Internships are ‘primary mechanism’ to expand federal cyber workforce, says Partnership for Public Service CEO
The CEO of the Partnership for Public Service has called for an expansion of cybersecurity internship programs, describing them as the “primary mechanism” for getting new talent into entry-level jobs at federal agencies.
“Our federal government needs to approach talent management as the best private sector organizations do,” said Max Stier, speaking at a congressional hearing on Thursday. “We think our student internship program is our primary mechanism for identifying talent for entry-level [cybersecurity] jobs.”
Thursday’s hearing was hosted as lawmakers debate the most effective way to foster a new generation of cybersecurity experts in government in response to the rise in cyberattacks on critical infrastructure. It follows also a memorandum from the Biden administration yesterday that will create new performance goals for federal agencies.
Converting internships into full-time, fully paid government positions is currently a laborious process and can leave candidates waiting for up to 100 days before receiving a job offer. Roles requiring security clearance often result in a longer delay for potential employees.
Stier said also that more granular metrics should be used to judge the success of departments in recruiting and retaining a broad range of candidates.
“The most senior leadership in government need to hold their teams accountable to make sure these numbers are good,” he said. “If they prioritize it themselves, you will see change.”
Among key challenges for federal agency cyber recruitment is the age of the workforce, which has fewer than 6% of staff under the age of 30.
In a conversation with FedScoop earlier this month, cloud technology experts identified the expansion of internships and partnerships with colleges and other institutions as key ways of tackling a lack of cloud talent.
The Partnership for Public Service is a D.C.-based nonprofit that is focused on improving how government agencies function.
Aging infrastructure the ‘single, greatest threat’ to NASA missions and technology
NASA infrastructure should be part of the wider effort to fund federal research and development infrastructure, said Rep. Eddie Bernice Johnson, D-Texas, during a House Science Subcommittee on Space and Aeronautics hearing Thursday.
The chair of the full committee said NASA‘s infrastructure needs include one of the nation’s most powerful supercomputers, utility and access systems across nine centers and other research and test facilities, wind tunnels for developing subsonic and hypersonic aircraft, and clean rooms and vacuum chambers for building sensitive interplanetary spacecraft.
NASA Administrator Bill Nelson has previously said the agency’s full list of infrastructure needs is more than $5.4 billion, which includes $2.6 billion in deferred maintenance — roughly 7% of its $39 billion asset value.
“NASA’s infrastructure represents the single, greatest threat to mission success,” said Robert Gibbs, associate administrator for NASA’s Mission Support Directorate. “Practically 82% of our facilities are beyond their designed life.”
Annual maintenance requirements increase every year and exceed NASA’s resources, which will begin jeopardizing efforts to return to the moon, establish a permanent lunar base and reach Mars, understand the impacts of climate change, and make engineering breakthroughs in the “near future,” Gibbs added.
Many of NASA’s buildings and laboratories date back to the National Advisory Committee for Aeronautics and Mercury, Gemini and Apollo projects, and Artemis Program investments are needed to maintain technical capabilities.
In addition to the hypersonic tunnel at Langley Research Center with high-speed air travel implications, NASA wants increased funding for its new robotics lab within the Jet Propulsion Laboratory benefitting Mars exploration and its recently opened Health and Human Performance Laboratory at Johnson Space Center studying the impacts of space travel.
JSC also runs NASA’s space sample return program, which hasn’t yet sited a new facility for processing samples returned from Mars. Missions like that are consistently prioritized over NASA’s deferred maintenance backlog across 5,000-plus buildings and structures.
“The reality is I’ve had to delay, defer, descope 47 [construction] projects over the last two budget cycles because I just didn’t have the resources,” Gibbs said.
The House Science Committee hadn’t examined NASA’s infrastructure since 2013, when the deferred maintenance backlog was $2.1 billion, and the agency received less funding than it’s requested 10 out of the last 12 budget cycles.
Rep. Brian Babin, R-Texas, said NASA’s infrastructure funding request needs to be formalized, rather than remaining an “off-budget wishlist.”
NASA’s fiscal 2022 request represents a $6.3% increase on last year with an additional $3 billion for safety, security and mission services that include maintenance and operations. But the agency’s request for construction, environmental compliance and remediation represents a 9% reduction.
“If NASA’s facilities and infrastructure are in need, they should be appropriately prioritized in the agency’s budget request,” Babin said.
Riggs said mission, safety and health remained higher priorities in the budgeting process, but there’s an opportunity to invest in state-of-the-art facilities and demolition of outdated ones to shrink NASA’s footprint.
Exactly how lawmakers plan to approach the problem remains up in the air.
“While the path forward in Congress might not yet be totally clear, my commitment to addressing our R&D infrastructure needs is steadfast,” Johnson said. “Science, research and innovation are our future.”
ABMS test events focus on applying tech to enterprise IT
As the Air Force continues testing artificial intelligence programs for the future of connected warfare, it is also assessing how some of that tech can support the service’s broader enterprise IT modernization goals.
The Air Force recently wrapped up its fifth Architecture Demonstration and Evaluation (ADE) event, which brought together 11 combatant commands, 46 commercial companies and a host of tech-focused offices throughout the Department of Defense to test emerging tech in the battlefield.
The ADE events were created to test the Advanced Battle Management System (ABMS) and other programs. ABMS is designed to link more data from battle together and use artificial intelligence to help analyze it. Demonstrations for the events went from July 8-28, according to a release.
The latest experiment tested new “packages” of communications technologies that could improve both the reliability and security of data flowing across the globe, Preston Dunlap, the Air Force’s chief architect, said during a press conference Thursday.
Those new technologies could also be used to improve enterprise IT, he added.
“We have always been doing that; however, in the first year we had been laser-focused on [the Advanced Battle Management System],” Dunlap said of the event’s focus on IT, not just ABMS.
ABMS is the Air force’s contribution to Joint All Domain Command and Control (JADC2) — a framework the military hopes the services will implement where all data and communications are linked from air, land, sea, space and cyberspace operations. AI will be central to this new way of waging war to sift through all that newly linked data and generate options for commanders.
During this fifth version of the demonstration, the team was looking to make successful tech “ubiquitous” for the Air Force enterprise, Dunlap said. That means new ways of transmitting data or securing endpoints for ABMS could become standard practice in enterprise IT.
Dunlap added that not only are specific pieces of tech being tested, but the entire underlying architecture of how tech is put together is also being tested. The open-architecture approach ABMS has could also be a template for enterprise IT solutions, Dunlap said.
“ADEs are interned to be able to funnel together departmentwide space and air capabilities,” he said.
One program that showed success was the Defense Advanced Research Projects Agency (DARPA) called System-of-systems Technology Integration Tool Chain for Heterogeneous Electronic Systems (STITCHES). The software is essentially an automated translation service for data. When a weapon system or platform spits out numbers in a format unreadable to another machine, STITCHES can be one of the tools to help translate it to readable format.
The program was at risk of falling through the cracks of the DOD’s financial system, due to budgeting issues. Dunlap said the Air Force will be picking up the tab on the software, saying it could be a viable tool for future use. But it’s unclear how it would work on an enterprise level.
Tech was not the only thing experimented with — the operational construct of how tech gets used in battle was another focus. Much of that came down to arranging the right personnel, Dunlap said.
The event consisted of a broad collection of sub-events that included Northern Command’s Global Information Dominance Experiment 3 (GIDE 3) and IndoPacific Command’s Pacific Iron 2021 Agile Combat Employment. Dunlap described the model as a Venn diagram, where each event had large overlaps in technology used and personnel, but they also hosted their own, unique tests.
“We are drawing a common thread through it all,” Dunlap said.
Contributing to data and AI
One of the personnel moves the Air and Space Forces are making is contributing to a new initiative to send technical experts into the field. The AI and Data Accelerator Initiative (AIDA) sends small teams of data and AI experts out to combatant commands to build new tools to fit their specific problem sets. The idea came from the National Security Commission on AI and was implemented by the Deputy Secretary of Defense Kathleen Hicks.
Dunlap said the Air Force is already sending people to build tech that will help combatant commands in the field use their data better.
“We are pushing that hard and we already started building a minimum viable product,” he said.
The initiative is designed to be department-wide and eventually will include all services. Dunlap said the Air Force is leaning especially hard into it, praising the initiative as a way to put technical talent where it’s needed.
GAO survey of federal managers suggests progress needed on evidence-based policymaking
Only about 45%-47% of federal managers believe that staff within their agencies have the skills needed to collect, analyze and use different types of evidence, according to a survey by the Government Accountability Office.
The study, which was carried out by the oversight body between July and December last year, identified further concerns about the availability of tools and personnel needed to enact policies based on the foundation of clear evidence and analysis.
“These results suggest the finding from the Commission on Evidence-Based Policymaking’s report—that capacity to support evidence-building functions is uneven across agencies—persists,” said GAO.
The survey was carried out as part of GAO’s work to review the implementation of the Evidence-Based Policymaking Act, a responsibility that is encoded within the legislation itself.
Of respondents to the survey, between 50% and 60% said that within their specific programs, staff had the skills needed to collect, analyze and use different types of evidence. About half of federal managers reported that aspects of evidence building capacity existed to a “great” or “very great” extent across different types of evidence.
Despite the finding, nearly all federal managers – an estimated 95% of respondents – reported having at least one type of evidence for their programs. When evidence was available, about half to two-thirds reported using it in different decision-making activities, including in the allocation of resources.
Additionally, the survey found that only about one-third of managers surveyed said they used evidence to inform the public about a program’s performance.
In 2016, Congress passed and President Trump signed into law the Evidence-Based Policymaking Commission Act of 2016, which established a commission to examine the comprehensive data infrastructure associated with federal policymaking.
When it reported in September 2017, the commission found that agencies’ capacities to generate a range of evidence were uneven and that where it existed, it was often poorly coordinated.
The Evidence Act, which was subsequently passed in 2019, represents a continuation of laws and executive actions to establish officer positions to improve federal government management, which began with the Chief Financial Officers Act of 1990.
In its report, GAO concluded that the Office of Management and Budget and the Office of Personnel Management should use its findings to improve implementation of the act, but did not offer further recommendations.
CACI gets $496M Air Force contract for automated system testing
The Air Force Sustainment Center issued a $496 million indefinite delivery, indefinite quantity contract to CACI to do automated testing and modernization on a range of legacy system.
The contract, called the Air Force Automated Test System Sustainment Initiative II (ATSSI II), has a nine-year work period and extends previous testing work to new weapons and sub-systems.
“We are proud to bring our highly-skilled workforce and mission technology to expand our partnership with the U.S. Air Force to ensure their critical systems are resilient and ready for the connected battlespace of today and tomorrow,” CACI’s CEO John Mengucci said in a statement.
Under the contract, CACI program engineers and software developers will aim to ensure operational safety, suitability and effectiveness of multiple Air Force weapon systems and sub-systems through automated testing. The Air Force selected CACI for its “software methodologies” and “robust industrial process controls and quality systems.”
CACI was one of 144 vendors selected by the Defense Intelligence Agency in March to participate in its $12.6 billion Solutions for Information Technology Enterprise III contract. In 2019 the company was also awarded an $880 million task order by the Army for personnel and force management.
Army awards $2.4B National Cyber Range contract
The Army has awarded a potential $2.4 billion contract to 14 companies to provide IT services to its National Cyber Range Complex.
According to the Department of Defense, companies that have won spots on the potential 10-year contract will compete for individual orders. They will provide event planning and execution, site security, information technology management and range modernization and operations support for the military’s cyber mission force teams.
The National Cyber Range is an Army program focused on improving battlefield resilience by creating operationally representative cyberspace environments for testing, training and mission rehearsal. Since 2014, it’s been solely supported by Lockheed Martin.
Now, the 14 companies on the contract, which include Lockheed, Boeing, Command Post Technologies and Axiologic Solutions, will compete for task orders.
Army Contracting Command received 29 bids for the cost-plus-fixed-fee and order-dependent contract and expects work to conclude by July 26, 2031.
Top space acquisition general Thompson retires
The Air Force‘s top general in charge of acquisition for space systems has retired, paving the way for the Space Force to stand up its own space procurement command.
Lt. Gen. John Thompson stepped down from the post of commander of the Space and Missile Systems Command (SMC) Tuesday, where he oversaw 6,300 personnel and $9 billion. The command will be dissolved and a new Space Systems Command will be established in its place to focus on developing and purchasing space technology. Pending Senate confirmation, the new command will be led by Space Force Maj. Gen. Michael Guetlein, who the president nominated in mid-July.
“Heading into this next chapter in space history, I look forward to the establishment and activation of the Space Systems Command and how that takes this organization, our processes and our people even further,” Thompson said.
He leaves after 36 years in uniform in the Air Force. Much of his career was spent in acquisition and logistics, including assignments at Air Force Material Command and the office of the Assistant Secretary of the Air Force for Acquisition, Technology and Logistics, according to a statement on his retirement.
“Whatever we do in support of the Department of Defense, it starts with developing and acquiring space capabilities. All of that is done here, under the stellar leadership of JT,” Chief of Space Operations Gen. John Raymond said at Thompson’s retirement ceremony.
If confirmed, Guetlein will be in charge of ongoing reform efforts within the Space Force’s acquisition structure. Some lawmakers have been frustrated with delays in the new branch’s plan, which many had hoped would adopt agile acquisition practices.
“The Space Force lacks a clear plan which defines its future space architecture and lacks a strategy for how this architecture will be acquired,” lawmakers wrote in a summary of the fiscal 2022 defense appropriations bill.
FITARA scores mostly stay firm, with TMF and cyber EO changes looming
Editor’s Note: This story has been updated with information from the 2 p.m. FITARA 12.0 hearing of the House Oversight and Reform Subcommittee on Government Operations.
Most agencies’ FITARA grades stayed the same on the 12th biannual scorecard released Wednesday — but big shifts could be coming as they begin new Technology Modernization Fund (TMF) projects and meeting the mandates of the president’s recent cybersecurity executive order.
Among the 24 Chief Financial Officer Act agencies analyzed, 18 maintained their grades, four improved them and two saw downgrades — with the General Services Administration restoring its sole A+ status from two scorecards ago.
Much of the stagnation can be attributed to agencies’ focus on change management to accommodate increased telework during the pandemic. But an influx of TMF funding — coupled with aggressive timelines to improve federal cyber preparedness — could prompt the House Oversight and Reform Subcommittee on Government Operations to tweak the expectations of agencies for the FITARA 13.0 scorecard.
“You can view this scorecard as really the baseline for the implementation of TMF and the [cyber] executive order,” Joe Flynn, public sector chief technology officer at Boomi, told FedScoop. “The modernization and cybersecurity things are really going to take front and center regarding upcoming work.”
The American Rescue Plan Act infused $1 billion into the TMF in March, and the TMF Board has received 108 project proposals, worth more than $2.1 billion in requested funds, from 43 agencies. Proposals continue coming in to the TMF Board, which spends about 10 hours a week reviewing them, as most agencies have “pretty significant” project backlogs and need flexible IT modernization funding, said Clare Martorana, federal chief information officer, during the subcommittee’s FITARA 12.0 hearing.
But the final version of the Financial Services and General Government appropriations bill for 2022, produced by the House Appropriations Committee on Monday, only included an additional $50 million for the TMF — well shy of the White House’s request for $500 million.
“The Administration appreciates the funding provided in the bill for the TMF and urges the Congress to provide the full $500 million requested in the FY 2022 Budget, which would support a more rapid transition of legacy systems and the adoption of more secure commercial technology,” reads a statement released by the Office of Management and Budget later that day.
Even so, TMF funds will have a “significant impact” on future FITARA scorecards as the money begins to flow — especially with OMB having released guidance relaxing repayment requirements for agencies, Flynn said.
During the FITARA hearing, Rep. Jody Hice, R-Ga., suggested the subcommittee consider adding a component grading agencies’ use of TMF funds for IT modernization.
“Those funds are spread around, but what’s their impact?” Hice asked. “What are we really getting in relation to modernization? Is it happening?”
Hice also wondered aloud if more cyber components should be added to the scorecard or spun off into a separate one.
The cyber executive order, issued by President Biden in May, contains tight deadlines — including a 60-day cutoff for all executive branch agencies to update their cloud adoption plans and develop zero-trust architecture implementation plans.
Martorana said cybersecurity was her “immediate priority,” and the FITARA 12.0 scorecard confirmed it’s a place where agencies continue to lag.
“Cybersecurity continues to be an area of struggle for the agencies,” said Carol Harris, IT and cybersecurity director at the Government Accountability Office, during the hearing. “One-third have a D or F, and another third are getting by with a C.”
The FISMA component of the FITARA scorecard is but one dimension of federal cyber, and GAO is open to adding more, or creating a separate scorecard, at the subcommittee’s discretion — provided agencies’ vulnerabilities aren’t publicly disclosed, Harris said.
Rep. Gerry Connolly, D-Va., who chairs the subcommittee, said he’s open to evolving the scorecard but is hesitant to add more components currently.
“I definitely see the FITARA scorecard as always a work in progress,” Connolly said. “The only caution is, as you can see from the grades in front of us, we have not yet succeeded in full implementation, so we don’t want to lose sight of that.”
The departments of the Interior and State and the Social Security Administration were the three other agencies to improve their FITARA 12.0 grades, while the departments of Justice and Veterans Affairs saw the only downgrades.
DOJ now holds the worst overall FITARA grade with a D-. A C or higher is considered a passing grade.
Agency transitions to the $50 billion Enterprise Infrastructure Solutions contract for network and telecommunications modernization, a component of the FITARA scorecard, continue to advance slowly. Two agencies — SSA and the U.S. Agency for International Development — received As for being at least 50% transitioned off the legacy Networx contract.
While NASA and SSA appointed CIOs since FITARA 11.0, the Department of Health and Human Services CIO continues to serve in an acting capacity. And the Department of Defense, DOI, Department of Transportation, VA, and Office of Personnel Management all have acting CIOs as of FITARA 12.0 — though OPM just recently named Guy Cavallo, who’d been acting in the role, its permanent CIO.
White House urges Congress to increase proposed $50M funding for TMF
The Office of Management and Budget has called on lawmakers to increase the $50 million Congress has proposed adding to the Technology Modernization Fund as part of the fiscal 2022 appropriations process.
The proposed figure, which is 90% less than the $500 million initially sought by the Biden Administration in April, was included in an appropriations bill drafted Monday by the House Committee on Appropriations. The legislation has now been passed to the full House for consideration.
“The Administration appreciates the funding provided in the bill for the TMF and urges the Congress to provide the full $500 million requested in the FY 2022 budget,” said OMB, adding that the TMF has received more than 100 proposals from agencies, totaling over $2.1 billion in requested funds.
TMF was authorized by Congress in 2017 and provides funding that agencies can apply for to support their modernization projects.
OMB ‘disappointed’ by State, NIST proposals
In addition to its comments on TMF funding proposals, OMB said also it is “disappointed” by Congress’ plans to provide the State Department’s Capital Investment Fund (CIF) with just $275 million, below the $449 million previously requested.
“The budget requested a substantial increase for CIF to address the national security threat posed by increasing cyberattacks. Notably, the bill fails to include $101 million to safeguard the Department’s cybersecurity infrastructure in direct response to the SolarWinds incident,” OMB said in a statement. “While the bill authorizes up to $150 million in transfer authority from the diplomatic programs account to the CIF account, no additional funds were provided in the DP account that would allow for the effective use of this authority.”
The State Department’s CIF was established by Congress in 1994 to ensure the efficient management and coordination of IT resources. According to State’s fiscal 2022 budget request justification, extra funding is needed for its CIF to tackle key areas of concern, including cybersecurity event logging, cyber incident response, and cloud security.
OMB has also called on lawmakers to expand funding for the National Institute of Standards and Technology’s Manufacturing Extension Partnership, which currently stands at $125 million above fiscal 2021 spending. This is well below the $462.7M sought to grow funding for nationally critical mission areas and expand NIST’s manufacturing programs.
“[T]he Administration urges the Congress to provide the full FY 2022 Budget request for Manufacturing USA institutes. The Administration believes that a comprehensive manufacturing strategy is crucial to bringing jobs back to the United States, and that the Manufacturing USA institutes play a critical role in that effort,” OMB said.
Lawmakers push DOD to identify legacy IT in 2022 NDAA draft
The new House subcommittee charged with overseeing the Department of Defense’s cybersecurity and IT programs wants the department to take stock of all the legacy systems that could be sunset, according to a summary of draft legislation.
Initially published Tuesday in the House Armed Services Subcommittee on Cyber, Innovative Technology and Information Systems markup of the fiscal 2022 National Defense Authorization Act, the proposed mandate calls on each of the military services to audit their IT portfolios for legacy systems and applications within 270 days of the NDAA’s enactment, typically Jan. 1.
Secretaries of the services would also be required to issue a report to Congress that — in addition to identifying the legacy IT, their sources of funding and who’s accountable for their operation — lays out a plan to discontinue use and funding for those systems to “ensure that redundant and unnecessary investments can be better aligned to departmental priorities,” the draft says.
The subcommittee approved its draft Wednesday and sent it to the full committee for markup and inclusion in the larger annual defense policy bill, a process that begins Sept. 1.
Other notable proposed additions from the subcommittee include reports on how the department is overcoming barriers to scaling innovation. There are many offices focused on building and buying prototypes of emerging technology, but few that have the ability to turn small improvements in tech into broader enterprise changes. It’s a challenge that leaders in Congress and in the DOD have long bemoaned.
“This year’s mark makes substantial progress in key areas of innovation, technology transition, and emerging areas of competition including the information domain and electromagnetic spectrum,” subcommittee Chair Rep. Jim Langevin, D-R.I., said in an opening statement.
This is the subcommittee’s first mark since it was created in a February reorganization of the House Armed Service Committee to focus its legislative work more on the DOD’s pivot to competing with China through technical means.
Other provisions in the mark include:
- A report on the effectiveness of DOD’s Silicon Valley outpost that works to purchase emerging technology, the Defense Innovation Unit;
- A report on the barriers DOD faces in scaling emerging technology acquisitions, like the prototypes DIU purchases, and a pilot program to break through those barriers;
- A pilot program to more effectively transition Small Business Innovation Research grants onto larger contracts;
- Increase cyber threat testing and protections for DOD systems;
- A report on the state of digital twin practices, where physical objects have artificial mirror images of them stored in software; and
- New hiring authorities to pay for relocation fees for 15 Defense Advanced Research Projects Agency (DARPA) employees a year.
The proposed requirement for the services to report on their legacy IT systems comes after members of the subcommittee expressed frustration with DOD’s own tracking of its IT. In hearings before the mark was released, Langevin chided acting DOD CIO John Sherman over a lack of transparency on how the DOD accounted for its disparate IT systems.
“With all due respect, if your office cannot be troubled to put together the necessary materials for this committee’s oversight, how can we trust the stewardship of this critical portfolio?” he said in a previous hearing.