DIU approves cloud management tools from Google, Zscaler and McAfee
The Defense Innovation Unit on Thursday said it has cleared new secure cloud management tools from three non-traditional defense companies that will facilitate video teleconferencing and cloud file sharing.
DIU is running its pilot with Google Cloud, Zscaler and McAfee Public Sector, all of which received “success memos” following a year of initial testing. The memos allow any DOD organization to use the SCM prototypes. Eventually, one company will be selected for a larger, long-term contract, likely by September, DIU said.
“These solutions simplify engagement with non-traditional technology vendors by allowing DIU users to collaborate in real time. The solutions provide equivalent security and control to the DoD’s Cloud Access Point (CAP) while delivering real-time performance, which is critical for such things as videoconferencing and file sharing,” John Chen, interim CIO for DIU, said in a release.
The Department of Defense currently has an acute need for cloud management tools for use in projects including its Joint All-Domain Command and Control (JADC2) program.
According to the DIU, technology from the three companies embraces zero trust principles, in line with the May 2021 Executive Order that is focused on improving the nation’s cybersecurity and DOD’s recent Zero Trust Reference Architecture. DIU hopes the way it prototyped the new tech can serve as a guide for other organizations throughout the department looking to implement zero trust principle.
“We have seen widespread interest in our SCM effort from Services and DOD agencies that are looking for solutions to similar challenges,” said Rick Simon, contractor and DIU project lead. “These successful prototypes will give services and agencies several independently-assessed choices, especially as they implement zero trust architectures.”
Lawmakers push back on VA’s plan to use ‘opaque’ fund for IT modernization
Lawmakers aren’t very bullish about the Department of Veterans Affairs’ new plan to repurpose funds from other accounts to fund its IT modernization projects, they said in a hearing Thursday.
Some members of the House Veterans’ Affairs Technology Modernization Subcommittee equated the VA’s recent request to take $670 million from its Transformational Fund (TF) account to supplement its $4.8 billion proposed budget for IT in fiscal 2022 to taking from an “opaque, uncertain slush fund.” Doing so puts VA’s overall proposed IT budget for next year at roughly $5.5 billion, compared to the $4.9 billion VA received in fiscal 2021.
“I need a lot more information about the Transformational Fund to be convinced it will be a reliable productive funding source,” subcommittee Ranking Member Rep. Matt Rosendale, R-Mont., said during the hearing.
The Transformational Fund consists of past discretionary funds that went unused in prior appropriations cycles. Fiscal 2022 will be the first year that the VA can use money deposited in the fund, as the leftover appropriations need to sit untouched for five years before tapping into them. But there are limitations on what the VA can use them for, namely the improvement of health care facility infrastructure and “IT systems improvements and sustainment,” per the law.
Though Congress granted the VA the authority to start the fund five years ago under the Consolidated Appropriations Act of 2016, lawmakers now worry it is creating a harmful incentive for the agency to underspend what it’s been budgeted so it can later use those funds freely for IT or infrastructure — thought it’s completely within the law to do so.
“What is very concerning to me is that these funds that were dedicated or earmarked to be utilized for the delivery of health care purposes and now are being diverted out … and they go into a fund that gives you dramatic latitude on where it could be spent,” Rosendale said.
VA acting CIO Dominic Cussatt tried to assuage members by saying department leaders “manage the demand very carefully.” Department CFO Jon Rychalski said the funding often comes from contracts that finish under budget or services the VA budgeted for but did not end up needing.
“A lot of it has to do with [contracts] that just didn’t cost as much as we thought it was going to,” Rychalski said.
He defended the concept of the fund by saying “it was, in my estimation, a smart move [and] very much appreciated.”
Ultimately, though, to establish checks and balances, Congress has the power of the purse and oversight over executive branch spending. And Rosendale and subcommittee Chair Rep. Frank Mrvan, D-Ind., shared concern for the lack of oversight Congress could have on how the VA spends money in the Transformational Fund.
“I am concerned that modernization of IT assets and the critical upgrade of VA’s financial system are not included in the base budget request,” but instead in the Transformational Fund, Mrvan said.
Mrvan also voiced concerns about the management of the VA’s new electronic health record modernization funding. Part of the program is funded through the Veterans Health Administration’s budget and another by the department’s Office of Information Technology budget — a split that the subcommittee chair said could lead to a lack of oversight.
“In our accounting system, we are keeping track of all of them,” Rychalski said of the accounts associated with the EHR program, which has a projected cost of $16 billion over its scheduled 10-year lifespan.
Tech contractors urge NIH to answer their questions about $50B CIO-SP4 contract
The Professional Services Council has urged the National Institutes of Health to explain its treatment of tech industry questions about the request for proposals (RFP) issued for a long-awaited, $50 billion health IT contract.
In a letter of complaint sent Monday, PSC queried the agency’s decision to modify and consolidate industry questions before responding to them in RFP amendments. The advocacy group described NIH’s response as inequitable and confusing.
The recently-launched Chief Information Officer-Solutions and Partners 4 (CIO-SP4) contract, which has a higher funding ceiling than the prior CIO-SP3 contract vehicle, is managed by NIH.
NITAAC already had to re-compete the best-in-class, governmentwide acquisition contract, introduced back in March 2020 so NIH institutes and centers, the Department of Health and Human Services, and other agencies could purchase IT for biomedical research, software development, cloud services and cybersecurity. Now its new RFP and subsequent amendments are creating “more anxiety and concern” for contractors as they attempt to form teams to make bids on CIO-SP4, according to PSC.
“Unfortunately, there were many surprises in the final RFP released on May 25,” PSC said in the letter. “In the month since that release, amendments containing imprecise and at times inconsistent language have only contributed to further confusion among interested offerers, forcing them either to consider alternative strategies within the severely compressed timeframe for response or to abandon their pursuit of the CIO-SP4 opportunity altogether.”
PSC requested NITAAC list all of industry’s original questions concerning bid evaluation and submission requirements with its answers.
The advocacy group further asked that NITAAC extend the RFP response deadline to July 30, 2021, at the earliest and set its window for contractor past performance information and project descriptions to 36 months prior to the RFP’s release, rather than yet another due date — a moving target creating more work for contractors.
NITAAC’s third amendment issued June 22 only extended the response deadline 10 days to July 8, and the fourth amendment issued June 24 didn’t come with any extension. The July 8 deadline is “inadequate” for many potential offerers because NITAAC updated its past performance questionnaire, and it could take contractors up to 30 days to get approval from other agencies to share the required information, according to PSC.
NITAAC also removed a ban on using first-tier contractor past performance, which could affect teaming and joint venture arrangements that take time to negotiate and finalize.
PSC expressed additional concerns about the ISO 20000 “Go/No-Go” requirement and the lack of an attachment or certification document supporting it, as well as requiring development of up to 39 separate project descriptions — which other agencies will likely need to approve. Contractors also worried about the lack of guidance on required documentation for corporate experience.
NIH didn’t respond to a request for comment on PSC’s letter and a new extension by publication time, but the advocacy group is prepared for a drawn-out process.
“[A]ny additional explanations, clarifications, or corrections that NITAAC sees fit to provide in response to this letter and any other similar letters would seem to require future amendments,” PSC said. “That process, too, will take time, if it is to lead to a successful acquisition outcome.”
NSA not sharing information on controversial surveillance system, whistleblower alleges
The National Security Agency never provided its historical legal analyses of its XKeyscore surveillance system, according to a member of the independent oversight board that has been investigating it for the last five years.
Though the Privacy and Civil Liberties Oversight Board asked the NSA for all its prior legal analyses showing XKeyscore system’s data analytics comply with federal law, all it’s received is a 13-page memo from general counsel in 2016.
At more than a decade old, XKeyscore — first flagged by former NSA contractor Edward Snowden in 2013 — is used to search massive internet traffic databases to find and analyze a target’s communications. But the unavoidable, incidental collection of citizens’ personal information raises legal concerns the NSA never proved to PCLOB it considered before launching the system, Travis LeBlanc, a Democratic member of the board appointed by former President Trump, said in an unclassified statement released Tuesday.
“At a general level and on the basis of the documents that have been provided to the board, it is concerning that any surveillance tool would have been conceptualized, coded, implemented, and then executed and routinely used without such a prior written legal analysis,” LeBlanc wrote.
Of PCLOB’s five members, only LeBlanc voted against the release of what he called a “rushed” report on XKeyscore to Congress, the White House and the Office of the Director of National Intelligence in March.
The NSA told PCLOB its 2016 memo was based on legal analyses of XKeyscore conducted prior to the system’s launch — analyses general counsel did not or could not provide. The agency didn’t respond to a request for comment on the number of legal analyses completed or their withholding them from the board, by publication time.
LeBlanc further criticized NSA general counsel for basing its memo on dated case law and failing to update its legal analysis since 2016, despite the agency’s surveillance capabilities continuing to outpace electronic surveillance law.
Commenting on the matter, an NSA spokesperson told FedScoop: “The representation that NSA had not conducted a full legal analysis prior to the Board asking for legal materials in 2014 is not accurate. NSA conducted appropriate legal reviews of NSA’s use of XKEYSCORE. NSA’s Office of General Counsel regularly reviews NSA intelligence programs and capabilities to ensure compliance with the Constitution, laws, and other applicable regulations and policies.”
The NSA did address LeBlanc’s complaint that its analysts weren’t trained to use XKeyscore, or required to, by adopting that recommendation.
NSA’s alleged failure to prove it conducted prior legal analysis wasn’t the only reason LeBlanc took issue with PCLOB releasing a report, which he said “reads more like a book report summary of the XKeyscore program.”
PCLOB didn’t conduct a cost-benefit analysis of the system that accounted for how many people have been impacted, how much data has been collected and analyzed, how that data is shared, how many lives have been saved, or how many terrorist attacks have been stopped, LeBlanc said.
The board also didn’t follow up on reported compliance incidents, a redacted number of which were deemed “questionable intelligence activities” — intelligence community-speak for illegal surveillance or review of a citizen’s communications.
PCLOB didn’t include in its report a recommendation of LeBlanc’s that incidentally intercepted communications be tagged “personal information” in the system.
The board “failed the public” by not seeking to declassify its findings, he said.
LeBlanc also wanted PCLOB to weigh in on the technological and modern electronic surveillance issues XKeyscore raises, given its use of machine learning, autonomous collection of massive datasets and algorithmic analysis of them.
“Whether the public wants it or not, these systems are almost certainly here to stay,” LeBlanc said.
Oracle petitions Supreme Court over $10B JEDI protest
Oracle has filed a new brief with the Supreme Court, calling on it to hear the latest argument in its years-long legal battle against the Joint Enterprise Defense Infrastructure (JEDI) cloud contract.
The tech company hopes to overturn the initial ruling of the U.S. Court of Federal Claims, which identified issues with the $10 billion cloud contract’s award structure but said that potential conflicts of interest had not affected Oracle’s chances or cost it the deal. Oracle then brought its case to a federal appeals court, which also quashed its appeal.
The new brief comes after Amazon earlier this month filed its own arguments in this case as a co-defendant, calling on the Supreme Court to avoid making a decision over the contract because it contained disputes over matters of fact rather than disputes over points of law.
According to Oracle’s lawyers, the appeals court in its prior judgment failed to consider the fact that a criminal conflict of interest “alone” renders a federal contract unenforceable.
“Both of those two errors are mistakes of law, not fact,” Oracle said in its submission to the court.
The cloud computing company argues that the U.S. Court of Appeals made a serious error when it rebuffed an early appeal and kept the contract award intact.
JEDI is a key component of the Department of Defense’s larger enterprise cloud strategy. The contract was first put up for bid in 2018 before DOD awarded it to Microsoft in late 2019, but since then, it’s been largely dormant due to a separate legal protest led by Amazon.
But even before that award, Oracle has been waging an ongoing legal battle. It started in August 2018 with a pre-award bid protest filed to the Government Accountability Office, claiming that the sole-source structure of the award is not justified and arguing in court documents that links between DOD employees and Amazon Web Services had hurt its chances at competing for the contract. After GAO denied the protest, Oracle took its case to the Court of Federal Claims, then the U.S. Court of Appeals, and now its reached the nation’s highest court.
Meanwhile, the DOD has been reassessing what it might do if JEDI is held up much longer in the courts. Earlier this month, Deputy Secretary of Defense Kathleen Hicks said DOD could take a new direction on the contract by next month, and that it was “actively looking at [its] options.”
Previously, a Court of Federal Claims judge granted AWS’s requested timeline for hearings in its separate litigation. The web hosting giant continues to seek the disclosure of additional internal communications from the Department of Defense, including emails and Slack messages.
This followed a decision in April by the same court to stop the government from dismissing AWS’s allegations of political interference, elongating the timeline for a decision in that case. AWS has protested the DOD’s decision to award the deal to Microsoft, alleging that the procurement was influenced by former President Donald Trump, who has publicly criticized Amazon founder and Washington Post owner Jeff Bezos.
AWS and Oracle did not respond to a request for comment.
Better government CX requires leadership plus IT modernization
Juliana Vida, a retired U.S. Naval commander and former deputy CIO at the Pentagon, is Group Vice President and Chief Strategy Advisor for public sector at Splunk.
The nation’s sudden accelerated dependence on government services over the past year cast a huge spotlight on agency IT systems performance. As we all know, some systems held up remarkably well under the strain and others did not.

Juliana Vida, Group Vice President and Chief Strategy Advisor, Public Sector, Splunk.
From the public’s point of view, and over a longer-term perspective, the federal government’s customer experience “remains weak and uneven compared with the private sector,” according to Forrester’s 2020 U.S. Federal Customer Experience Index. The report found that the federal average CX score of 15 key agencies and programs trailed nearly 11 points behind the private sector average and was “lower than any other industry or sector” we studied.
More starkly, “Only 38% of federal customers who used digital-only channels considered the experience emotionally positive,” the report states. While some agencies — notably the National Park Services — scored better than others among some 98,000 adults who interacted with 250 brands measured in the index, overall, federal agencies in aggregate are getting lapped by more user-friendly private sector services.
It doesn’t have to be this way.
True, federal agencies must contend with more rigorous regulatory constraints than their commercial counterparts. Living within unpredictable, single-year budget cycles and abiding by strict consumer data-gathering rules, among other factors, make it hard for most agencies to step on the gas when it comes to improving citizen CX.
Clearly one of the barriers that can, and must, be overcome is the notion that the user experience is “good enough” for government. While officials in the last administration made strides to improve the customer experience and service delivery for federal customers, more needs to be done so those efforts do not continue to languish until agencies and the administration as a whole more fully commit to addressing the concurrent need to modernize federal IT systems.
It’s not that the federal government isn’t investing mightily in its IT systems. Investment remains robust though woefully misplaced. As much as 80% of those IT and cybersecurity funds are funneled into sustaining legacy technology instead of investing in modernized, cloud-based technologies that can deliver continuously updated IT infrastructure and applications – technologies that are both less expensive and more secure.
There are many opportunities for agencies to fast track their CX efforts, by leveraging their data, even as they ramp up their modernization efforts.
It’s relatively easy now, for example, to use a data platform to mine the types of words that customers use when they’re engaging online or contacting an agency by phone or email and determine what they’re looking for, or whether they had a good or bad experience. That intelligence can easily fold into customer service platforms, to deliver more data-driven, real-time insights and improve service delivery over time.
There are also a variety of IT automation and system orchestration tools to speed up backend processes, reduce repetitive administrative tasks and ultimately help employees focus on more valuable ways to support the customer experience. Those same tools can also help agencies identify what internal applications and systems people are really using or not using. If people are using what you’re putting in their hands, that’s a measure of success; and if they’re not, that can tell you where to reallocate your investments.
In the end, though, good customer experience requires a champion with top leadership’s support.
One example that has really impressed me is the work unfolding at the U.S. Air Force under its new Chief Experience Officer, Colt Whittall. He is the first appointee from any military service in this role across the Department of Defense, arguably the world’s largest and most complex organization.
Speaking at a recent federal CX panel discussion, Whittall described, for instance, his approach to measuring IT user satisfaction, beginning with an Air Force IT Pulse survey. The survey asks IT users across the Air Force a few simple questions and uses national language processing to help analyze the results.
He’s also rolling out a monitoring platform that captures system response time and availability data for all of the Air Force’s key applications — in real time and which tracks performance over time. That analysis will help gauge the impact of system upgrades and IT support services as they are deployed across the entire Air Force.
The decision to support remote users during the pandemic — by rolling out hundreds of thousands of VPN connections and cloud-based applications — had a dramatic effect on user satisfaction, with telecommuters registering twice the level of user satisfaction compared to those working primarily on base, he said.
Whittall’s approach to enhance customer experience is pragmatic: “Partnering with commercial technology is the only way to go, because it’s the only kind of capability that’s going to deliver the agility and the speed, and the scalability that’s required to keep us moving forward,” he said in the panel discussion. “Nobody wants to go backwards,” now that they used to a better experience.
The U.S. Air Force’s example illustrates the art of the possible in government. It also highlights how modernization and user experience go hand in hand — and how that in turn, can translate into greater productivity, faster decision making and most importantly, more effective delivery of mission-related services.
Learn more on how Splunk is helping federal agencies modernize for the future.
VA’s McDonough reaffirms commitment to Cerner records management platform
The Department of Veterans Affairs will stick with the existing records management platform that forms the center of its electronic health records (EHR) strategy following a review of its modernization program.
The agency in March launched a 12-week review into the $16 billion program, following the identification of failures including by the Government Accountability Office, which in February recommended that the VA stop work on the program to updates its health IT and scheduling system.
Speaking Wednesday at a press conference, VA secretary Denis McDonough said the department was committed to the Cerner Millennium records management platform, which is provided by health care technology company Cerner. The secretary said it will likely take two further weeks to determine additional changes to the program that will be made following the review,
Cerner is building a cloud-based system for VA that the department says will eventually be interoperable with the DOD’s Military Health System (MHS).
“That’s the coin of the realm,” said McDonough, commenting on the interoperability of the new system.
The next sites to get the system will be a network of hospitals in Columbus, Ohio.
Prior inspector general reports have warned that the VA’s legacy systems and infrastructure may not be able to handle the load of the cloud system and new health IT interfaces.
Langevin takes DOD CIO Sherman to task for ‘unacceptable’ budget justification
The Pentagon wants more than $50 billion for IT and cybersecurity in fiscal 2022, but so far, it hasn’t given Congress a thorough enough justification for that money, according to a top cyber-focused lawmaker.
Rep. Jim Langevin, D-R.I., expressed disappointment Tuesday for the Department of Defense’s lack of specifics in its IT budget request summary for fiscal 2022 — which includes $5.5 billion for cybersecurity and much more for enterprise IT other “cyberspace activities” on top of that. The document gives top-level budget figures for the past and present, but few other programmatic details are shared.
Langevin rebuked acting DOD CIO John Sherman because much of the budget documentation for 2022 is “nearly a carbon copy” from the previous year, equating it to plagiarism. Because of this, DOD’s IT and cyber budget summary document shrank from 30 pages last year to six for fiscal 2022 — “only two of which contain any substance,” the congressman said.
“With all due respect if your office cannot be troubled to put together the necessary materials for this committee’s oversight, how can we trust the stewardship of this critical portfolio?” Langevin, chair of the House Armed Services Cyber, Innovative Technologies, and Information Systems Subcommittee.
He continued: “Without that level of detail, you need to understand, we can’t fulfill our oversight responsibilities; we’re in the dark otherwise,” Langevin said. “That’s unacceptable going forward.”
On top of this, Langevin criticized the department’s seeming lack of understanding of how to define and categorize total cybersecurity spending across its enterprise. For instance, the Navy and Air Force count end-point security differently toward their cybersecurity budgets, he pointed out. That lack of standardization in categorizing IT spending makes putting a top-line number on the DOD’s cybersecurity budget difficult, he said.
“I will own this…we need to do a better job,” Sherman said of the evidence his office presented Congress while pointing to new requirements to restrict some of the materials in the document as controlled unclassified information as part of the reason it shrank.
In addition to agreeing that his office needed to provide Congress more information, Sherman also admitted the issue with how DOD defines and categorizes IT spending — a problem the department perennially has across its budgeting activities. “$5.5 billion for cyber doesn’t indeed represent the totality of cybersecurity for the department,” he said.
Redundancies in the terminology DOD uses for cybersecurity could also create gaps in authorities of that spend, Langevin said, pointing out that DOD uses the terms “operational technology” or “industrial control systems” for the same protection of industrial systems, like air conditioning and elevators.
Langevin has long been a vocal proponent of funding cybersecurity and IT modernization. His subcommittee marks up the section of the defense appropriations bill that grants DOD its IT and cyber funding.
During his testimony, Sherman gave little else away on other hot-button issues, like the Joint Enterprise Defense Infrastructure (JEDI) cloud procurement. He reiterated comments made by Deputy Secretary of Defense Kathleen Hicks that the DOD is in the process of figuring out what it will do next to develop an enterprise cloud solution.
CMMC Accreditation Body board member Edens resigns
A founding member of the accreditation body implementing the Department of Defense‘s new contractor cybersecurity standards resigned Tuesday.
Regan Edens had served on the board of the Cybersecurity Maturity Model Certification Accreditation Body (CMMC-AB) since it was incorporated in January 2020 and led the Standards Working Group, the volunteer entity responsible for establishing CMMC programmatic definitions.
Edens declined to comment. The CMMC-AB confirmed Edens’ resignation in an email to FedScoop.
CMMC is the new program to increase the security of DOD’s supply chain against theft of controlled unclassified information (CUI). It mandates contractors get assessments to test their networks agains a five-tiered model, with the CMMC Accreditation Body being the group to manage the ecosystem of assessors, trainers and others who contractors will need to hire to get certified to continue working with DOD.
Edens’ work on the Standards Working Group focused on foundational issues to the program, including its definition of CUI, the type of sensitive information CMMC is designed to protect.
His resignation comes as the AB transition from being run by a group of volunteers like Edens to having full-time staff take care of the day-to-day operations of the group. The board recently hired a CEO and has on-boarded some full-time staff.
The accreditation program has faced a number of challenges since its rollout, including concerns from the defense industry that it may create an unduly onerous barrier for smaller contractors.
In testimony given to a House Committee on Small Business subcommittee last week, small enterprise leaders also raised concerns about how new requirements are being communicated to businesses.
The DOD has since said that it is addressing concerns over the cost of complying with the scheme for small businesses in an ongoing internal review, and that it will shortly launch a public media campaign to improve communication with industry about the scheme.
Poor coordination hampers HHS cyber threat info sharing with industry
The Department of Health and Human Services doesn’t routinely share cyber threat information with private sector partners because the two centers responsible haven’t formalized coordination, according to the Government Accountability Office.
GAO found the Healthcare Threat Operations Center, an interagency program providing actionable cyber data, didn’t regularly provide threat information to the Health Sector Cybersecurity Coordination Center (HC3) for sharing with industry.
Private sector partners want more actionable threat information from HC3 with cyberattacks on health care organizations on the rise, since the start of the U.S. COVID-19 response in March 2020, putting patient privacy and telehealth services at risk.
“Given the many players involved in cybersecurity management at the department and in supporting the cybersecurity of the [health care and public health] sector, deliberate and well-organized coordination and collaboration are essential to ensure that efforts are successful,” reads GAO’s report released Monday. “Safeguarding federal information systems and those systems supporting our nation’s critical infrastructure has been a longstanding GAO concern.”
HC3 alerts included mitigation strategies but not information from HTOC reports like the Internet Protocol address used by a malicious actor to facilitate an attempted cyberattack.
Neither the HTOC Concept of Operations nor the HC3 Strategic Plan include specific coordination responsibilities, and a senior HTOC official said it rarely shares “appropriate” information with HC3, according to GAO.
HHS‘s chief information security officer told GAO that HTOC and HC3 coordinate information sharing during daily situational awareness meetings, but those meetings are led by the Computer Security Incident Response Center and coordination wasn’t apparent, according to GAO.
GAO recommended HHS’s chief information officer coordinate information sharing between the two centers, but HHS disagreed with the recommendation arguing already “close coordination” takes into account agreements between private-sector partners and stakeholders.
“[D]ue to the high level of fidelity and sensitivity that surround federal intelligence data and the HTOC federal partner cybersecurity operational data, HTOC partners do not share information outside the partnership without the expressed permission and authorization of the originating agency,” wrote Rose Sullivan, acting assistant secretary for legislation at HHS, in the department’s response.
HTOC receives intelligence data from the Department of Homeland Security, open source data, HC3, and subscription-based intelligence sources.
GAO further found HTOC and six other HHS entities it reviewed only partially addressed three cyber collaboration practices: defining and tracking outcomes and accountability, clarifying roles and responsibilities, and documenting and regularly updating guidance and agreements.
GAO recommended HHS’s CIO report on the progress and performance of the HHS CISO Council, Continuous Monitoring and Risk Scoring Working Group, and Cloud Security Working Group, as well as regularly update collaboration agreements between them with approval.
GAO also recommended the Assistant Secretary for Preparedness and Response do the same for the Government Coordinating Council’s Cybersecurity Working Group and HHS Cybersecurity Working Group, as well as update the charter for the Joint Healthcare and Public Health Cybersecurity Working Group for the current fiscal year.
HHS agreed with those recommendations.