FedRAMP just automated checking security authorization packages for completeness
The General Services Administration plans to release XML-automated validations next week allowing vendors to check their security authorization packages for completeness before submitting them to the Federal Risk and Authorization Management Program.
FedRAMP used Schematron’s rule-based validation for making assertions against XML to automate the process and wants vendors to self-test their packages to ensure all the required data is there, before the program reviews them and decides whether to issue a cloud product an authority to operate (ATO).
More easily hackable legacy systems stay in operation longer when agencies can’t quickly purchase cloud products they need for lack of an ATO, and vendors have long wanted FedRAMP to automate parts of its authorization process.
“I think it’s a great step in automated validation,” said Zach Baldwin, automation lead within the FedRAMP program management office (PMO), during an ACT-IAC event Tuesday. “I want cleaner documentation before I have my review team lay eyes on it.”
The PMO wants vendors to implement the validations that allows them to reinsert new files with more complex checks as FedRAMP improves them, Baldwin said.
FedRAMP is also considering an agile ATO, a critical set of controls vendors can implement quickly while saving lesser ones for later.
The PMO recently partnered with the Department of Homeland Security’s .govCAR to score vendors’ security architectures against cyberthreat heat maps. Updated scores will be released in the near future, but they can be used to create a risk profile as agencies make cloud service purchasing decisions, Baldwin said.
Automation wouldn’t be possible without FedRAMP’s work with the National Institute of Standards and Technology to create the standardized Open Security Controls Assessment Language (OSCAL) for authorization packages. NIST released OSCAL 1.0.0 in early June.
“I’m going after the time it takes to get an authorization and the number of passbacks between my review teams and the [cloud service providers] and [third-party assessors],” Baldwin said.
Pentagon names Gregory Kausner acting head of acquisition
The Department of Defense has appointed Gregory Kausner to assume the duties of undersecretary of defense for acquisition and sustainment.
He takes up the role in an unofficial capacity after a career in military leadership at the Pentagon, most recently as executive director for international cooperation.
There is some nuance to Kausner’s appointment — he has been asked to do the job of undersecretary of defense for acquisition and sustainment but does not officially hold the position, as undersecretary of defense for acquisition and sustainment requires a presidential nomination and Senate confirmation.
News of the Kausner’s assumption of the duties comes after Defense Innovation Unit Director Mike Brown earlier this month requested that his name be withdrawn from Senate consideration for the position as President Biden’s nominee. His decision came amid an ongoing investigation from the DOD’s Inspector General into his conduct.
DOD today also announced the appointment of Paul Cramer to perform the duties as deputy undersecretary of defense for acquisition and sustainment.
In the undersecretary role, Kausner is responsible for all matters relating to defense acquisition, contract administration, logistics and materiel readiness. The scope of his brief also encompasses work relating to installations and environment, operational energy, as well as the acquisition workforce and the defense industrial base.
Kausner had performed the duties of deputy undersecretary of defense for acquisition and sustainment since January this year and previously served in a multitude of other senior military roles.
How automated analytics can improve digital services, security and workflows
As leaders at federal civilian, health and defense agencies continue to grapple with the explosion of data coming at them from all directions, the need for more robust platforms, capable of managing and making sense of all that data, has taken on new urgency.
The good news is, a new generation of AI-assisted IT operations (AIOps) platforms and intelligent analytics platforms — as well more advanced security orchestration, automation and response (SOAR) solutions — are giving agencies powerful new capabilities to keep up with that data, according to a new report from FedScoop.

Read the full report.
The availability of AIOps, data analytics and SOAR solutions are expected to play an important role in helping agencies achieve the White House’s May 12 “Executive Order on Improving the Nation’s Cybersecurity.” The order, among other directives, requires agencies to begin implementing new steps to modernize their cybersecurity practices and improve how they respond to cybersecurity vulnerabilities and threats. Those requirements come on top of the Federal Data Strategy 2020 Action Plan, which calls for agencies to take concrete steps to govern, manage, protect and leverage the value of federal data.
The challenge agencies face, according to the report, isn’t just the volume of data getting generated and processed every day. It’s how to effectively assemble so many types of structured and unstructured data emanating from so many disparate systems — and then, how to make sense of it in order to make timely business decisions or mitigate cybersecurity threats.
The report, which was underwritten by Splunk, outlines five critical functions that modern AIOps platforms can now perform, from ingesting dating to analyzing it in real time and initiating remedial actions when necessary.
It also touches on the benefits of platforms like Splunk SOAR and Splunk IT Service Intelligence (ITSI) platforms, that can help agencies reduce the time it takes to investigate and resolve IT issues.
Ann Mehra, strategic healthcare programs leader at Splunk, recalls in the report how “close to 50 individuals were trying to get to the root cause of what was happening, utilizing a number of different tools. We stepped in and in 48 hours, we were able to look across the organization’s networks, across its applications, and across its data sources and were able to identify the root cause.”
ITSI also gives agencies a platform for managing large-scale IT development projects. That was the case when the U.S. Census Bureau decided to conduct the 2020 decennial census online, requiring a massive effort to modernize their IT, security and data operations, according to Wylie Vasquez, leadership advisor for observability and AIOps markets at Splunk.
One of the key advantages Census found in Splunk’s Data-to-Everything platform, according to the report, is the ability to ingest and unify nearly any kind of data — structured or unstructured, including logs, metrics, text, wire, API or social-media — from nearly any tool and any system, on-premises or in the cloud.
Another benefit of automation, the report says, is the ability to reduce the potential for human errors or delays that can occur in highly repetitive tasks. Automation also can help agencies maintain greater system continuity in circumstances where personnel rotate in and out of positions, as is routinely the case in the military.
“Removing the error factor” is one of the key benefits of automation, says Eric Hennessey, staff consulting solutions engineer for national defense accounts at Splunk. “Whenever you can take humans out of the loop on some of these tasks — especially a task that you do over and over again — and institutionalize these repetitive processes, using an automated playbook like we do with Splunk SOAR, you greatly reduce that opportunity for error.”
Read the full report on how automated analytics can improve digital services, security and workflows.
This article was produced by FedScoop and sponsored by Splunk.
Booz Allen expects number of staff working in office to decline
Booz Allen Hamilton is expecting the number of its staff working full time in its offices and on government premises to fall from previous levels, according to the federal contractor’s CEO.
Speaking on a second-quarter earnings call, Horacio Rozanski praised the creativity of the company’s clients during the COVID-19 pandemic and said many continue to embrace new ways of working.
“[W]e have a group of people who work full time at government and our facilities. And that too will continue, although we expect it to proportionately decline from historical levels,” Rozanski said. “Our clients have shown a great deal of creativity over the course of the pandemic. And based on this experience, many are interested in flexible models that better serve their missions while reducing the number of people who are 100% onsite.”
The comments come as agency staff return to the office and follow an earlier policy advising federal departments to consider embracing a more geographically distributed workforce. The Office of Personnel Management also issued further guidance on that policy July 23 “to assist agencies … as they plan for the safe, increased return of Federal employees to physical workplaces (“reentry”) and the post-reentry work environment.”
Agencies have each set their own strategy for bringing their workforce back to the office with input from the Safer Federal Workforce Task Force.
According to the prior guidance, federal departments were advised to embrace more telework “where possible and appropriate,” and where it could help to benefit equity, inclusion and the delivery of missions.
The geographic location of the federal government jobs was highlighted last month with the Biden administration’s Executive Order on Diversity, Equity, Inclusion and Accessibility, which was intended to examine new ways of getting underserved and minority communities into the workforce.
Responding to questions from analysts on the company’s earnings call, Booz Allen’s executive team said also that the company’s projection for achieving about $200 million in cost savings from its acquisition of Liberty IT, remains unchanged.
In an interview earlier this year with FedScoop, Booz Allen’s head of civil business Kristine Martin Anderson said the consulting company’s “number one” job following the $725 million deal would be to deliver on existing contracts with the Department of Veterans Affairs, but that the transaction will allow the company to deploy Liberty’s resources across other areas of its balance sheet.
Accelerating forensics investigations by leveraging AWS GovCloud
Christine Halvorsen has spent more than 20 years working in various law enforcement, intelligence and IT roles for the Department of Justice and the FBI before joining AWS in 2019. She currently serves as senior technical business development manager on AWS’s Mission Acceleration Team.
The explosive growth of digital forensics information over the past two decades has transformed the way federal law enforcement and regulatory agencies deliver their missions. But it has also put new pressures on many federal agencies to develop more scalable and advanced solutions.

Christine Halvorsen, Sr. Technical Business Development Manager, AWS’s Mission Acceleration Team
When I started out as an FBI agent in 1996, we were still getting used to the forensic tools and principles for collecting, extracting, storing and safeguarding digital evidence. By 2010, the FBI’s Regional Computer Forensic Laboratory reported the average case by sifting through and managing four terabytes of data.
That was modest compared to the FBI’s 2013 Boston Marathon bombing investigation, which collected more than 50 terabytes of information. By the time I was called in as senior investigator in the 2017 Las Vegas Mandalay Bay shooting, the FBI was faced with collecting and analyzing a petabyte of data for that single case.
Were it not for the built-in capabilities of the cloud — to upload and analyze all of that unstructured, circumstantial evidence quickly, and in ways that were both secure and auditable — it would have been impossible to manage a case of that size, involving 13 responding agencies and so many tragic deaths and injuries.
Meeting mission needs at scale
Finding proverbial needles of evidence in today’s massive digital haystacks has never been more challenging. The volume of data from personal computers, smartphones, social media, emails, and e-commerce, as well as surveillance cameras, sensors and countless other devices continues to grow exponentially. By 2025, the amount of data generated each day is expected to reach 463 exabytes globally.
And it’s not just a challenge for law enforcement. There’s a wide range of government agencies, overseeing financial, health, consumer protection and many other sectors, that are similarly responsible for properly handling, analyzing, preserving and storing evidential information from the point of ingest and throughout its lifecycle.
Leveraging the cloud can help agencies scale IT resources up and down, as well as save IT costs. But perhaps more importantly in government, the cloud offers agencies on-demand compute power and modern applications to process workloads at a pace that agencies require to meet their missions.
The cloud can help address four recurring challenges we hear from our customers, particular those whose missions depend on managing digital evidence:
- Reducing the processing backlog — When it comes to managing digital evidence, there are five critical stages that must be handled properly: collection, extraction, storage and chain of custody, analysis, and dissemination. As digital case workloads grow larger and more complex, fixed IT resources make it harder to complete the front-end tasks. That cascades into costly delays in completing analytic work. At AWS, we’ve been helping customers use the scale of the cloud to provide a dynamic and cost-effective way to accelerate workloads in those first three stages — helping in turn to analyze and disseminate evidence faster.
- Optimizing familiar forensics tools to work in the cloud – Customers tell us they want the ability to use the secured forensic tools they are familiar with on-premises turbo-charge them using the cloud’s high-performance compute environment. Together with our partners, we’re helping them make that transition while reducing their software licensing costs. Instead of agencies, for instance, having 10 licenses sitting on one workstation, which limits how many people can process evidence, AWS and its partners are developing new licensing models in the cloud to support the customer’s needs and application of the tools, allowing more examiners and analysts to work simultaneously with agility and speed, given the cloud’s processing power.
- Automating digital extraction and analytics processes – Our customers also tell us that many of their processes are still manual, cumbersome and repetitive. We’ve been able to automate significant portions of that work. For instance, examiners using AWS’s GovCloud can extract digital evidence from bundles of data and then immediately apply analytics. That helps narrow their searches for needles in the digital haystacks and quickly gain insights from what’s in the data.
- Managing evidence storage more effectively – The unique statutory requirements for storing evidence — in some cases for 25 years — presents a special challenge for agencies. It’s no longer practical or economical to keep buying more and more storage infrastructure. With AWS infrastructure, agencies can choose a range of storage models, including our deep archive option, which allows agencies to store data for pennies on the dollar compared to on-prem storage. AWS also makes it easier to automate the movement of evidential data from one stage to the next and into final storage after cases are closed, freeing up forensic examiners and analysts to concentrate on delivering their missions.
AWS has been working with multiple federal agencies from federal law enforcement to federal financial institutions to establish working models that address all four of these challenges. These models have reduced the time to process digital evidence from weeks to minutes. The cloud’s elasticity has spurred innovative approaches to analyzing forensic data and given investigators greater analytical, entity extraction, and translation capabilities. But most of all, the cloud is giving agencies the ability to manage their digital evidence workloads at a pace that’s more commensurate with their needs of their missions.
Learn more how AWS is helping federal agencies manage their escalating digital workloads.
Anduril appoints Goldfein, MacFarland to advisory board
Defense technology firm Anduril has appointed a handful of top former defense officials to its advisory board.
The company named five new advisors including Katharina McFarland, former assistant secretary of defense for acquisition, retired U.S. Air Force Chief of Staff Gen. David Goldfein and former U.S. Navy officer Adm. Scott Swift, who was commander of the U.S. Pacific Fleet.
Goldfein was the 21st Chief of staff of the U.S. Air Force, in which role he was responsible for organizing, training and equipping the service.
Pangiam CEO Kevin McAleenan, who served as acting secretary of the Department of Homeland Security during the Trump administration, and Constantine Saab, the chief technology officer at Valor Equity Partners and a longtime CIA executive, also join its advisory committee.
Commenting on the five new appointments, Anduril CEO Brian Schimpf, said: “We are honored to be joined by an esteemed group of experts who will provide strategic counsel as we grow the company and scale Anduril’s software and hardware products across the DOD.”
“The board brings a wealth of knowledge and perspective on the inner workings of the government agencies responsible for our nation’s safety and security. They will help guide our work to rapidly modernize U.S. defense capabilities,” he added.
Earlier this month, Anduril won a $99 million contract to provide the Department of Defense with a new automated counter-unmanned aerial system (C-UAS) capability. The Production Other Transaction (P-OT) Agreement was struck between the company and the Defense Innovation Unit,
DOJ reveals 27 U.S. Attorneys offices had emails compromised in SolarWinds hack
A total of 27 U.S. Attorneys offices had one or more employees’ Microsoft 365 email accounts compromised, when Russian hackers used the SolarWinds Orion updating system to push malware to agencies, the Department of Justice revealed Friday.
DOJ believes the advanced persistent threat group, APT29 or Cozy Bear, had access to the accounts from May 7 to Dec. 27, 2020 and all sent, received and stored emails and attachments within.
The department first acknowledged the intrusion on January 6 but made its latest announcement to promote cybersecurity information sharing among agencies.
“The Department of Justice understands that when victims make information public about the nature and scope of computer intrusions they suffered, others can use that information to prepare themselves for the next threat,” the update read. “To encourage transparency and strengthen homeland resilience, today we are providing additional details about the SolarWinds intrusion in December 2020.”
At least 80% of employees in New York’s Eastern, Northern, Southern and Western district offices had their accounts compromised, and all have been notified and instructed on how to identify cyberthreats, the department said.
Among the other districts compromised were two in California, the District of Columbia’s, three in Florida, one in Georgia, one in Kansas, one in Maryland, one in Montana, one in Nevada, one in New Jersey, one in North Carolina, three in Pennsylvania, three in Texas, one in Vermont, two in Virginia, and one in Washington.
Upon discovery, DOJ’s Office of the Chief Information Officer eliminated the hackers’ backdoor into its email environment and notified the Cybersecurity and Infrastructure Security Agency and Congress, but the damage persists.
“The department’s objective continues to be mitigating the operational, security and privacy risks caused by the incident,” reads the update.
Senate committee calls for FISMA to be revamped
The Senate Committee on Homeland Security and Governmental Affairs has identified continued major cybersecurity failings across agencies and is calling for the Federal Information Security Modernization Act (FISMA) to be reformed.
A new report published Tuesday identifies IT security flaws across almost every major U.S. government department, including the failure to secure citizens’ personal and financial data and the inability to keep track of thousands of items of IT equipment.
According to the committee, lawmakers should update FISMA to require federal agencies and contractors to notify the Cybersecurity and Infrastructure Security Agency (CISA) of certain cyber incidents and to amend the definition of “major event” to ensure Congress is notified of breaches quickly.
FISMA was enacted in 2014 to create a requirement that each federal agency develop, document and implement a complete information security plan. It has come under scrutiny following recent hacks, including the SolarWinds attack in late 2020, during which multiple government departments were compromised.
The report recommends also that CISA expand shared offerings to all federal agencies, including enhanced endpoint detection.
Core government departments, including the Social Security Administration, are failing to handle data securely, according to the report.
An audit by the Department of Transportation’s Inspector General found 14,935 IT assets belonging to the department of which it had no record. This included 7,231 mobile devices, 4,824 servers, and 2,880 workstations that were unaccounted for.
The Senate committee’s review highlighted also that many agencies continue to run copies of software on their computer systems that are no longer supported by technology vendors and also flagged the failure of agencies to obtain the required authorities to operate for all of their technology business systems.
The committee’s findings are based on its own analysis, as well as work carried out by the inspectors general of federal agencies during fiscal 2020.
It followed up on an earlier report, issued in 2019, that identified the failure of eight key government agencies to comply with federal cybersecurity standards. According to the latest iteration of the study, seven agencies have made only minimal progress in improving their compliance with the regime, and only one – the Department of Homeland Security – was judged to have employed satisfactory cybersecurity standards during 2020.
Top Navy officer says Project Overmatch work ‘headed in the right direction’
The Navy’s work to execute its portion of the Joint All Domain Command and Control (JADC2) strategy has a way to go, but the service is “headed in the right direction,” according to Adm. Mike Gilday.
Speaking Monday at the Sea-Air-Space conference, the Navy’s most senior officer said the service is in the third cycle of testing new technology this year as part of the program, but that challenges remain.
“We’re very excited about where it’s headed. We’re not satisfied with where we are. We have a way to go before we get to the point where we roll out strike group-wide in 2023,” Gilday said.
The Navy’s section of the JADC2 strategy is known as Project Overmatch, and its goal is to connect data multiple domains of warfare. The senior officer added that he hopes that within a decade ships will have the connectivity to send all of their data over any network in a secure manner.
By having the ability to constantly share data, the hope is military command and control can be assisted by artificial intelligence that can generate more options for commanders orchestrating a multi-domain battle. It’s a tall order for a service beset with cybersecurity challenges and legacy systems the service recently started to modernize.
Rear Adm. Douglas Small, who is leading Project Overmatch, also said his office is still working on the foundational architecture and testing new tech. He said he has enough money and enough cloud computing to work through the technical challenges, but finding ways to actually share data have yet to be discovered.
Small said one of the most challenging aspects of the programs is transferring data across domains, from the air to sea to other parts of warfare. That challenge is augmented by the Navy’s geographic posture, having its ships being disconnected through miles of oceans.
The CNO said Overmatch and the JADC2 framework it follows is a priority for the service. It’s also a priority for other services and the department as a whole, that recently signed a JADC2 strategy. But so far, few enterprise capabilities have materialized beyond some battle management applications on ships.
VA awards Peraton $497M IT infrastructure contract
The Department of Veterans Affairs has awarded Peraton an IT infrastructure contract that could be worth up to $497 million over seven years.
The Virginia-headquartered company will provide infrastructure-as-a-managed service for storage and computing infrastructure facilities across the U.S. and globally.
According to the company, it will deliver an enterprise-scale solution that integrates on-premise infrastructure with the VA’s enterprise cloud architecture.
Under terms of the contract, Peraton will be tasked with supporting up to 220+ petabytes of data, ranging from business operations data to the medical images used in veteran care. It will undertake the contract work at up to 300 VA sites across the continental U.S. and abroad.
Commenting on the award, George Rollins, vice president of VA and defense health at Peraton, said: “This is an incredible win for the team. We look forward to our continued partnership with the VA, and to helping the Department realize the expected benefits from its major modernization initiatives.”
ThunderCat Technology had protested the award of the contract to Perspecta — which was recently acquired by Peraton — earlier this summer but then withdrew its complaint.