Agencies and industry are seeing movement on the government’s biggest cybersecurity effort to-date with the first awards on the second task order for the Continuous Diagnostics and Mitigation (CDM) program announced and more to come this year.
The $29 million award — won by a group led by Knowledge Consulting Group — will provide the first set of technologies and services toward building a real-time view of networks managed by the Department of Homeland Security and its components.
More: Second set of CDM task orders awarded
Over the next few months, task orders will be awarded for all federal agencies, with the final set, Group F, expected before the end of the calendar year.
Getting started at DHS
Matt Brown, vice president of Homeland Security and Cyber Solutions at KCG, said the plan is to have the sensors and dashboards in place at DHS components by the end of the year. Once operational, agencies will have a view of every device connected to the network and regular scans to detect malicious activity.
“The goal of the CDM program is to be able to discover and manage 100 percent of IP addressable devices,” Brown said. “You’ll be able to monitor 100 percent of the devices that are on your infrastructure, ensure that they meet policy guidance, ensure that there is automated monitoring of any configuration changes and be able to scan for vulnerabilities of those devices every 72 hours.”
That last piece is a major leap forward, as most systems are scanned every 30 days, at best. Performing full network scans every three days will greatly reduce detection and remediation time, making systems significantly more secure.
The CDM system will also reverse some current cybersecurity norms, said Ken Kartsen, vice president of Intel Security Federal, which is providing its McAfee security software as a subcontractor on the TO2A award.
“If you look at traditional anti-virus it does a lot of blacklisting — if you see bad things, it says we know that’s bad and we will not allow it,” he said. “In today’s day and age, we don’t always have the ability to say we know this is something that’s bad – we may not have seen it before. But what we can do is look at a system and what it’s supposed to be doing … and we can apply technologies that say these are the only things this system should be doing and don’t allow it to do anything else. What we call whitelisting.”
How these systems are rolled out will differ slightly at each agency but the end goal is the same: a holistic, real-time view of the network.
More: DHS outlines new CDM task order agenda
“Different agencies and different departments have already deployed different capabilities and technologies. They’ve invested in different technologies based on what their requirements are internally,” Kartsen said. “What you’ll see [through Phase I] is them trying to fill the gaps based on what technologies they’ve enabled.”
By the end of Phase I deployment, all agencies across the federal government will have the same base level of monitoring, which will allow for more integration and better information sharing, as well, Kartsen noted.
Continuous monitoring by 2016
Homeland Security is the first agency to award Phase I contracts but the rest of government will be close behind, with industry representatives expecting most of the remaining groups to be awarded before the end of the year.
Group B, which covers Energy, Interior, Transportation, Agriculture, Veterans Affairs, OPM and the Executive Office of the President, is expected next quarter, followed by C through E before the end of fiscal 2015.
Solicitations have yet to go out for group F, which includes a number of smaller agencies. Those solicitations are expected sometime this summer, however this final group will likely make up for lost time by incorporating Phase II — identity, credential and access management — in the set of task orders.
More: CDM Phase II centers on monitoring user privileges, activities
“It could have to do with the fact that they’re looking at doing a shared service,” said Ken Ammon, chief strategy officer at Xceedium, noting this is a preliminary idea, as the requirements for Group F have not been set yet. “You look at Phase II being least privilege and infrastructure integrity, it would make sense to bake that capability into the shared service.”
In a shared service model with multiple agencies working off the same system, identifying who is on the network, what they are doing and what they should be allowed to do — the goals of Phase II — become even more important.
Agencies in the first five groups also have more existing monitoring capabilities, which makes Phase I more about standardizing those systems and creates more of a delineation between the first and second phases.
“In many cases, if you were to go across Group A, Group B, Group C, you find that every single one of those individuals already had some level of deployment of technology that’s called out in Phase I,” Ammon said. “So most of what is being done in Phase I is making sure you can round out the offering so they have a complete offering and ensure they have the feeds necessary to produce the information that will be rolled up for the dashboard.”
While it has taken time to get to the first task order two awards, most expect the pace to quicken now that the process has been established.
“This is a pretty complex program and certainly a transformational initiative for federal cyber and those things don’t happen overnight,” Brown said. “There are a lot of unique aspects of this program — the combination of both products and services under one contract, the grouping of departments and agencies together to implement these sensors and the services behind them … We’ve had a long road but it’s indicative of how complex and transformational the program is. And that’s a good thing.”
Brown noted the program has gained a lot of momentum and maturity over the last year that will help carry it through Phase III, even with the retirement of John Streufert, longtime CDM lead and one of the major proponents of Continuous-Monitoring-as-a-Service.
More: CDM lead John Streufert set to retire
“The urgency is there because there is such a significant amount of attacks that are taking place from nation-state entities these days,” Ammon said. “It’s turning into an oiled machine now. They’ve worked a lot of it out and it should be much faster moving forward.”




