the goal for now involves focusing the resources they have where they can deliver the most impact.

The recently issued cybersecurity executive order from the Biden administration promises to give cybersecurity modernization efforts greater attention. Though most agencies already have enough security and device management tools, many teams lack the visibility they need to be confident in complying with new security efforts.

Using a cybersecurity asset management platform offers a greater opportunity to close those visibility gaps.

The Axonius cybersecurity asset management platform, for instance, gives agencies the ability to gather asset and vulnerability data across an organization’s entire network into a centralized view. The platform connects to all of an agency’s different asset management and security tools to collect and analyze their respective data — regardless of the asset type.

The totality of that data, when combined and correlated, provides a powerful overall picture. But it also allows an organization’s IT team to query how any and every asset either adheres to, or deviates from, their security policies. The results often prove eye-opening. For example, one  Axonius customers recently ran a query to test the deployment of an endpoint protection tool and discovered that it was only installed on 40% of those devices that required endpoint protection.

Once vulnerabilities are exposed, an agency can decide what action to perform. So, if the query finds an endpoint that is missing an agent, an automated action can be programmed to install it, update a database or submit a ticket.

Taking steps towards achieving full visibility across federal agencies’ network environments will always come down to knowing what is on the network.

What we recommend above all: Use the momentum created by the pandemic and recent security incidents to encourage strategic conversations among agency leadership on implementing an operational plan for full network visibility today.

Learn more about how Axonius can help your organization address security risks with modern asset management solutions.

Industry group warns onerous criteria for GWACs may benefit large contractors

The Alliance for Digital Innovation (ADI) has urged caution over the introduction of further evaluation schemes for contractors bidding on governmentwide acquisition contracts, or GWACs.

In a report issued Tuesday, the industry group said that while it supports action by the federal government to tackle rising cybersecurity threats, the use of overly complex evaluation criteria benefits large incumbent companies working in the federal technology space, and may be stifling innovation.

“An example of this concern is presented by the recent heavy reliance on using scoring worksheets for evaluations of GWAC proposals (where companies must score high in order to receive an award),” says the report. “While this objective method of evaluating high numbers of offers can save time and protect the government from frivolous protests, the criteria used in these worksheets is based on traditional large, long-term government contracts.”

The report argues that such criteria “heavily favor the traditional large government contractors and create a huge barrier to entry for smaller, more specialized firms that provide deep expertise in specific technology solutions.”

In addition to raising concerns about one-size-fits-all evaluation criteria, ADI has called on GWAC administrators to engage more effectively with commercial industry. It noted that some agencies had made recent progress by appointing liaison staff to maintain relationships with the private sector.

“[M]any agencies still have a limited interest in meeting with potential vendors that are not familiar with the unique government culture and acquisition processes. This unintended bias particularly impacts nontraditional vendors whose commercial solutions were not built primarily to deal with government-specific requirements,” the report says. “Moving these activities further up in the procurement cycle gives GWAC administrators greater access to information, market intelligence, and customer feedback that can help them even before the first word of an RFP is published.”

ADI also called on GWAC administrators to show a more open approach to prior commercial use cases presented by new vendors. In some cases, according to the trade body, these may provide as accurate a guide as a company’s previous track record in government procurement.

“Just because a certain vendor (or vendors) have followed the letter of previous procurements and built the government whatever unique, bespoke solution they requested, that does not necessarily mean that they have the kinds of ideas, products, and services that will meet the evolving customer demands required in new GWACs,” ADI said in the report.

DOD to embed data experts within military units

The Department of Defense is launching a new Artificial Intelligence and Data Accelerator initiative (AIDA) that will embed teams of data experts within combatant commands, Deputy Secretary Kathleen Hicks said Tuesday.

Under the scheme, two types of teams will be embedded: operational data teams, which are focused on creating new tools and policies, and “flyaway teams” that are parachuted in to assist on specific problem sets.

The initiative is part of the DOD’s work to implement its Joint All Domain Command and Control (JADC2) strategy, which outlines a vision in which a military internet of things and data become central to the theater of war.

Hicks said the new data teams will bring “top tier talent and technology” to modernize the data and IT infrastructure combatant commands rely on and the policies that dictate data usage. They will start with a 90-day window to make improvements.

Artificial intelligence is to be used to sift through the large amounts of data being generated as part of the JADC2 strategy. AI systems in command centers will have the power to communicate directly with each other.

The strategy for how JADC2 could modernize military operations was signed by Defense Secretary Lloyd Austin in May, giving the department the approval to move ahead on new initiatives like AIDA.

The technology that is intended to drive JADC2 has largely yet to materialize. That’s one of the problems the new operational and flyaway teams will work on, building out the data platforms and AI infrastructure that will form the basis of the strategy.