Rep. Hice calls on IGs to assess telework’s impact on agency performance
Rep. Jody Hice, R-Ga., has called on inspectors general to assess the impact of remote working on federal agencies’ missions and the performance of their employees.
In a statement Thursday, Hice said it was “clear” that the increase in the number of federal employees working from home had contributed to delays, inefficiencies, and declines in performance.
“I’m calling on inspectors general to investigate the overall impact telework had on our federal agencies during this pandemic and report back to Congress so we can accurately assess how to move forward before rushing into foolhardy reforms,” the lawmaker said.
The congressman has written to the inspectors general of 10 agencies, including the departments of Defense, Justice and Homeland Security, asking them to look into the impact of mass telework over the past 16 months. Hice is a ranking member on the Subcommittee on Government Operations, which is part of the House Committee on Oversight and Reform.
Agencies across the federal government have been given a July 19 deadline by which they must finalize plans to get staff back into the office, a process that is being overseen by the White House-backed Safer Federal Workforce Task Force.
However, according to new guidance issued as part of the return-to-office program earlier this month, agencies have been instructed to consider embracing a more virtual workforce.
A joint memorandum sent by the Office of Management and Budget, the Office of Personnel Management and the General Services Administration said that such a move should be taken “where possible and appropriate.”
Pentagon installs Garstka as acting CISO for acquisition and sustainment
Former U.S. Air Force officer and long-time cybersecurity specialist John Garstka has taken up the role of acting CISO for acquisition and sustainment at the Department of Defense, FedScoop has learned.
In the new post, Garstka will be responsible for leading the integration of security and cyber efforts within the Office of the Under Secretary of Defense and work to ensure security within the department’s technology supply chain. According to sources, he takes over the role on an interim basis from Katie Arrington.
Garstka is a Pentagon veteran, having worked in military research and development since 1984, including over a decade within the space division of the U.S. Air Force. Since 2012, he has held leadership roles within the Office of the CISO at the DOD, most recently as director of cyber programs. Between 2000 and 2002 he was CTO for the Joint Chiefs of Staff.
It is not immediately clear how much of a role Garstka will play in the management of the Cybersecurity Maturity Model Certification Program (CMMC). Recently-installed Deputy Assistant Secretary of Defense for Industrial Policy Jesse Salazar in May told Congress that he now has oversight of CMMC.
One of the core responsibilities of a CISO for acquisition and sustainment at the DOD is to ensure the digital security of weapons systems across the military.
Services have struggled with cybersecurity risks within the defense supply chain. In 2019, a landmark report by the Department of the Navy found that the service had failed to account for the fact that defense companies it contracts with would be aggressively targeted by foreign hackers for their valuable data.
The DOD, in response, has ramped up its implementation of measures such as the CMMC program.
In November last year, the Department of Defense appointed Dave McKeown, a long-time government IT and security official, as chief information security officer. He replaced former CISO Jack Wilmer, who departed in July to lead a private security company.
The DOD declined to comment.
Navy CDO Sasala says service has a ‘massive’ data duplication problem
The Navy will spend the rest of 2021 inventorying its data and solidifying management roles and responsibilities because making department-wide data policy is currently daunting, said Chief Data Officer Tom Sasala on Thursday.
Like other departments, the Navy is drawing on the Federal Data Strategy 2020 Action Plan and its Department of Defense Data Strategy Implementation Plan to focus its efforts. But the department didn’t meet the 2020 Action Plan’s six-month target for inventorying its data because of its size and scope, Sasala said.
Just how quickly the action will be completed is unclear because data quality and, more specifically, duplicate sets of low-quality data remain a problem for the Navy.
“We’re finding just massive, rampant data duplication,” Sasala said, during an AFFIRM event. “And so that’s actually hurting us much more than the quality itself.”
The data exists across multiple systems, and users have been allowed to “quote unquote innovate” with it without the Navy having a handle on its pedigree or provenance, he added.
Sasala said his priority is identifying “authoritative” datasets and where they come from while establishing who can use them and for what purposes.
Previously the Navy sought to establish authoritative systems, but not all data in a system is authoritative for the purpose the system was created. For instance, the Navy Enterprise Resource Planning financial management system serves as a general ledger for components, but not all users or even the department’s organizational structure.
At the same time, the Navy has created deputy data officer positions for the Navy and Marine Corps, which didn’t previously exist, and is working on establishing associate data officers for every command. Fortunately most commands already had associate data officers acting under different titles like “data analytics for the command” or “command data officer,” confusing because the acronym is CDO.
Sasala is in the process of appointing people to those roles and delegating statutory responsibilities from the OPEN Government Data Act to them, as well as creating a mechanism for holding them accountable for the work.
The Navy has also taken “great strides” injecting data and data professionals into its acquisition review process, known as Gate 6 reviews.
“Rather than allowing something to go into production that doesn’t have APIs and it doesn’t have data standards and is a closed ecosphere — that we can’t get access to the data and all this other stuff — we’ll have some say in some regard about whether or not we want to make that investment,” Sasala said.
What government CIOs need for AI to succeed
Kirke Everson is a principal in KPMG’s Federal Advisory practice, focusing on technology enablement, intelligent automation, program management, process improvement, cyber security, risk management, and financial management. He currently serves as the government lead for Intelligent automation for KPMG in the U.S.

Kirke Everson, Principal, Federal Advisory, KPMG
Federal and state government leaders are witnessing the expansion of artificial intelligence all around them. From back-office automation, that can help reduce backlogged work, to cognitive platforms, that can identify and respond to natural language requests to better serve the public, AI and automation have become a driving force in addressing mission and business objectives.
That’s clearly evident in speaking directly with federal and state government CIOs in multiple roundtable discussions over the past several weeks. Based on the use cases they described, it’s clear that agencies are making significant headway in putting AI to work.
At the same time, there are a variety of issues where government CIOs also need broader support. The issues they and their executive teams face, in many ways, are not that different from previous technology breakthroughs that tended to upend familiar work processes. The technology component — like the disruption of mobile and cloud technology — is only part of a larger equation involving processes, policy, culture, governance and ethics. That said, government is already seeing the value of AI, especially in light of unprecedented citizen demands for agency services during the pandemic.
CIOs in these roundtable discussions expressed a collective optimism and determination for how government can and must put AI to work. There was a broad consensus that they cannot delay integrating AI into their operations. “It’s not a question of when, but how we allow AI to come into our processes,” said one leader.
What’s critical now for agencies is to address these larger policy issues. At the same time, they also need to assess and select the right technologies for more advanced use cases; establish the means to scale AI solutions; and improve the quality of, and access to, clean and digestible data.
It’s getting to the “how” that CIOs are now wrestling with. Here’s a partial list of what many of them say their organizations still need from their leadership to ensure AI will live up to its promise:
Clearer use cases — We have already seen how AI is helping government agencies to analyze data, automate responses through robotic process automation and augment employee workloads. But agencies have all kinds of opportunities to build upon those successes to develop more advanced use cases, where more complex AI components can be applied to drive innovation and strategic decision making for better mission outcomes. Fortunately for government, AI’s application in commercial sectors — for detecting fraud, for example — are demonstrating tangible results and offer a helpful roadmap for what’s possible.
Greater data preparation — The ability to readily identify useful patterns in government data depends on having clean and reliable data to work with. Given the volume and velocity of data agencies generate, CIOs need modernized IT infrastructure, more robust data management applications and the resident skills to capitalize on them. Here is where automation and AI solutions can be part of the solution, to help access, consolidate, normalize and cleanse data.
Commitment to trustworthiness — This was one of the top concerns among CIOs in these discussions. It is vital that senior leadership establish and implement an ethical and responsible approach to AI, that adequate controls be put in place, and that agencies execute against an ethical AI framework. Without those safeguards, agencies run the risk of relying on untrustworthy or biased data or undermining the productivity gains AI promises.
Greater governance — Decisions need to be made on how agencies will manage the application of AI, which use cases to pursue and how to implement, scale, monitor and evaluate the impact of AI. CIOs can’t do that alone. Governance will also play a key role in building in proper checks and balances and guidance on how AI is ultimately put to work — and ensuring that AI initiatives conform with wider accepted practices.
Broader training — Artificial intelligence is more than the technology that creates it. It is a powerful set of outcomes that requires care, calibration and control — beginning with the data that goes into it and for the decisions that come out of it. Not unlike the fields of medicine or building design, AI will require specialized and continuous training at many levels across every organization endeavoring to integrate AI into its operations.
There’s no question, AI promises to be an incredible force-multiplier in helping government better serve the public. CIOs have a unique perspective and a critical role to play in all of these areas. But AI’s promise also hinges on agency leaders focusing on the mission or business, developing clear use cases, and then applying the technology, not the other way around.
Learn more about how KPMG can help your organization harness AI more effectively.
CMMC uncertainty threatens small contractors, business leaders warn
Small business owners warned members of Congress on Thursday that uncertainty over the costs and timeline of the Department of Defense’s Cybersecurity Maturity Model Certification (CMMC) program could push their enterprises out of the defense industrial base.
In testimony given to a House Committee on Small Business subcommittee, they also raised concerns over the department’s communication strategy for the scheme, saying it has allowed information to trickle out through social media, rather than contacting affected contractors directly.
“There is no consistent method or message from DOD,” said Michael Dunbar, a small business president who testified on behalf of HUBZone Contractors National Council. “A lot of small businesses have been ignored.”
CMMC will require third-party certification that contractors meet a five-tiered range of security controls. Critics say that the cost of meeting those standards could fall unfairly on small businesses because they have fewer resources to deploy on cybersecurity than large defense firms.
Dunbar said during the hearing that much of the communication around the implementation of the scheme had been conducted through LinkedIn and urged the DOD to formalize its communication with industry with official policy documents.
“It’s basically been kept to a very small group of people that are running all of this and then we get told later on what is happening,” he said.
In testimony, the CEO of professional services contractor T47, Tina Wilson, warned that uncertainty over costs and the implementation timeline for the regime had left many small businesses fearful of being shut out of the defense industry.
“The fear could be real,” she told lawmakers. T47 provides policy procedures and analysis services to agencies within the DOD.
Jonathan Williams, a partner at law firm PilieroMazza, warned that the DOD must clarify which of the five levels of CMMC contractors would qualify for. He noted also that one potential avenue for reducing the cost of certification to small businesses would be to ensure prime contractors are largely responsible for ensuring subcontractors adhere to cybersecurity requirements.
“If we can keep as many small businesses as possible at level one, that will strike the right balance,” Williams told the committee.
The attorney said also that the DOD must explain how it intends to meet a self-imposed 2026 deadline to make CMMC a requirement in all contracts.
In response to the concerns, subcommittee Chair Rep. Dan Meuser, R-Penn., called for the creation of a platform through which the DOD can hear concerns over the implementation of the scheme.
“I think we can conclude that these measures are overly harsh and we do need to create a forum to have this discussion with DOD,” he said.
The hearing on Thursday came after electronics manufacturer trade group IPC earlier this week published a study that found 24% of industry respondents anticipate being pushed out of the defense industry due to the costs and burdens of CMMC.
A separate report published by the Alliance for Digital Innovation on Tuesday also warned about the risks of implementing “expensive but emerging requirements that are not ‘fully baked’” in the federal acquisition space.
“A clear example is the rush to impose the emerging standards of the Department of Defense’s Cybersecurity Maturity Model Certification (CMMC) requirements into civilian agency procurements,” the study said.
Lawmakers push DOJ to investigate China Initiative after engineer’s mistrial
Democratic lawmakers urged the Department of Justice to investigate FBI misconduct under an initiative for prosecuting people stealing trade secrets, hacking or spying for China, in a letter published last week.
The note specifically asks DOJ Inspector General Michael Horowitz to look into the failed prosecution of Anming Hu, a former engineering professor at the University of Tennessee, who was fired after FBI agents told his employer he was suspected of stealing government secrets for the Chinese military.
Hu was the first person prosecuted under the Trump administration’s China Initiative, the methods of which are being questioned after a jury deadlocked in his trial June 16 — following testimony from the investigating FBI agent that he spent 21 months surveilling Hu but doesn’t believe he was ever a spy, reported the Knoxville News Sentinel.
“As members of the House Judiciary Committee, we are deeply troubled by the alleged misconduct of the [FBI] in the unsuccessful prosecution of University of Tennessee at Knoxville associate professor Anming Hu,” reads the letter. “The FBI allegedly falsely accused professor Hu of being a Chinese spy; falsely implicated professor Hu as an operative for the Chinese military; and used false information to put professor Hu on the federal no-fly list — among a number of other actions.”
Reps. Ted Lieu, Calif., Mondaire Jones, N.Y., and Pramila Jayapal, Wash., want Horowitz to determine if the China Initiative pressures personnel at DOJ, which includes the FBI, into racially and ethnically profiling people.
During his testimony, FBI Agent Kujtim Sadiku couldn’t recall who tipped him off Hu might be a spy and said he’d encouraged Hu to attend a symposium in China and report back on security concerns, reported the News Sentinel.
When Hu refused, FBI surveillance began, Hu’s bosses were informed and he was ultimately charged, not with espionage, but fraud for concealing his affiliation with Beijing University of Technology while receiving NASA funding — an accusation Hu denies.
Chinese universities are considered to be incorporated under Chinese law. As such, U.S. laws that prevent high-ranking federal employees from working for Chinese companies can also prevent them from working at Chinese universities.
The letter asks Horowitz to investigate whether false information was used against Hu and whether false accusations were made. It also calls for clarification over whether the Department of Justice was aware of concerns over false accusations, and whether racial or ethnic profiling occurred.
In the missive, lawmakers also seek to determine whether the decision to open an investigation was based on adequate facts and whether the China initiative pressures DOJ personnel into profiling people.
The Department of Justice did not respond to a request for comment.
Navy looks to onboard 472,000 users to new virtual environment by end of September
Now that the Department of Defense has transitioned away from its temporary virtual collaboration environment developed to support remote work during the pandemic, the Navy has launched its own more secure long-term solution and is working to onboard hundreds of thousands of sailors and Marines to the new platform.
Called Flank Speed, the new virtual collaboration environment is built around Microsoft Office 365 cloud software — much like the DOD’s now-retired Commercial Virtual Remote (CVR) environment launched in the early days of COVID-19 telework — but with added security, Mike Galbraith, Navy’s chief digital innovation officer, said Tuesday at VMware’s Public Sector Innovation Summit, produced by FedScoop.
The CVR environment, which was taken offline June 15, “was a godsend, but it wasn’t perfect. If it was perfect, we’d still be using it,” Galbraith said, explaining that CVR was only authorized for data transmission at the IL2 level for any information cleared for public release. The Department of the Navy‘s Navy-Marine Corps Intranet (NMCI) instance of Office 365 will also expire Oct. 1.
Flank Speed falls under the larger DOD365 cloud collaboration platform being rolled out across the department and is authorized up to IL5, accomodating controlled unclassified information that may deal with national security systems. The environment will offer access to Microsoft Teams, a terabyte of OneDrive cloud storage, and access to Microsoft 365’s Excel, Word, OneNote, and PowerPoint.
“It’s secured. It is cloud-based, like CVR. But in a very secure and defendable place where CVR had a couple of holes,” Galbraith said, later emphasizing the importance of “weaving that thread of security through everything — securing our data, securing our devices, securing our networks and our transport.”
He also called Flank Speed a “catalyst for our zero-trust architecture, which is built into that network and transport model that we have designed.”
Galbraith said it’s called Flank Speed — based on the Navy term for a ship’s maximum speed and given as an order to escape danger — because “we are moving very quickly” to give some 472,000 users access to the platform before the close of fiscal 2021.
The Navy began transitioning users to the new environment June 1, selecting an initial set of “260,000 current users of CVR and NMCI O365” who have begun moving over first, according to a release. As network performance gets better over time, more users will be gradually added.
Moving to CVR last year was “bumpy,” Galbraith said, and moving to Flank Speed will be no different.
“There’s some cultural change that’s going on,” he said. “So very similar to CVR where it was bumpy to begin with, our Flank Speed implementation in the Department of Navy, it’s going to be a little bumpy as well as we migrate users in a phased way, as we migrate and bring technical capabilities into that environment a piece at a time. And it’s happening very quickly, with every day new capabilities being added by the team.”
Robin Carnahan confirmed to lead GSA
Robin Carnahan, was confirmed by the Senate as Administrator of the General Services Administration Wednesday afternoon.
She was confirmed by voice vote, meaning there was not a final tally of yeas or nays on her nomination.
Carnahan founded and led the state and local government practice at 18F, GSA‘s tech consultancy, from 2016 to 2020, having previously been Missouri’s secretary of state. She also co-founded the State Software Collaborative as a fellow at Georgetown University’s Beeck Center.
When she was at GSA during the Obama administration, Carnahan helped state and local governments improve their digital services while cutting costs. Her practice taught non-technical officials about IT risk management, procurement and modernization projects.
As Missouri’s secretary of state Carnahan modernized online services for hundreds of thousands of customers related to both elections and securities. A Democrat, she also ran for one of Missouri’s Senate seats in 2010 but lost to Republican Roy Blunt.
Commenting on her appointment, Carnahan said: “I am grateful for the support of the Senate, and I am honored to serve as the next Administrator of GSA.
“GSA is at the heart of creating a government that effectively delivers for the people and taxpayers, and I am committed to doing all I can to support that important mission.”
Dynamic information sharing depends on deploying the right automation
Rob Smallwood is vice president for digital modernization and enterprise IT at General Dynamics Information Technology.

Rob Smallwood, VP, Digital Modernization and Enterprise IT, GDIT
It’s hard to argue against the urgent need for modernizing federal IT systems. What’s often lost in the discussion, however, are the practical considerations of modernizing, given the sheer complexity inherent in managing so many legacy applications across today’s on-premises and cloud environments.
Add to that having to maintain the government’s stringent security requirements; the need to work within multiple security domains; and the challenges of ensuring that data can be accessed safely and at scale anywhere in the world.
That’s why it’s essential for agencies to take a closer look at the power of integrating and automating a combination of state-of-the-art technologies, to handle the astronomical cross-domain workloads that our nation depends on now and in the future. Automating classified cross-domain IT on common infrastructures, for example, would better enable the U.S. to collaborate across security domains, and with our foreign mission partners at previously unrealized scale and efficiency.
That said, the actual work of implementing automation across today’s patch-worked IT systems remains anything but automatic — especially in government and defense circles.
The reasons are as varied as they are familiar. Government policies, acquisition regulations and security demands — on top of an endless sprawl of siloed systems — have buried government IT engineering and maintenance teams under layers upon layers of complexity. As a result, implementing IT automation effectively and securely remains immensely complicated, requiring enormous technical skill and experience to integrate solutions across a wide range of commercial and customized platforms.
Those challenges are increasing as on-premises and cloud-based systems not only become more interconnected, but also more dynamically driven.
Take the Department of Defense, for example, which has committed to establishing a Joint All-Domain Command and Control (JADC2) platform, aimed at gathering and analyzing data from across all domains (sea, air, land, cyber and space) and distributing that information back to those who need it, where and when they need it.
One of the distinct challenges in that endeavor revolves around automating IT services capable of sharing information with our coalition and mission partners. Dynamically provisioning secure and classified IT capabilities across so many security boundaries — and ensuring those capabilities are executed reliably at the “speed of need” — requires mapping out a vast array of digital checkpoints before automating.
Compounding matters are government acquisition rules that historically slow down modernization efforts to a pace some some would describe as the “speed of the policy.” As a consequence, it remains difficult for agencies and their contractors to take advantage of emerging technologies — and the tools to integrate them. The reality is, the rigidity of contract regulations tend to leave little room to anticipate new technology developments coming onto the market, or an avenue to fold them into an existing program.
A better approach
So how can we set up better scenarios so that more and more IT workloads and provisions can be automated within the confines of a single contract?
One way is to transfer the risk of responsibility and the implementation of modernized IT capabilities more fully onto the backs of qualified contractors, using outcome-focused managed IT services model with fixed-priced contracts, much like today’s cloud computing models.
That helps agencies avoid the inevitable traps of cost-plus contracts, which, because of their long runways, routinely lead to technology build-outs that are already out of date by the time they’re turned on— and tend to cost more than expected. Properly structured contracts effectively alleviate the need for agencies to commit to technologies that inevitably become outmoded.
Transferring the burden of risk and liability to experienced contractors it not only incentivizes contractors to innovate more rapidly; it also facilitates automating IT services — and the benefits that automation brings — more quickly.
Those benefits can be immense. Secure automation helps to provision, operate, and sustain critical IT services automatically and dynamically. That in turn speeds up the ability to process, store, analyze and share information that drive and support enterprise missions.
Given the sprawling complexity of government IT systems, the security and regulatory rules that govern them, and the risks inherent in modernizing them, it makes increasing economic sense to partner with contractors deeply familiar with those rules and risks. But agencies should also look for partners with proven experience in assessing the larger, enterprise-wide operating picture across all silos and seams.
That means, for instance, choosing contractors capable of grasping the most complicated operational scenario that an agency might face, and then solve backwards from there. As importantly, you want partners who know how to transition legacy infrastructures and have the ability to field new capabilities and services at the same time.
One of the most extreme scenarios GDIT has tackled, for instance, is how to automate managed services for sharing information of different military classification levels with coalition partners. The task involved not only automating the nation’s most stringent security requirements, but also doing so across some of the most diverse IT environments that exist around the world.
Agencies also need to consider contractors familiar with delivering services on a global scale — while also adapting them to specialized environments. GDIT, for instance, has delivered large swaths of enterprise IT services on defense programs, ranging from the U.S. Battlefield Information Collection and Exploitation System Extended (US BICES-X) to milCloud 2.0, which connects competitively priced, highly secure cloud service offerings to DoD networks. MilCloud 2.0 provides turnkey, high-performance cloud solutions that enable DoD agencies and partners to manage big workloads across different security classifications in ways that commercial providers can’t match.
President Biden recently stated, “America’s alliances are our greatest asset.” Our ability to connect to them in cyberspace continues to be critical to that alliance. Connecting these governments together in a more automated fashion will remains an ongoing and essential task. Choosing an experienced partner who knows what that looks like, and has the necessary talent and skills, is a key step to getting to the speed of need.
Learn more how GDIT is helping defense and civilian agencies capitalize on the power of IT automation.
Hyten signs new requirements to ensure military services make data accessible
Gen. John Hyten, the vice chair of the joint chiefs of staff and head of the Joint Requirements Oversight Council, has signed four new strategic directives that mandate all U.S. military services to make data accessible for all their weapons and platforms.
The new directives are based off recent “Data Decrees” signed by the Deputy Secretary Kathleen Hicks in May, which give specific advice on data management and call on senior leaders to use the DOD’s Advana platform as a central repository for data analysis that is used to support decision making.
The latest requirements are intended to support the development artificial intelligence systems within the DOD, which require access to vast datasets in order to learn new capabilities. In the private sector, tech giants such as Amazon, Apple and Microsoft have long relied on access to such pools of data for the development of AI-supported search functions such as Alexa and Siri.
“Thee simple requirement will be from this day forward all data form the Department of Defense … will be accessible. period. It has to be that way, there can be no other alternative,” Hyten said.
“Services will have to build their systems to meet that requirement,” he added.
Hyten said that without interoperable and accessible data, further dreams like implementing artificial intelligence can’t become a reality.
Hyten also urged the department to adopt enterprise cloud computing capabilities. Not mentioning the stalled Joint Enterprise Defense Infrastructure (JEDI) by name, Hyten said that without a “real cloud” the DOD won’t be able to use and store all of the newly interoperable and accessible data.
Once the DOD has large, accessible data sets and the cloud capabilities to turn that data in to intelligence, networking together operations across the domains of air, land, sea, space and cyberspace operations will be the new means the DOD thinks about deterrence.
“That will create a deterrent that is nearly as powerful as our nuclear deterrent,” Hyten, who used to lead Strategic Command which controls the U.S. nuclear arsenal, said.