Austin commits to $1.5B for DOD’s Joint AI Center over next 5 years

Secretary of Defense Lloyd Austin on Tuesday said he will commit $1.5 billion for the Department of Defense’s Joint Artificial Intelligence Center over the next five years.

While Congress ultimately decides what funding the JAIC will get, in recent years, it has shown willingness to appropriate funding to develop it as DOD’s AI “enabling force.” The most recent budget requests have yielded around $200 million annually for the JAIC, a number that would increase to about $300 million per year if Austin’s promised $1.5 billion is authorized by Congress.

“Done responsibly, leadership in AI can boost our future military tech advantage — from data-driven decisions to human-machine teaming. And that could make the Pentagon of the near future dramatically more effective, more agile, and more ready,” Austin said at the National Security Commission on AI conference Tuesday.

Austin said that the department has more than 600 AI projects running, many more than the year prior. The JAIC has been at the center of the DOD’s AI push, at first working on individual projects but now focusing on assisting the DOD’s myriad of AI offices. One of the programs the center continues to focus on is the Joint Common Foundations, an AI development platform that it eventually hopes will be the central tool developers across the department will use to write code, work with data and advance AI projects of their own.

The vision for AI in the DOD revolves around “integrated deterrence,” Austin said. In essence, the idea is to weave AI tools and the concept of operation into everything the DOD does, from logistics to waging war in all domains. It includes the new framework of Joint All-Domain Command and Control, where all sensors from across the domains of battle are integrated and use AI to make sense of data from the battlefield.

“AI and related technologies will give us both an information and an operational edge,” Austin said.

He also acknowledged that in order to achieve this type of integration, new acquisition methods will need to be used to field the rapidly changing technology. “But we know that truly successful adoption of AI isn’t just like, say, procuring a better tank,” he said.

One of the new tools in the DOD’s acquisition toolbox is the Rapid Defense Experimentation Reserve (RDER), which helps get promising tech across the so-called “valley of death” — the struggle for the Pentagon to transition and scale research-and-development efforts, particularly innovative technologies, to use on the battlefield

“In today’s world, in today’s department, innovation cannot be an afterthought. It is the ballgame,” Austin said.

GSA stresses agencies align IPv6 and zero-trust plans ahead of next week’s deadline

The General Services Administration continues to stress that agencies align their IPv6 and zero-trust architecture implementation plans, ahead of the deadline for the latter next week.

Zero-trust architectures should be protocol agnostic, and plans should ensure there aren’t any gaps in the cybersecurity products used, said Tom Santucci, director of IT modernization within the Office of Governmentwide Policy, at an ATARC event Tuesday.

GSA‘s main concern is that agencies also crafting their IPv6 implementation plans, due before the end of fiscal 2021, will end up undertaking duplicative work if the two plans aren’t coordinated.

“Those two should coincide with each other,” Santucci said.

President Biden‘s cybersecurity executive order issued May 12 gave agencies 60 days to develop their zero-trust plans, with an emphasis on accelerating the purchase of secure cloud services.

Agency cloud adoption strategies require planning at the C-suite level, and the Data Center Optimization Initiative that Santucci oversees developed a Cloud Smart guide to help. The guide advises agencies to evaluate their people, processes and tools, followed by the business value of cloud migration.

Examining cloud procurement and acquisition strategies is also important.

“One of the things we find is that people aren’t buying it right or aren’t using it right,” Santucci said.

Agencies will need to evolve cloud automation and monitoring tools over time and share information among their offices and teams because it’s often “amazing” how much one may know about how a modernization effort is going that the others don’t, he added.

DOD needs to better collaborate with DHS on cyberdefense, IG says

The Department of Defense’s work to help defend the cybersecurity of critical infrastructure needs a stronger implementation plan in its collaboration with the Department of Homeland Security, the DOD inspector general reported Tuesday.

The IG examined the implementation of a 2018 memorandum that outlined the partnership between the two departments on how they can coordinate the protection of critical infrastructure without violating their jurisdictions. The watchdog found DOD’s work lacks milestones and implementation plans for joint operations and general collaboration with DHS, which could put the nation’s cyberdefense of its critical infrastructure at risk.

“Without an implementation plan that clearly defines roles and responsibilities and identifies milestones and completion dates, the DoD may not be able to sustain collaboration with the DHS in protecting the Nation’s critical infrastructure,” the report states.

DHS’s IG also did an investigation, but it does not appear to be published yet.

DHS has the authority to protect the U.S. homeland, with its Cybersecurity and Infrastructure Security Agency taking the lead on cyberdefense, whereas DOD operates largely outside of the U.S. in both offensive and defensive operations. With the omnipresence of cyberthreats that can emanate both in and outside the U.S., the two departments have worked together to defend critical infrastructure. The first memorandum between the departments was signed in 2010.

The report complimented some of what the two agencies have done to date, like processes the departments established for how each can request help from the other. But recent hacks like the SolarWinds breach show the criticality of implementing more collaborative processes, the report said.

“[T]he compromise continues to show the importance and criticality of the DoD’s and DHS’s ability to respond to any and all cyber threats, which would be significantly improved by implementing a plan to accomplish shared goals in the 2018 joint memorandum,” it stated.

The Pentagon agreed with most of the specific recommendations, stating it would work to create implementation plans and more collaboration. But the vice director of the Joint Staff said the military would seek “interdepartmental consensus” on how to best move forward.

CDC looks to modernize its immunization information system

The Centers for Disease Control and Prevention intends to make sole-source contract awards to seven vendors to modernize its immunization information system, according to a presolicitation.

Vendors will make changes to the system allowing connectivity to the Immunization (IZ) Gateway, a message router that operates as a single connection point for participants like hospitals, clinics and pharmacies.

The contracts are part of a CDC initiative to enhance reporting of routine vaccination data and automate reporting of COVID-19 vaccination data, a weakness during the pandemic.

Vendors will also ensure connectivity to new IZ Gateway features like multi-jurisdictional queries and data submission to CDC.

The vendors CDC selected are Blue Cross Blue Shield of North Dakota, Deloitte Consulting, Gainwell Technologies, HLN Consulting, Optimoz, Software Partners, and Myriddian.

CDC selected the seven vendors citing Federal Acquisition Regulation 6.302-1, which allows sole-source awards when only one contractor can satisfy agency requirements. In this case, the vendors currently provide system operations and maintenance support to their specific jurisdictions, and the Office of Acquisition Services argues it would be “disruptive and inefficient” to have two contractors or system integrators providing the same services and duplicate costs while violating best practices.

Other vendors may submit capability statements, proposals or quotes for consideration by CDC by July 15. If the agency determines other vendors can meet its requirements, a competitive procurement will be conducted.

NASA seeks cybersecurity and privacy enterprise support

NASA wants contract personnel to provide cybersecurity and privacy enterprise solutions and services (CyPrESS) in support of all its centers and facilities, according to a request for proposals (RFP).

The contract will consist of a single award for an indefinite-delivery, indefinite-quantity contract of solutions and services over a nine-year period.

NASA‘s IT Procurement Office issued the RFP on behalf of its Office of the CIO in June.

The cost-plus-award fee (CPAF) contract covers CPAF and firm-fixed-price task orders, with the latter being phased in over a 60-day period at the outset.

A top-secret facilities clearance is required.

NASA anticipates making its award Nov. 8 and beginning core work on Feb. 1, 2022.

CMMC assessment requirements could be changing, potentially raising costs for some

The cost of some Cybersecurity Maturity Model Certification assessments could soon increase as the Department of Defense considers introducing new requirements, four people familiar with the matter told FedScoop.

DOD and the CMMC Accreditation Body are working to finalize requirements that could mandate having more experienced — and expensive — assessors conduct the needed tests of contractor networks that transmit controlled unclassified information. In effect, it could raise the price for some assessments as the per-hour cost of provisional assessors is higher than the original plan.

“Anything that is going to drive up the costs … is going to be detrimental to the small business community,” Michael Dunbar, a small business owner who recently testified before Congress on behalf of the small business trade association HUBZone Contractors National Trade Council, said in an interview.

CMMC requires third-party verification that all DOD contractors meet one of five levels of security established under the rule. DOD has maintained the majority of contractors will only need to meet level one, with least number of security controls.

While the proposed requirement is not finalized and would only apply to CMMC level three assessments for companies that handle the department’s controlled unclassified information, it is part of a growing list of ideas that the DOD CMMC Program Management Office is generating that several people familiar with the process worry will negatively impact the program’s cost and timely implementation.

Two people directly familiar with the process described it as DOD throwing out ideas without fully thinking through the effects, adding that the final requirements have not been published because DOD continues to add to them.

Under the changes, for an assessment at level three, Certified Third Party Assessor Organizations (C3PAOs) would need to hire four full-time provisional assessors. It was previously understood that these authorized assessment companies would only need to hire one assessor and three “registered practitioners” — entry-level assessors that do not meet the standards needed to become an assessor — to conduct a level three assessment.

To be eligible to be an assessor for level three assessments, an applicant needs at least four years of cyber or IT experience and to pass through on levels one and two first, according to the CMMC Accreditation Body’s website, which manages the ecosystem.

The proposed change to requiring four assessors has already been communicated to at least one of the first C3PAOs that will be doing level three assessments. Other potential changes include having quality control employees and new standards for the assessors be imposed on organizations.

“It’s my understanding that they are moving away from having the provisional assessors and registered practitioners and just having provisional assessors doing assessments,” Justin Padilla, CMMC lead at Kratos, said in an interview.

Padilla sees it less as an issue around costs or quality but as another reduction in the supply of resources necessary to implement the CMMC program. With 300,000 contractors eventually needing assessments at one of the five levels, and now even fewer people eligible to conduct level three assessments, the possibility of a demand crunch is growing.

“It’s more of a limited resource issue,” Padilla said, adding that Kratos has been lucky to have a few employees be selected to take the provisional training.

The DOD and the CMMC Accreditation Body did not return a request for comment.

GAO encourages agencies to improve forensic algorithm standards in new report

Agencies and Congress should consider improving standards, training and transparency around forensic algorithms to help analysts better use them in criminal investigations, according to a Government Accountability Office technology assessment released Tuesday.

GAO found such algorithms strengthen forensic analysis by improving the speed and objectivity of investigations, but their usefulness is limited by the human error and cognitive bias introduced by analysts.

The tech assessment comes two months after GAO released a report describing how the forensic algorithms used by federal law enforcement work and one week after the watchdog warned more than a dozen agencies using facial recognition, one of three primary forensic algorithms, couldn’t account for which systems they use — increasing public distrust of the technology.

“Policymakers could support the development and implementation of standards and policies related to law enforcement testing, procurement, and use to improve consistency and reduce the risk of misuse,” reads the assessment. “This could help address the challenges we identified related to human involvement, public confidence, and interpreting and communicating results.”

While both the National Institute of Standards and Technology and the Organization of Scientific Area Committees for Forensic Science (OSAC), are already developing standards for forensic algorithms, a new federal forensic oversight body may be in order. The other option is assigning a greater role to NIST and other agencies, according to GAO.

The three primary forensic algorithms are: latent print, facial recognition and probabilistic genotyping.

Both latent print and facial recognition search larger databases faster and more consistently than analysts, but poor quality prints reduce the accuracy of the former and human involvement introduces errors with the latter. Agencies further struggle to test and procure the most accurate facial recognition algorithms and find ones with minimal performance differences across demographic groups.

Meanwhile probabilistic genotyping helps analysts evaluate a wider variety of DNA evidence, that may have multiple contributors or be partially degraded, and compare it with samples from persons of interest. But evaluating such algorithms’ performance is complex, and there are no standards for interpreting or communicating the results.

Developing standards around the appropriate use of algorithms will reduce improper use if data quality is addressed and improve confidence in their use by enforcing consistency across law enforcement agencies, as well as streamlining testing and performance in the case of facial recognition, according to GAO.

The challenge will be implementing standards across all levels of government because agencies and localities may not want to confirm. The cost of procuring and maintaining algorithms could also rise, and researching and testing standards is already resource-intensive, according to GAO.

GAO also suggested agencies and Congress consider increasing algorithm training for analysts and investigators, which would reduce human error and improve cognitive bias. A certification process could reduce improper use at federal and non-federal labs.

The challenge would be developing and distributing training materials and determining what agencies are in charge of a certification process, according to GAO.

Lastly GAO suggested increasing transparency to improve trust by providing more information on algorithm testing results, data sources, use and investigations. Better comparative results could even help other agencies select better algorithms.

GAO foresees developers potentially resisting release of proprietary algorithm information, and the sharing of data sources could create privacy risks.

The watchdog agency made it clear that nothing suggested in its assessment constituted a formal recommendation, and no legal changes were proposed in the report to the House Science Committee leadership and Rep. Mark Takano, D-Calif.

DISA launches broadband satellite contract worth $980M

The Defense Information Systems Agency is soliciting bids for a contractor to service a 10-year commercial broadband satellite program.

The contract has a ceiling of up to $979.8 million and is structured as an indefinite-delivery, indefinite-quantity contract, against which the agency intends to award firm-fixed-price task orders.

According to documents filed on Sam.gov, the new contract is intended to augment government-owned and operated telecommunications systems and to provide additional redundancy to meet critical mission requirements. It will be structured as a three-year base period, three two-year option periods, and another final option period.

It will replace an existing contract that provides connectivity between Navy and Military Sealift Command (MSC) ships and Navy designated points of presence.

The government expects to award a single contract from the bid process.

Booz Allen civil business chief lays out strategy post-Liberty IT acquisition

Booz Allen Hamilton’s head of civil business has said that fulfilling existing contracts with the Department of Veterans Affairs is the consulting company’s “number one” job following its acquisition of technology provider Liberty, but that the deal presents growth opportunities for the federal contracting giant in other areas of government.

Kristine Martin Anderson spoke to FedScoop after Booz Allen last month closed its $725 million acquisition of Liberty IT Solutions, which has a $2 billion order backlog and specializes in working on healthcare-related digital technology missions for federal agencies.

“In the civilian space, we have been — for a few years — pushing further and further into technology around transformation of the citizen experience,” said Martin Anderson, who is executive vice president at Booz Allen and leads the company’s civil business. “Job number one is to do that work for VA, but then second to that, with their advancements around low code-no code and API development, we obviously see throughout our business in civil that they will help us scale.”

The VA is among the company’s largest clients, and Liberty is currently one of 24 sub-contractors supporting the rollout of the VA’s $10 billion electronic health record modernization program. Following the acquisition, which was funded by a combination of cash and debt, Liberty IT will be a wholly-owned subsidiary of Booz Allen.

Liberty IT Solutions specializes in the provision of low-code and no-code solutions for federal agencies and has a special relationship with Salesforce, which the company says enables projects to be undertaken quickly.

Martin Anderson explained that following the acquisition, the two companies are working to integrate their systems to allow Booz to offer its digital cyber and AI systems to Liberty clients also.

The executive noted also that Booz Allen Hamilton operates as a single P&L balance sheet, and that Liberty’s resources in the future could be deployed across other business areas including defense and intelligence.

“The appeal of the approach Liberty takes with Salesforce and low-code, no-code solutions is speed. With a traditional IT project, you might spend 18 months getting to the initial operating capability,” she said. “With the low-code, no-code platforms, you can see progress within 90-100 days, so I certainly think the market that has developed from low-code, no-code – while it won’t be everything – will continue to accelerate, and we’re going to see, with agile, and DevSecOps, and cloud.”

Responding to questions about potential further acquisitions within Booz Allen’s public sector division, Martin Anderson said the company is always looking for organizations with aligning strategy and culture, “at the right price.”

Commenting more broadly on the challenges for federal contractors that can accompany an administration change, Martin Anderson said Booz Allen tries to remain focused on missions where demand for services will always be required.

“On the one hand, you could say we are aligned well for the priorities of the Biden administration – and it’s true, we are – there are areas, key missions in civil we are focused on, that are also areas where there is still interest in this administration,” she said. “But we really do try to focus on the enduring missions. What are those missions where the government must provide the service no matter what?”

VA giving ‘insufficient’ training on electronic health records, IG warns

The Department of Veterans Affairs is not giving sufficient training to medical staff on the new electronic health records systems it is rolling out across the country, the inspector general found in a new report.

The lack of training has stopped clinicians from using the system in the ways it was designed, the report shows. The new IT system is a part of the VA’s $16 billion electronic health records modernization program first launched in the Mann-Grandstaff facility in Spokane, Washington. The rollout has been plagued by a range of issues, from several delays due to training issue and warnings of weak testing. The program was paused while it underwent a “strategic review” by the new secretary.

In a separate report, the IG found that VA underestimated the costs associated with upgrading the IT infrastructure that will support the new EHR system, by as much as $2.5 billion. Cost overruns could bring additional Congressional scrutiny to a program already under lawmaker’s microscopes.

“During this review, the OIG found that VA OEHRM failed in that the approved curriculum had significant deficiencies in training content, training delivery, and its ability to assess the efficacy of the training delivered,” the report states.

The training software provided to staff does not closely resemble the final product being rolled out, the IG found. The discrepancy on its own would have caused confusion even if the training went smoothly, but its execution was botched by assigning users to training that didn’t fit their jobs. The training was focused on specific tasks and not on the wide-ranging clinical scenarios staff at Mann-Grandstaff have to respond to, processes called “workflows,” in the report.

“Facility staff reported an absence of workflow training content and associated reference materials that prevented them from not only understanding how to apply what little they had learned to their daily work, but also prevented a basic understanding of the meaning behind workflow processes,” the report stated.

The report found that leaders at the facility coined the term “button-ology” to refer to training as it only provided information on what button to push and now how to use the tech in real world scenarios.

The inefficient training has led staffers to have a lack of trust in the system, a survey included in the report found. A majority of users said they do not feel they can navigate the applications, access patient information or easily share it, or that they have the ability to document patient care in the new system. Only 5% of users responded positively to all four questions, the survey result said.

“Overall, the survey results showed that after training and two to three months of new EHR use, only a small percent of facility users reported facile use with EHR core functions,” the report states.

The training issues come as more reports of cost over runs question if the VA will need to ask for more money to support the system’s nation-wide roll out. The IT infrastructure upgrades for EHR system was initially projected to cost $4.3 billion, which could be as much as $2.5 billion short.

One of the challenges in understanding how much the EHR system will cost is that the money is split between general Office of IT infrastructure upgrades and those specific to the EHR system. The VA is required to file reports to Congress on the costs associated with the EHR program,

“[T]here were inadequate procedures for determining if a cost-estimate update is needed in the office’s congressionally mandated reports,” the report states.

Another recent report pointed to similar issues on the physical infrastructure cost estimates. The secretary also noted in recent congressional testimony that costs might increase if the VA needs to surge additional resources to each medical facility that gets the EHR system as the department had to do at Mann-Grandstaff.

“It does appear to be requiring a lot more people on the target in Spokane,” he told the House Veterans Affairs’ committee in March.