VA’s McDonough reaffirms commitment to Cerner records management platform
The Department of Veterans Affairs will stick with the existing records management platform that forms the center of its electronic health records (EHR) strategy following a review of its modernization program.
The agency in March launched a 12-week review into the $16 billion program, following the identification of failures including by the Government Accountability Office, which in February recommended that the VA stop work on the program to updates its health IT and scheduling system.
Speaking Wednesday at a press conference, VA secretary Denis McDonough said the department was committed to the Cerner Millennium records management platform, which is provided by health care technology company Cerner. The secretary said it will likely take two further weeks to determine additional changes to the program that will be made following the review,
Cerner is building a cloud-based system for VA that the department says will eventually be interoperable with the DOD’s Military Health System (MHS).
“That’s the coin of the realm,” said McDonough, commenting on the interoperability of the new system.
The next sites to get the system will be a network of hospitals in Columbus, Ohio.
Prior inspector general reports have warned that the VA’s legacy systems and infrastructure may not be able to handle the load of the cloud system and new health IT interfaces.
Langevin takes DOD CIO Sherman to task for ‘unacceptable’ budget justification
The Pentagon wants more than $50 billion for IT and cybersecurity in fiscal 2022, but so far, it hasn’t given Congress a thorough enough justification for that money, according to a top cyber-focused lawmaker.
Rep. Jim Langevin, D-R.I., expressed disappointment Tuesday for the Department of Defense’s lack of specifics in its IT budget request summary for fiscal 2022 — which includes $5.5 billion for cybersecurity and much more for enterprise IT other “cyberspace activities” on top of that. The document gives top-level budget figures for the past and present, but few other programmatic details are shared.
Langevin rebuked acting DOD CIO John Sherman because much of the budget documentation for 2022 is “nearly a carbon copy” from the previous year, equating it to plagiarism. Because of this, DOD’s IT and cyber budget summary document shrank from 30 pages last year to six for fiscal 2022 — “only two of which contain any substance,” the congressman said.
“With all due respect if your office cannot be troubled to put together the necessary materials for this committee’s oversight, how can we trust the stewardship of this critical portfolio?” Langevin, chair of the House Armed Services Cyber, Innovative Technologies, and Information Systems Subcommittee.
He continued: “Without that level of detail, you need to understand, we can’t fulfill our oversight responsibilities; we’re in the dark otherwise,” Langevin said. “That’s unacceptable going forward.”
On top of this, Langevin criticized the department’s seeming lack of understanding of how to define and categorize total cybersecurity spending across its enterprise. For instance, the Navy and Air Force count end-point security differently toward their cybersecurity budgets, he pointed out. That lack of standardization in categorizing IT spending makes putting a top-line number on the DOD’s cybersecurity budget difficult, he said.
“I will own this…we need to do a better job,” Sherman said of the evidence his office presented Congress while pointing to new requirements to restrict some of the materials in the document as controlled unclassified information as part of the reason it shrank.
In addition to agreeing that his office needed to provide Congress more information, Sherman also admitted the issue with how DOD defines and categorizes IT spending — a problem the department perennially has across its budgeting activities. “$5.5 billion for cyber doesn’t indeed represent the totality of cybersecurity for the department,” he said.
Redundancies in the terminology DOD uses for cybersecurity could also create gaps in authorities of that spend, Langevin said, pointing out that DOD uses the terms “operational technology” or “industrial control systems” for the same protection of industrial systems, like air conditioning and elevators.
Langevin has long been a vocal proponent of funding cybersecurity and IT modernization. His subcommittee marks up the section of the defense appropriations bill that grants DOD its IT and cyber funding.
During his testimony, Sherman gave little else away on other hot-button issues, like the Joint Enterprise Defense Infrastructure (JEDI) cloud procurement. He reiterated comments made by Deputy Secretary of Defense Kathleen Hicks that the DOD is in the process of figuring out what it will do next to develop an enterprise cloud solution.
CMMC Accreditation Body board member Edens resigns
A founding member of the accreditation body implementing the Department of Defense‘s new contractor cybersecurity standards resigned Tuesday.
Regan Edens had served on the board of the Cybersecurity Maturity Model Certification Accreditation Body (CMMC-AB) since it was incorporated in January 2020 and led the Standards Working Group, the volunteer entity responsible for establishing CMMC programmatic definitions.
Edens declined to comment. The CMMC-AB confirmed Edens’ resignation in an email to FedScoop.
CMMC is the new program to increase the security of DOD’s supply chain against theft of controlled unclassified information (CUI). It mandates contractors get assessments to test their networks agains a five-tiered model, with the CMMC Accreditation Body being the group to manage the ecosystem of assessors, trainers and others who contractors will need to hire to get certified to continue working with DOD.
Edens’ work on the Standards Working Group focused on foundational issues to the program, including its definition of CUI, the type of sensitive information CMMC is designed to protect.
His resignation comes as the AB transition from being run by a group of volunteers like Edens to having full-time staff take care of the day-to-day operations of the group. The board recently hired a CEO and has on-boarded some full-time staff.
The accreditation program has faced a number of challenges since its rollout, including concerns from the defense industry that it may create an unduly onerous barrier for smaller contractors.
In testimony given to a House Committee on Small Business subcommittee last week, small enterprise leaders also raised concerns about how new requirements are being communicated to businesses.
The DOD has since said that it is addressing concerns over the cost of complying with the scheme for small businesses in an ongoing internal review, and that it will shortly launch a public media campaign to improve communication with industry about the scheme.
Poor coordination hampers HHS cyber threat info sharing with industry
The Department of Health and Human Services doesn’t routinely share cyber threat information with private sector partners because the two centers responsible haven’t formalized coordination, according to the Government Accountability Office.
GAO found the Healthcare Threat Operations Center, an interagency program providing actionable cyber data, didn’t regularly provide threat information to the Health Sector Cybersecurity Coordination Center (HC3) for sharing with industry.
Private sector partners want more actionable threat information from HC3 with cyberattacks on health care organizations on the rise, since the start of the U.S. COVID-19 response in March 2020, putting patient privacy and telehealth services at risk.
“Given the many players involved in cybersecurity management at the department and in supporting the cybersecurity of the [health care and public health] sector, deliberate and well-organized coordination and collaboration are essential to ensure that efforts are successful,” reads GAO’s report released Monday. “Safeguarding federal information systems and those systems supporting our nation’s critical infrastructure has been a longstanding GAO concern.”
HC3 alerts included mitigation strategies but not information from HTOC reports like the Internet Protocol address used by a malicious actor to facilitate an attempted cyberattack.
Neither the HTOC Concept of Operations nor the HC3 Strategic Plan include specific coordination responsibilities, and a senior HTOC official said it rarely shares “appropriate” information with HC3, according to GAO.
HHS‘s chief information security officer told GAO that HTOC and HC3 coordinate information sharing during daily situational awareness meetings, but those meetings are led by the Computer Security Incident Response Center and coordination wasn’t apparent, according to GAO.
GAO recommended HHS’s chief information officer coordinate information sharing between the two centers, but HHS disagreed with the recommendation arguing already “close coordination” takes into account agreements between private-sector partners and stakeholders.
“[D]ue to the high level of fidelity and sensitivity that surround federal intelligence data and the HTOC federal partner cybersecurity operational data, HTOC partners do not share information outside the partnership without the expressed permission and authorization of the originating agency,” wrote Rose Sullivan, acting assistant secretary for legislation at HHS, in the department’s response.
HTOC receives intelligence data from the Department of Homeland Security, open source data, HC3, and subscription-based intelligence sources.
GAO further found HTOC and six other HHS entities it reviewed only partially addressed three cyber collaboration practices: defining and tracking outcomes and accountability, clarifying roles and responsibilities, and documenting and regularly updating guidance and agreements.
GAO recommended HHS’s CIO report on the progress and performance of the HHS CISO Council, Continuous Monitoring and Risk Scoring Working Group, and Cloud Security Working Group, as well as regularly update collaboration agreements between them with approval.
GAO also recommended the Assistant Secretary for Preparedness and Response do the same for the Government Coordinating Council’s Cybersecurity Working Group and HHS Cybersecurity Working Group, as well as update the charter for the Joint Healthcare and Public Health Cybersecurity Working Group for the current fiscal year.
HHS agreed with those recommendations.
Cornelius leaves ADI to join staff of Sen. Gary Peters
Executive director at the Alliance for Digital Innovation, Matthew Cornelius, has left the trade body to take up an advisory role in congress.
He joins the majority staff for Homeland Security and Governmental Affairs Committee chairman Gary Peters, D-MI. Peters also serves on the Senate Commerce, Science, and Transportation Committee and the Senate Armed Services Committee.
Cornelius has led ADI since December 2019, and prior to this worked in several technology-focused roles in government before leading the trade group that focused on modernizing government IT.
His previous jobs included stints at GSA advising the administrator on cybersecurity, at the Office of Management and Budget and the Department of Treasury.
In his new job he will advise on the scrutiny of federal technology programs including the GSA’s Technology Transformation Services.
German government launches $12B fund to finance tech startups
The German government has launched a 10 billion euro ($12 billion) equity fund to support the launch of technology startups in the country.
The state-backed fund was first proposed in August 2020, and is intended to address concerns that entrepreneurs in the country have had to turn to foreign investors because of a lack of domestic venture capital.
In the U.S. government grants for startup businesses are available, yet a small percentage of entrepreneurs take advantage of the funding, which is in part due to the lack of knowledge of these government grants.
The two most prominent awards in the U.S. are The Small Business Innovation Research (SBIR) program and the Small Business Technology Transfer (STTR) Program. Both are designed to help startups engage in research and development, similar to the Future Fund.
Details of the scheme were revealed earlier this year in March. At the time, Germany’s Federal Minister of Finance, Olaf Scholz, said it was “critical” for the country to provide assistant to startups, and said the state had laid the foundation for boosting the VC market in in the country.
Federal Minister for Economic Affairs Peter Altmaier also said at the time that the government would work also with the private sector, and that in total it would raise at least EUR 30 billion ($35.7 billion) in VC support for startups.
“Combined with our existing financial instruments we will be able to provide over EUR 50 billion ($60 billion) in venture capital for startups in the next few years together with private investors.
“This is unique in Europe and is also a significant contribution by international comparison,” said the minister.
Bill to create federal rotational program for cyber experts passes to House floor
The Oversight Committee sent a bill that would create a federal rotational program for private-sector cybersecurity experts to the House floor Tuesday.
An identical version of the Federal Rotational Cyber Workforce Program Act is working its way through the Senate after being reintroduced there and in the House in April and May respectively.
If created, the rotational program would allow senior tech industry workers to ply their trade for the U.S. government for a set period before returning to their original or a similar role in the private sector.
Sens. Gary Peters, D-Mich., and John Hoeven, R-N.D., first proposed the legislation in 2019, but recent, high-profile cyberattacks like the SolarWinds hack have increased the urgency of lawmakers attempting to help agencies recruit and retain top cybersecurity talent.
“While we don’t agree on everything, the severity of the cyber threat has proven so immediate that both conservative Republicans and progressive Democrats came together to support our bill,” said Reps. Ro Khanna, D-Calif., and Nancy Mace, R-S.C., in a joint statement. “As we saw recently with the Colonial Pipeline attack, the cyber threat is real and ever present.”
Khanna and Mace reintroduced the bill in their chamber and thanked Rep. Carolyn Maloney, D-N.Y., who chairs the Oversight Committee, for moving the bill — which they expect House leadership to take up soon.
Agencies would be expected to select rotational positions with integrated cyber missions, with the Office of Personnel Management overseeing the program in coordination with the Chief Human Capital Officers Council, Chief Information Officers Council and Department of Homeland Security. The Government Accountability Office would study a pilot version of the program’s effectiveness, prior to it being scaled up.
Former DISA Director Norton joins professional services firm T-Rex
The former director of the Defense Information Systems Agency, Vice Adm. (Ret.) Nancy Norton, has joined professional services firm T-Rex Solutions.
She takes up a position on its national security board of advisors, which advises the company’s leadership on how to shape IT solutions to serve the Department of Defense and the Intelligence Community.
Norton previously served simultaneously as both the Director of DISA and a commander within the U.S. Cyber Command component responsible for securing and defending the DOD’s information network. Earlier in her career, she was the U.S. Navy’s director of warfare integration of information warfare, where she oversaw all Navy systems.
Prior to this, Norton served as the Director of Command, Control, Communications and Cyber for the U.S. Pacific Command.
T-Rex is focused on helping federal government agencies to modernize, protect and scale their systems and data. The company designed and implemented the active cyber defense solution that was used to secure the 2020 Census, which was the first such census to be conducted online.
Commenting on the appointment, Norton said: “I am looking forward to working with T-Rex and my National Security Board of Advisors colleagues to provide insights from my experience within DISA and the U.S. Navy.”
“T-Rex’s ability to launch and secure the technical integration of the United States Census is a capability we have to replicate and mature throughout the defense and intelligence communities,” she added.
Katie Arrington placed on leave amid probe into suspected disclosure of classified information
Katie Arrington has been placed on leave in connection with a suspected unauthorized disclosure of classified information from a military intelligence agency.
According to a memo seen by Bloomberg News, she was informed on May 11 that her security clearance for access to classified information had been suspended. A legal representative for Arrington confirmed the contents of the memo in an email to FedScoop.
The document said that her clearance had been suspended as “a result of a reported Unauthorized Disclosure of Classified Information and subsequent removal of access by the National Security Agency.” The document did not provide details about the possible disclosure of information.
Arrington is CISO for Acquisition and Sustainment at the Department of Defense, a role in which she is responsible for the application of supply chain risk management principles within the DOD’s procurement strategy. She was brought to the Pentagon in 2019 under the category of “highly qualified expert,” a hiring classification that allows the Department of Defense to bring in civilian experts with state-of-the-art knowledge in fields of critical importance.
She is a former one-term Republican state representative from South Carolina who ran an unsuccessful campaign for Congress in 2018. According to her Pentagon biography, she has more than 15 years of cyber experience “ through positions at Booz Allen Hamilton, Centuria Corporation, and Dispersive Networks.”
Late last week, this publication reported that former U.S. Air Force officer and long-time cybersecurity specialist John Garstka had taken up the role of acting CISO for acquisition and sustainment at the Department of Defense. Sources at the time told this publication that he had taken on the role from Arrington on an interim basis.
Mark Zaid, an attorney representing Arrington, said: “The suspension of Ms. Arrington is nothing more than a routine administrative action but she is now being victimized by delays that are unfairly causing harm to national security and her reputation.
“We are ready now to address any DoD concerns and she deserves timely due process which is being denied.”
A Department of Defense spokesperson said the department does not comment on personnel matters.
Department of Defense AI ethics principles still lack implementation guidance
The Department of Defense will produce guidance for its artificial intelligence ethical principles by late August, six months after an initial self-directed deadline for the creation of the guidance.
Officials had said by February 2021 the DOD would detail how the bureaucracy should implement its five AI principles, which state that the technology should be responsible, equitable, traceable, reliable and governable. But that date has come and gone without any such document detailing how the bureaucracy should translate the principles into their daily work.
The principles were adopted by the department in February 2020 and were designed as a starting point for the DOD’s approach to building and using AI ethically. The new deadline for a draft of implementation guidance was mandated by a May memo from Deputy Secretary Kathleen Hicks which reiterated the department’s commitment to building “responsible AI.”
Alka Patel, head of responsible AI at the Joint AI Center, told FedScoop in September that the guidance was to give DOD offices working on AI a “shared vocabulary” on how to understand and work with the principles. She said the guidance would be a critical part of turning the conceptual framework into rules to live by.
“We recognizing the urgency around this work,” Alka Patel said during a press conference Thursday. “We are making progress,” she and other officials added.
When the principles were first adopted, Lt. Gen. Jack Shanahan, the then-director of the Joint AI Center, said implementing them would be the hard part.
“Implementing the AI ethics principles will be hard work. The Department’s efforts over the next year will shape the DOD’s future with AI,” Shanahan said when the principles were adopted in February 2020.
But implementation goes beyond any one document, said Paul Scharre, vice president and director of studies at the Center for New American Security who focuses on autonomy and AI in warfare.
“The DOD runs on process,” he said. For something as novel and diverse as AI, “it looks like a more diffuse set of policies, procedures, offices, organizational knowledge.”
Patel also mentioned that diffuse set of knowledge in previous interviews, saying that AI ethics “is all part of our jobs.” She had said that the guidance will help with that as it will help build a shared vocabulary for AI ethics.
The latest memo from Hicks reaffirms the DOD’s commitment to responsible AI, signed by the deputy secretary of defense in May. The memo tasks the JAIC with leading work on developing policy on responsible AI through working groups and adds more high-level tenets to how the department will approach the making AI.
The JAIC is not the only group working on ethics. There is a responsible AI subcommittee of the DOD’s AI steering group which meets monthly and an international program for military-to-military collaboration on AI among 16 partner nations. There also has been progress in developing test and evaluation programs to assess the reliability of AI systems the DOD is working on.
The principles also have been included in contracts, with requests from the department seeking industry’s input on how they would use the principles in their work.
Scharre said that the DOD is not the only institution that is struggling with how to implement AI ethics. With such a new set of technologies, it requires new procedures to implement ethical frameworks, he said.
“It’s not like the best AI researchers in the world don’t have this problem to solve,” he said.