Raytheon awarded $960M communications systems support contract

Raytheon Technologies has won a $960 million contract from the Air Force‘s Nuclear Weapons Center to provide software and hardware that will support the unit’s secure satellite-based communications systems.

The contract is for 10 years, and is structured as an indefinite-delivery, indefinite-quantity contract. Raytheon will work on the Advanced Extremely High Frequency(AEHF) system, which is a communication network reserved for the military’s highest priority information. The network is supposedly “secure, protected, and jam-resistant,” the Air Force states in its description of the system. 

“AEHF enables the Department of Defense to control tactical and strategic forces through all levels of conflict and supports the attainment of space superiority for the joint force,” according to the Air Force.

It is a sole-source acquisition contract, and Space Force will contribute $1.35 million in fiscal 2021 procurement funds to the contract cost. Other work done as part of the procurement will include “contractor logistics support, terminal depot activation, terminal hardware/software procurement and studies associated with support of the AEHF-T systems.”

The contract was awarded from Hanscom Air Force Base.

State Department IT investments lack central oversight, IG report finds

The State Department still doesn’t route all bureau and office IT procurements to its chief information office for approval, despite establishing a process to approve contracts, according to its Office of Inspector General.

OIG performed an audit of the department’s process for selecting and approving IT investments and found the Bureau of Information Resource Management could do more to centralize oversight and avoid duplicative purchases. The State Department spent $2.5 billion on IT in fiscal 2019.

The audit was a follow-up to a March 2016 report that found the State Department lacked a “defined process” that met Office of Management and Budget requirements, although five of OIG’s seven recommendations have since been closed.

“Until additional actions are taken, IRM will not be able to fully identify duplicative systems and related cost-saving opportunities, optimize its IT investments, or promote shared services,” reads the follow-up report released Wednesday.

OIG recommended IRM conduct a benchmark assessment of the agency’s IT portfolio to find duplicative systems — despite mitigating duplication by creating a process for comparing investment requests — and then implement a strategy to combine, implement or replace such systems.

Despite adopting OMB guidance and updating internal policy on recording IT investment in a portfolio management system, iMatrix, IRM needs a way to review reorganizations, OIG recommended.

IRM verbally concurred with OIG’s recommendations in a July 15 meeting.

OIG further recommended the Bureau of Administration identify IT-related acquisitions of $10,000 or more, a finding it agreed with.

IRM failed to make substantial progress on two OIG recommendations from the 2016 report. The bureau still hasn’t reviewed the IT investment methods of all bureaus of enforced the requirement that they and other State Department offices avoid duplication.

“These actions are needed to improve accountability and to further identify and avoid duplicative IT investments,” reads the report.

DHS conducting initial assessment for CMMC-like cyber compliance regime

The Department of Homeland Security has launched a “pathfinder assessment” to examine whether it should implement a new contractor cyber compliance program similar to the Department of Defense’s Cybersecurity Maturity Model Certification (CMMC).

DHS officials have previously expressed their interest in possibly implementing a similar program to improve the protection of sensitive information stored on contractor networks. CMMC mandates DOD contractors verify their compliance with one of five tiers of a compliance regime, instead of simply self-reporting their adherence to requirements. Private sector contractors have often been vulnerable to attackers seeking access to sensitive information, a weakness programs like CMMC are trying to address.

“Our end goal is to have a means of ensuring a contractor has key cybersecurity and cyber hygiene practices in place as a condition for contract award,” DHS CIO Eric Hysen said in a notice posted to SAM.gov Aug. 10. “As an immediate first step, DHS is conducting a pathfinder assessment to establish a path forward.”

It is unclear what exactly the “pathfinder assessment” is looking at, but the notice from the CIO states that DHS has been watching CMMC very closely and is looking to learn from its implementation. It is not the first time the DHS CIO has signaled interest in monitoring CMMC.

“We’re looking very closely at [the Department of Defense]’s Cybersecurity Maturity Model Certification, or CMMC, and looking to pilot that approach within our vendor base as well,” Hysen said during the April IT Modernization Summit presented by FedScoop.

While DHS might be looking closely at CMMC, it has not communicated with the third-party organization conducting much of its implementation. The CMMC Accreditation Body oversees the accreditation of the cyber assessors and the ecosystem of consultants and trainers that will work in the space. Its CEO, Matthew Travis is barred from communicating with DHS as he recently left the department as the No. 2 at the Cybersecurity and Infrastructure Security Agency (CISA).

“[T]he AB has not been in touch with DHS as Matthew Travis is currently restricted from doing so due to ethics restrictions,” a CMMC AB spokesperson told FedScoop.

CMMC has been praised for its ambition to verify cyber practices in contractors, but has faced implementation roadblocks. Small businesses working with DOD also worry it could raise costs to both meet the cyber standards and pay for the consultants and assessors needed to pass the test.

Katie Arrington, who at the time led the CMMC effort in DOD, said in April 2020 that she had met with DHS leaders about implementing CMMC.

The General Services Administration (GSA) has also taken notice of CMMC and implementing some of its requirements in government-wide contracting vehicles since DOD is a large consumer of the services GSA procures.

DHS did not respond to a request for comment.

DOD IG warns military staff to remove sensitive information from tech in Afghanistan withdrawal

The Department of Defense’s oversight body has warned military personnel they must wipe sensitive health and medical data from technology being returned as part of the U.S. withdrawal from Afghanistan.

In a report, the Inspector General (IG) reiterated rules that state all personally identifiable information must be removed from equipment including medical equipment, laptops and cell phones.

According to the IG, this is crucial both to prevent civilian and military records such as health and service records from falling into the wrong hands. The oversight body said also that officers must keep accurate records of technology that is returned as part of the withdrawal process.

In prior audits of military base equipment in Afghanistan, the IG found that the protocol for clearing information from equipment was not always being followed. In one case a device used to protect soldiers from improvised explosive devices was left showing sensitive location data.

“Unless equipment is properly processed by unit personnel before turning it into redistribution property assistance team personnel, there is a risk of theft and compromise of sensitive information,” the report said.

In May, DOD officials acknowledged that some U.S. military equipment could end up in the hands of Taliban fighters, but said military planners were using the time left until the pullout is complete to minimize the threat.

In February last year, the U.S. and the Taliban signed a conditional agreement to remove all U.S. forces from Afghanistan by April 2021. The military mission is set to conclude on August 31.

US Indian Health Service to replace health information system

The Indian Health Service is looking for electronic health record (EHR) vendors to replace the outdated health information system it and many tribal and urban American Indian healthcare organizations use, according to a draft statement of objectives (SOO).

Part of the Department of the Health and Human Services, IHS intends to award a 10-year indefinite delivery, indefinite quantity Health IT (HIT) Modernization Program contract with time-and-materials and firm-fixed-price task orders.

IHS developed the Resource and Patient Management System (RPMS) internally to support everything from patient registration to billing and pull from hundreds of databases nationwide. But recent advances in HIT and changes in regulations — as well as the decision of partner agency the Department of Veterans Affairs to move to a commercial off-the-shelf (COTS) solution — have IHS looking to do the same.

“IHS seeks HIT solutions that use innovative, next generation technologies and incorporate best practice clinical and business processes for improved health care outcomes,” reads the SOO. “The scope of capabilities and services touched by the IHS HIT modernization initiative is broad.”

Services include cradle-to-grave primary care, prenatal care, behavioral health, dental, eye care, physical therapy, and telehealth for American Indian and Alaska Native patients.

IHS wants a set of HIT COTS solutions that improve patients’ access to those services and their health information, quality of care, and health status. The agency is also looking to improve interoperability and information sharing across the American Indian health system and private and government partners, as well as security.

For that reason solutions must comply with the Federal Risk and Authorization Management Program, Federal Information Security Modernization Act, National Institute of Standards and Technology‘s Special Publication 800-53, recent cybersecurity executive order, and Health Insurance Portability and Accountability Act.

IHS anticipates vendors may face challenges meeting the diverse requirements of its tribal partners, as well as reporting requirements at the various levels of government.

The agency seeks vendor feedback on the requirements in its draft SOO and their capabilities, according to a request for information (RFI). Interested vendors have until 10 a.m. EDT on Aug. 19 to respond to the questions in the RFI.

NIST looks to perform AI, nanotechnology lab-to-market study

The National Institute of Standards and Technology intends to negotiation a contract for an artificial intelligence and nanotechnology lab-to-market (L2M) study to the Institute for Defense Analyses, according to a notice issued Aug. 3.

NIST wants to accelerate the commercialization of federally funded AI and nanotechnology research and development out of the Science and Technology Policy Institute.

The Institute for Defense Analyses administers STPI, a federally funded R&D center (FFRDC) that supports the White House Office of Science and Technology Policy in making L2M decisions.

NIST believes the Institute for Defense Analyses is the only vendor capable of performing the study because private companies may benefit “unfairly” from access to government information out of STPI or attempt to steer recommendations in their favor, according to the notice.

The Institute for Defense Analyses has history broadly assessing the federal technology transfer landscape and performing agency-specific analyses of early investments in R&D and commercialization efforts.

NIST may opt to compete the contract based on responses to its notice, due 8 a.m. EDT on Aug. 15.

Cyberspace Solarium Commission warns over slow progress on supply chain risk

The landmark Cyberspace Solarium Commission warned Thursday in an annual report that major barriers remain over the designation of cybersecurity responsibilities under the Defense Production Act (DPA).

In its initial report, published in March last year, the commission called on the federal government to use the DPA to foster domestic production of critical technology and components, and to ensure resources are available if foreign supply chains are disrupted.

Under the Defense Production Act, the federal government can invoke the authority to compel the private sector to prioritize certain contracts, as has occurred during the COVID-19 pandemic with companies such as 3M being compelled to produce masks and other medical equipment.

The report explains that regarding cybersecurity responsibilities related to the DPA, the commission “has encountered significant pressure against this recommendation, which is one of the four that face known significant barriers to implementation,” as it expected.

Other areas for concern identified in the annual report on implementation include progress in the creation of permanent select committees on cybersecurity in the House and Senate.

The report found also that major obstacles will need to be overcome before a national law on data security and privacy protection can be passed.

The latest document represents a progress update on the implementation of recommendations from the initial Cyberspace Solarium Commission report. Of recommendations included in the initial report, 22% have so far been implemented, 13.4% are nearing implementation, and 43.9% are identified as being “on track.” However, progress has been limited on 15.9% of proposals, and significant barriers remain in enacting 4.9% of recommendations.

However, the report also highlighted a number of core recommendations that so far have been achieved by the White House, including the creation and appointment of the role of National Cyber Director, provisions to strengthen the Cybersecurity and Infrastructure Security Agency, the codification of sector risk management agencies, and the launch of a joint cyber planning office.

“The Commission is proud of its progress but recognizes that in order to determine where we go next in cybersecurity, we must be clear eyed about what is not working,” the report said.

The commission is chaired by Sen. Angus King, I-Maine, and Rep. Mike Gallagher, R-Wisc.

GAO to decide WildandStormy bid protest outcome by Oct. 29

The Government Accountability Office will decide the outcome of a bid protest filed by Microsoft over a billion-dollar cloud procurement involving the National Security Agency by Oct. 29.

A GAO spokesperson confirmed to FedScoop that the agency had received a complaint from the tech giant, and outlined a timeline for the bid protest process.

Under procurement rules, GAO will issue an initial report in response by Aug. 20, and Microsoft will have 10 days to respond.

The dispute is understood to relate to a $10 billion cloud contract, which according to sources was awarded to Amazon. It is known in the federal IT community as WildandStormy.

“NSA recently awarded a contract for cloud computing services to support the Agency. The unsuccessful offeror has filed a protest with the Government Accountability Office (GAO),” a spokesperson for the NSA told FedScoop. “The Agency will respond to the protest in accordance with appropriate federal regulations.”

Details of the bid protest were first reported by Washington Technology.

A spokesperson for Microsoft confirmed the protest, saying: “Based on the [award] decision we are filing an administrative protest via the Government Accountability Office. We are exercising our legal rights and will do so carefully and responsibly.”

News of the bid protest comes after the Department of Defense last month announced that its Joint Enterprise Defense Infrastructure (JEDI) cloud contract would be scrapped, following a nearly two-year legal dispute waged by Amazon protesting the contract’s award to Microsoft. It has been replaced with the Joint Warfighter Cloud Capability acquisition, which the department intends to issue as a multi-cloud, multi-award contract.

Forthcoming Commerce enterprise IT contract could total $1.5B in task orders

The Department of Commerce intends to issue an enterprise IT contract worth as much as $1.5 billion in task orders over 10 years, according to a draft request for proposals posted to SAM.gov.

The Commerce Acquisition for Transformational Technology Services (CATTS) contract covers six task areas: chief information officer support, digital document and records management, managed service outsourcing and consulting, IT operations and maintenance, IT services management, and cybersecurity.

DOC‘s CIO office wants to use cloud platforms to deliver as-a-service offerings to its agencies to meet their business needs.

“The department is moving in a direction of minimizing the capital investments needed every three-to-five years for a technology refresh of obsolete infrastructure equipment and hardware,” reads the performance work statement. “Utilizing IT as a service, the DOC can position itself to meet the strategic goals, deliver its missions, and be recognized as a leader within future administrations and the federal enterprise in its use of information technology.”

The indefinite delivery, indefinite quantity contract is expected to have a maximum value of $1.5 billion and has a base period of one year and nine option years. Task orders may be issued on a firm-fixed-price of time-and-material/labor hour basis and may be performance based

DOC wants contractors that can reduce its on-premise footprint in favor of the cloud as much as possible.

Within the six task areas, DOC anticipates purchasing artificial intelligence, DevSecOps and FITARA program support services in addition to as-a-service offerings. Additional task work could include Cybersecurity Maturity Model Certification support.

DOC plans to hold a virtual industry day for all vendors on August 12 and another for minority-owned small businesses on August 16 to brief interested contractors on its vision, procurement strategy and timeline for CATTS, as well as solicit industry feedback prior to releasing the final solicitation.

The case for establishing an interoperable zero trust foundation for JADC2

Dan Schaaf is Senior Solutions Director and Army Sector CTO for GDIT, with more than 30 years’ experience implementing IT solutions and enterprise architecture for the U.S. Army and in the defense sector.

Defense officials for much of the past decade have recognized that future conflicts will require leaders to make decisions within minutes, or even seconds, and that the days of prolonged analysis are no longer an option. That concern was clearly spelled out more than three years ago by the National Defense Strategy Commission, which concluded that the state of the military’s Command and Control (C2) systems had “deteriorated” relative to potential competitors; and that the concept of a Joint All-Doman Command and Control (JADC2) network was clearly needed.

For all of the many strengths each of the services brings to the nation’s common defense, their central weakness remains the fact that the Air Force, Army, Marine Corps, Navy and Space Force each rely on separate and incompatible information networks. This reality leaves the Defense Department, and its ability to effectively defend and protect America’s interests, increasingly at risk. 

Dan Schaaf, Senior Solutions Director and Army Sector CTO, GDIT

The vision for JADC2 is to create a single network to connect sensors to weapons systems and deliver information advantage at the speed of relevance. Currently the services are developing transformational IT capabilities tailored to their own needs, focused on cloud, data platforms and the implementation of zero trust. But for JADC2 to achieve warfighting capability, it is critical that DOD leaders put a stake in the ground and insist on establishing a set of common, foundational capabilities that will ensure that mission critical data can move across the DOD securely; data can be shared and analyzed where and when it’s needed; and the data can be trusted. 

It is broadly accepted that a DOD-wide implementation of zero-trust security is foundational to the success of JADC2.  But if DOD leaders do not establish critical zero trust capabilities, there are very real risks that as each of the services develop their own service-centric cloud environments and data platforms, they will also implement service-centric zero-trust capabilities. Ultimately this will increase the complexity of the operating environment and short circuit the DOD’s ability to access and exploit the relevant data and services required for joint and multi-domain operations.

To that end, DOD leaders should establish a foundational set of common zero trust capabilities and then require the services, the defense industry and our mission partners to use and ideally leverage those foundational zero trust capabilities. 

The value of establishing a foundational DOD zero trust capability can be found in examining the use case of DOD’s decision to establish a PKI root certification authority for all identity and access management initiatives. By mandating the use of a common PKI root certification, the Defense Department created an environment that maintained and promoted cross-service interoperability and trust while still enabling each service to individually deploy identity and access management services.

Conversely, we can also learn from the DOD deployment of network directory services where they did not mandate the use of a trusted root. Though that deployment occurred more than two decades ago, the DOD still faces challenges to effectively federate and consolidate the multiple network domains that were created within the DOD, and which continue to significantly hamper efforts to develop a unified DOD network.  

A way forward for cross-DOD zero trust

To further illustrate this point and conceptually describe what foundational zero trust capabilities should be developed, Figure 1 below is the GDIT zero trust architecture which demonstrates two key innovative concepts: 1) federated security enforcement and 2) centralized and data driven policy decision capability

Figure 1: GDIT Zero Trust Architecture

Cloud

Source: GDIT

Along the center of Figure 1 is a “Policy Administration” capability that we propose. It represents the federated security enforcement devices which control the connection to resources. These are typically devices like firewalls or other access control mechanisms and are distributed throughout the enterprise today; but they also represent new and emerging zero-trust technologies that provide micro-segmentation of a network or dynamically establish software defined perimeters around resources. 

Our recommendation for a foundational zero trust capability is the “Policy Decision” capability (along the bottom of Figure 1) which integrates a policy engine, a trust engine and a single source of truth. When centrally developed and managed, this capability will enable the DOD to incrementally deploy zero trust capabilities as well as integrate existing security enforcement devices. 

To develop the “Policy Decision” capability, it’s critical that the DOD establishes the ground rules for what constitutes authoritative data — and ultimately lay the foundation for an enterprise-wide authoritative data environment. It’s also crucial that security enforcement systems working at machine speeds can discern what’s authoritative and what’s not in real time. That’s especially important as artificial intelligence within the trust engine is processing the data to determine relative risk and thresholds so that it is delivering the highest quality input to the policy engine that will synchronize the security enforcement devices and technologies.

Logically, the zero trust foundational capabilities should be delivered from a DOD cloud infrastructure to ensure the zero-trust management platform can operate securely and is also accessible by each service, the defense industry, mission partners and their data systems. Commercial clouds offer significant advantage for general purposes, but for joint operations, data must be integrated and served up without the friction arising from such factors as ingress and egress costs, data locality challenges or stovepipes resulting from disparate multi and hybrid cloud architectures among the military departments. Likewise, it makes sense for DoD’s own standardized capability for policy enforcement in support of JADC2 to be held in reserve, and not have different, even competing access regimes across the services.

A DOD Enterprise cloud is especially important for this use case. For those reasons, we are recommending DISA’s milCloud 2.0 cloud and contract as the location for the zero trust foundational capabilities. It can host the same innovative capabilities that leading edge companies host in the commercial cloud today; and it is located securely on DISA’s premises and inside DOD’s information networks. It is also FedRAMP-certified to meet DOD Impact Level 5 security ratings (and soon to be IL-6 certified) and it’s already accessible by all DOD components and authorized DOD partners.

By putting the foundational zero trust capabilities in place now and establishing a secure and accessible control plane for zero trust, DOD has a better chance of ensuring that they can protect any resource, anywhere and at any time. And just as importantly, it will accelerate warfighter capability by ensuring data from sensors, users and applications operating on and across JADC2 can be trusted and be used more universally.

Learn more how GDIT is helping the defense sector establish effective foundations for interoperability and zero trust.