<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet media="screen" type="text/xsl" href="https://one.sightlinemg.com/federaltimes/wp-content/themes/smg/assets/xslt/rss-xslt.xml"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:media="http://search.yahoo.com/mrss/"
xmlns:news="http://www.pugpig.com/news"
>

<channel>
	<title>Cloud - Federal Times</title>
	<atom:link href="https://one.sightlinemg.com/federaltimes/it-networks/cloud/feed/" rel="self" type="application/rss+xml" />
	<link></link>
	<description>Federal Times</description>
	<lastBuildDate>Tue, 18 Aug 2026 20:52:13 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.4</generator>

<image>
	<url>https://one.sightlinemg.com/wp-content/uploads/2026/06/favicon-fed.png?w=32</url>
	<title>Cloud - Federal Times</title>
	<link></link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">255331619</site><atom:link rel="next" type="application/rss+xml" href="https://one.sightlinemg.com/federaltimes/feed/?paged=2" />
	<item>
		<title>Space warfare in 2026: A pivotal year for US readiness</title>
		<link>https://one.sightlinemg.com/federaltimes/it-networks/2026/01/05/space-warfare-in-2026-a-pivotal-year-for-us-readiness/</link>
					<comments>https://one.sightlinemg.com/federaltimes/it-networks/2026/01/05/space-warfare-in-2026-a-pivotal-year-for-us-readiness/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Mon, 05 Jan 2026 20:30:00 +0000</pubDate>
				<category><![CDATA[Artificial Intelligence]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[IT & Networks]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2026/01/05/space-warfare-in-2026-a-pivotal-year-for-us-readiness/</guid>

					<description><![CDATA[As the Space Force enters 2026 amid escalating threats from China and Russia, it faces a pivotal year as it transitions to full-spectrum warfighting.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/it-networks/2026/01/05/space-warfare-in-2026-a-pivotal-year-for-us-readiness/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">34257</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/9276143.jpg.jpg" width="6000" height="3992" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">As the U.S. Space Force enters 2026 amid escalating threats from China and Russia, the service faces a pivotal year as it transitions to full-spectrum warfighting. </p>



<p class="wp-block-paragraph">Recent assessments from the U.S.-China Economic and Security Review Commission’s 2025 annual report underscore the challenge ahead. According to the report, “China is aggressively positioning itself as a global leader in space technology and exploration, seeking to reshape international governance, influence standards, and displace the United States as the world’s premier space power.” </p>



<p class="wp-block-paragraph">The report notes China’s operational satellite fleet exceeded 1,060 by mid-2025, with hundreds dedicated to intelligence, surveillance and reconnaissance.</p>



<p class="wp-block-paragraph">Chief of Space Operations Gen. B. Chance Saltzman has signaled U.S. resolve on this front. During the opening keynote at the Air &amp; Space Forces Association’s Warfare Symposium in March 2025, he made U.S. intentions clear to allies and adversaries alike, declaring, “The Space Force will do whatever it takes to achieve space superiority.”</p>



<p class="wp-block-paragraph">The April 2025 release of “Space Warfighting: A Framework for Planners” codifies the service’s shift from primarily supportive roles to treating space as a contested warfighting domain, openly emphasizing offensive and defensive counter-space operations alongside traditional enabling capabilities. </p>



<p class="wp-block-paragraph">In the document’s foreword, Saltzman writes that space superiority “unlocks superiority in other domains, fuels Coalition lethality, and fortifies troop survivability. It is therefore the basis from which the Joint Force projects power, deters aggression, and secures the homeland.”</p>



<h2 class="wp-block-heading">‘Race to resilience’</h2>



<p class="wp-block-paragraph">Current core U.S. military space capabilities remain foundational but increasingly vulnerable. </p>



<p class="wp-block-paragraph">Missile warning and tracking systems, such as the Space-Based Infrared System and emerging Next-Generation Overhead Persistent Infrared satellites, provide global detection of ballistic and hypersonic launches, often within seconds of ignition. This capability is supplemented by proliferated low-Earth orbit sensors, including the Space Development Agency’s Tranche 3 tracking layer, a $3.5 billion investment awarded in late 2025 for 72 new satellites planned for launch beginning in 2029.</p>



<p class="wp-block-paragraph">Protected satellite communication and positioning, navigation and timing networks, including the jam-resistant Advanced Extremely High Frequency constellation and military GPS featuring enhanced anti-jam M-code, ensure resilient command and control in degraded environments.</p>



<p class="wp-block-paragraph">Space domain awareness tools, such as the maneuverable Geosynchronous Space Situational Awareness Program satellites, operate in near-geosynchronous orbit to conduct close inspections of objects. Upgraded ground-based sensors, including the Ground-Based Optical Sensor System, track orbital objects and potential threats.</p>



<p class="wp-block-paragraph">While robust, these systems are vulnerable to attacks such as signal jamming, sensor dazzling by directed-energy weapons and cyberattacks — reversible threats that U.S. officials report occur daily or near-daily. U.S. officials note that even temporary disruptions could significantly impair critical joint operations in wartime. </p>



<p class="wp-block-paragraph">These challenges are driving the service’s “Race to Resilience” initiative, which aims to achieve battle-ready architectures by 2026. Several key milestones in the coming year will advance the Space Force’s readiness in these contested environments.</p>



<p class="wp-block-paragraph">Boost-phase space-based interceptor prototypes, a proposed weapon system designed to destroy enemy ballistic missiles during the boost phase of their flight, were awarded under competitive contracts for the Golden Dome missile defense initiative in November 2025. Kinetic midcourse awards (hit-to-kill interceptors during the missile’s coasting phase) are expected in February 2026. </p>



<p class="wp-block-paragraph">Speaking shortly after his appointment at the Space Foundation’s Innovate Space: Global Economic Summit in July 2025, program lead Gen. Michael Guetlein shared his optimism for the program, stating, “I firmly believe that the technology we need to deliver Golden Dome exists today,” highlighting the importance of integrated command and control.</p>



<p class="wp-block-paragraph">The service will also finalize requirements for the Space Warfighter Operational Readiness Domain, a distributed digital training environment that builds on existing Space Flag exercises, enabling guardians across multiple locations to participate in virtual simulations of contested operations.</p>



<p class="wp-block-paragraph">Four on-orbit servicing demonstrations are planned for 2026 to test satellite refueling, repair, inspection and maneuvering. These capabilities are essential for maintaining dynamic space operations, extending the lifespan of assets and enhancing resilience in these contested environments. These missions, funded by various DOD entities and commercial partners, mark a key step toward proving the viability of in-space logistics.</p>



<p class="wp-block-paragraph">Additionally, the Commercial Augmentation Space Reserve will transition from pilot phase to full-scale operations in 2026, targeting 20 contracts by year-end to provide wartime access to commercial satcom networks. This resiliency measure is backed by record fiscal 2026 funding approaching $40 billion, reflecting priorities for hybrid military-commercial architectures.</p>



<p class="wp-block-paragraph">With threats intensifying, including China’s rapid satellite expansion and Russia’s disruptive capabilities, 2026 positions the Space Force to deliver resilient architectures that ensure U.S. space superiority, enabling joint forces to maintain the edge in any conflict or contested environment.</p>
]]></content:encoded>
	</item>
		<item>
		<title>Autonomous surface vessels to join Pentagon’s global C2 network</title>
		<link>https://one.sightlinemg.com/federaltimes/it-networks/2025/12/05/autonomous-surface-vessels-to-join-pentagons-global-c2-network/</link>
					<comments>https://one.sightlinemg.com/federaltimes/it-networks/2025/12/05/autonomous-surface-vessels-to-join-pentagons-global-c2-network/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Fri, 05 Dec 2025 14:00:00 +0000</pubDate>
				<category><![CDATA[Cloud]]></category>
		<category><![CDATA[IT & Networks]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2025/12/05/autonomous-surface-vessels-to-join-pentagons-global-c2-network/</guid>

					<description><![CDATA[The small vessels can maneuver through harsh environments and perform various tasks independently with minimal human oversight, such as surveillance. ]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/it-networks/2025/12/05/autonomous-surface-vessels-to-join-pentagons-global-c2-network/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">34245</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/Rampages-Port-of-Honolulu.jpeg.jpg" width="3000" height="2001" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">Autonomous surface vessels will become part of the global command and control network used by the U.S. Navy and other U.S. military services due to a new partnership between HavocAI and SAIC, effectively making the vessels an integrated part of U.S. naval surface power and expanding their availability to serve all U.S. military branches for the first time. </p>



<p class="wp-block-paragraph">The agreement announced by SAIC and HavocAI last month will see a link-up between HavocAI’s autonomous surface vessels and SAIC’s advanced <a href="https://www.saic.com/jre" target="_self" rel="" title="https://www.saic.com/jre">joint range extension gateway</a>. The JRE currently streamlines communications for U.S. and allied military forces worldwide and will extend the range of Link 16, a vast, all-domain global C2 infrastructure.</p>



<p class="wp-block-paragraph">This new move puts nimble autonomous surface vessels able to sweep wide stretches of ocean at the click of a button at the immediate disposal of the Navy and other military forces linked to the JRE gateway. Leadership of both companies shared the details with Defense News in an exclusive interview.</p>



<p class="wp-block-paragraph">“Being able to be interoperable with the existing network infrastructure with U.S., allied and partner navies is the biggest part,” Barbara Supplee, Executive Vice President, Navy Business Group at SAIC told Defense News. “We are piping the information on a much more expanded range. It’s taking the innovation that HavocAI is putting in the water and matching it with the existing networks.” </p>



<p class="wp-block-paragraph"><b>Unmanned teamwork</b></p>



<p class="wp-block-paragraph">The small vessels made by HavocAI operate as teams using its <a href="https://www.havocai.com/the-stack" target="_self" rel="" title="https://www.havocai.com/the-stack">Collaborative Autonomy Stack </a>system. They can maneuver through harsh environments and perform various tasks independently with minimal human oversight, such as surveillance. </p>



<p class="wp-block-paragraph">“The vessels communicate with each other. They’re always talking to each other to try to figure out how to execute something efficiently. The only kind of humans involved are in tasking,” Paul Lwin, co-founder and CEO of HavocAI, told Defense News. </p>



<p class="wp-block-paragraph">Thanks to the new pairing with SAIC, the vessels will now feed information back to military command centers. </p>



<p class="wp-block-paragraph">“They [the vessels] will connect to Link 16 and all C2 systems at the strategic level,” Lwin added. </p>



<p class="wp-block-paragraph"><b>Undersea experiments</b></p>



<p class="wp-block-paragraph">The JRE has seen investments over the last two years to expand its cloud-based capabilities, but the communications infrastructure already offers robust opportunities for autonomous technology, Supplee told Defense News.</p>



<p class="wp-block-paragraph">For example, both companies have already partnered to test technology using undersea vessels, which they believe they can potentially expand. “We’ve experimented with it. We believe it can be used prolifically. The communications can work today,” Supplee said. </p>



<p class="wp-block-paragraph">Lwin said that HavocAI’s use of Starlink can expand the potential of the autonomous surface vessels to communicate with underwater systems. “We can put acoustic modems on our vessels and allow them to communicate with undersea vessels,” he said. </p>



<p class="wp-block-paragraph"><b>Potential areas of operations</b></p>



<p class="wp-block-paragraph">The vessels’ new link-up to the military’s premier C2 infrastructure is hoped to strengthen the Navy’s hybrid fleet and project U.S. seapower in contested areas, such as near the Philippines.</p>



<p class="wp-block-paragraph">“We believe that this partnership is going to help the Navy realize its vision of thousands of these small USV capable platforms of operating in tandem hybridity in these contested environments,” Supplee said.</p>



<p class="wp-block-paragraph">“With autonomous systems, you want to remove humans from danger,” Lwin said. “You can send thousands of these out with their sensors, figure out what’s going on in these island chains and send that information back to the crews without putting humans at risk.”</p>



<p class="wp-block-paragraph">The vessels could potentially be used in the Arctic as well, Lwin told Defense News. </p>



<p class="wp-block-paragraph"><b>Future uses</b></p>



<p class="wp-block-paragraph">Both companies hope that being proactive in combining their strengths will not only expand their technology currently being used in the field but open up new possibilities, they said. </p>



<p class="wp-block-paragraph">“We’re working to solve the problem at hand in advance of even the requirement so that we can help the Navy scale where it’s needed,” Supplee said. </p>



<p class="wp-block-paragraph">HavocAI said that the vessels are easy to manufacture and could be produced en masse quickly over the next few years if needed. </p>



<p class="wp-block-paragraph">“We want to be able to get the U.S. Navy the option right now to deploy thousands of these,” Lwin said. ”What we’re building right now is no longer science fiction. We’re showing with SAIC you can integrate them right now and start to use them as weapons systems right away.” </p>
]]></content:encoded>
	</item>
		<item>
		<title>How to establish an effective data management governance program</title>
		<link>https://one.sightlinemg.com/federaltimes/opinions/2024/07/10/how-to-establish-an-effective-data-management-governance-program/</link>
					<comments>https://one.sightlinemg.com/federaltimes/opinions/2024/07/10/how-to-establish-an-effective-data-management-governance-program/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Wed, 10 Jul 2024 20:15:09 +0000</pubDate>
				<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Home]]></category>
		<category><![CDATA[Inside the Agencies]]></category>
		<category><![CDATA[IT & Networks]]></category>
		<category><![CDATA[Opinion]]></category>
		<category><![CDATA[opinion]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2024/07/10/how-to-establish-an-effective-data-management-governance-program/</guid>

					<description><![CDATA[A compliance program should be able to clearly articulate the criteria for evaluating success, highlighting the technology or processes required.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/opinions/2024/07/10/how-to-establish-an-effective-data-management-governance-program/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">27951</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/GettyImages-1046888894.jpg.jpg" width="3484" height="3071" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">In Part 1 of a two-part series on how federal agencies can adopt improved data management programs, Joah Iannotta Senior Data Governance Expert at <a href="https://www.abs-group.com/" target="_blank">ABSG Consulting Inc</a>., looks at the importance of combining policy with a well-planned compliance and evaluation program and the risk to an agency of not taking this approach.</p>



<p class="wp-block-paragraph">&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>



<p class="wp-block-paragraph">Failing to ensure compliance with new requirements can magnify gaps and weaknesses for auditors, akin to writing the organization’s next audit findings and delivering them to its Inspector General with a neat bow on top.</p>


	<aside class="smg-interstitial-link wp-block-smg-interstitial-link">
		<a href="https://one.sightlinemg.com/c4isrnet/cyber/2024/07/08/pentagon-zero-trust-office-aims-to-start-data-tagging-labeling-in-24/" class="smg-interstitial-link__inner">
							<div class="smg-interstitial-link__media">
					<img decoding="async" width="300" height="300" src="https://one.sightlinemg.com/wp-content/uploads/2026/08/GettyImages-667221538.jpg.jpg?w=300" class="smg-interstitial-link__image wp-post-image" alt="" />				</div>
						<div class="smg-interstitial-link__content">
				<span class="smg-interstitial-link__kicker">Related</span>
				<h3 class="smg-interstitial-link__title">Pentagon zero-trust office aims to start data tagging, labeling in ′24</h3>
									<p class="smg-interstitial-link__excerpt">The Defense Department is seeking to demo a solution, even an imperfect one, to a longstanding problem.</p>
							</div>
		</a>
	</aside>
	


<p class="wp-block-paragraph">Agencies often view the creation of <a href="https://www.federaltimes.com/it-networks/2023/11/28/ai-can-shore-up-federal-cybersecurity-overwhelmed-by-data-gdit-says/" target="_blank">policy, directives, guidance, and instructions</a> as a self-contained task. Policy shops are established, and their measure of success often is the publication of a number of policy documents. Once a policy is published, the lines of business are left to interpret the policy and develop implementation solutions from the ground up. When looking at the federal government, policy shops can tend to take a hands-off approach to implementation, on the basis that it is best to provide the program with maximum flexibility to implement policy in a way that best suits their organization.</p>



<p class="wp-block-paragraph">This approach very much emulates the relationship between the federal government and states, where the federal government sets a policy and program directive but allows the states wide latitude for implementation. This approach allows states to innovate and test approaches that suit their demography, culture, and particular needs, which can result in successful pilot programs being adopted and adapted by other states.</p>



<p class="wp-block-paragraph">However, this process can take time and result in failed experiments. While this type of incubation can be beneficial for creating <a href="https://www.federaltimes.com/veterans/2018/07/25/house-approves-plans-to-create-new-va-economic-opportunity-administration/" target="_blank">large scale social and economic programs</a>, it’s not necessarily the most efficient way to implement enterprise data governance policy.</p>



<p class="wp-block-paragraph">Most organizations are driven to revamp or create a new enterprise data governance policy because there has been an abundance of innovation, new solutions, and problem-solving at the “State” level within the organization, with the agency beginning to feel the pain of the proliferation of data-oriented solutions.</p>



<h2 class="wp-block-heading">Ungoverned data</h2>



<p class="wp-block-paragraph">For example, one source of pain is that, at a certain point, the proliferation of ungoverned data and data solutions can actually hinder an agency’s maturation towards becoming data-driven.</p>



<p class="wp-block-paragraph">Consider two different grant programs designing solutions to capture applicant information in an environment which lacks an effective data management policy and a compliance program to hold programs accountable.</p>



<p class="wp-block-paragraph">The grant programs develop their solution to capture customer data separately in their own silo, and these two different solutions are unlikely to develop the same data standards, data naming conventions, or other aspects of data management that would allow the two programs to integrate easily.</p>



<p class="wp-block-paragraph">As a consequence, analyzing grant data from the programs for insights on important factors that could make both programs more effective (such as identifying risk indicators that a grantee will fail to deliver) can become significantly more difficult and time consuming.</p>



<p class="wp-block-paragraph">In this situation, most agencies wanting to adopt data-driven decision-making will turn to creating an analytical platform where data from both programs can be transformed, cleansed, standardized, and integrated. However, this means the development of another data solution with a cadre of data scientists required to curate and normalize the data, which in turn is likely to require a new budget item and new hiring.</p>



<h2 class="wp-block-heading">Siloed technologies</h2>



<p class="wp-block-paragraph">A second source of pain in an organization with ungoverned data solutions is that the costs of maintaining and supporting these siloed technologies can increase exponentially over time.</p>



<p class="wp-block-paragraph">Tighter budgets can hinder improvements, debugging, and sometimes basic maintenance, resulting in increasingly poor customer delivery. At this point, the agency may also have realized that while the subject matter of the programs is different, there are significant commonalities among the data services provided that could be streamlined—for example, multiple programs capturing customer data, managing cases, processing benefits applications, and accepting or delivering payments.</p>



<p class="wp-block-paragraph">Under pressure to reduce costs and improve service, the agency begins looking for ways to centralize its data solutions, only to discover that doing so is expensive, complex, and few of their peer agencies have completed such projects on time and on budget.</p>



<p class="wp-block-paragraph">Integrating data solutions is significantly more difficult when solutions develop in the absence of an overarching data governance policy and compliance program to help ensure that, as solutions emerge, they are growing in a manner that will be sustainable.</p>



<p class="wp-block-paragraph">Establishing an enterprise data governance policy is a good first step to bring consistency, interoperability, and other benefits to a data ecosystem, but programs will need to effectively implement that policy in order to create a healthy and sustainable data environment.</p>



<p class="wp-block-paragraph">Furthermore, if the governance program stops with policy and guidance that merely establishes high-level principles such as “new and existing data systems must adopt standards to ensure data interoperability,” then it is not likely that an actual change will occur in organizational processes or staff behavior.</p>



<p class="wp-block-paragraph">Sticking with the grant example, for a data governance program to be more effective, it would need to take an active role in designing standards that could work for both grant programs, facilitating discussions and brokering an agreement on the standards for specific required data elements.</p>



<p class="wp-block-paragraph">It would also need a compliance program with a deadline by which the standards must be adopted to help ensure that those standards were actually being implemented.</p>



<h2 class="wp-block-heading">Effective compliance</h2>



<p class="wp-block-paragraph">Successful data governance policy programs integrate policy into implementation by using their compliance program as the bridge between policy principles and driving change in data management practice.</p>



<p class="wp-block-paragraph">Compliance programs achieve this in part by painting a clear picture of what implementation looks like, and does this by establishing concrete expectations of what will be considered successful compliance with policy.</p>



<p class="wp-block-paragraph">For example, if a data governance policy included a principle of strengthening data quality, the compliance document could articulate that lines of business must establish specific parameters for monitoring data quality aligned with the needs of the program they serve.</p>



<p class="wp-block-paragraph">A data quality parameter that the compliance program establishes could be that grant recipient payee data will have less than 1 percent of missing values to help ensure timely and accurate delivery of payments.</p>



<p class="wp-block-paragraph">An effective compliance program should be able to envision a path to evaluate successful compliance. If it cannot do that or needs to rely on a program official’s attestation of compliance, then it is not reasonable to expect the lines of business could comply with a policy directive on their own.</p>



<p class="wp-block-paragraph">These expectations should be published as part of a compliance policy or procedure so that the lines of business have a yardstick by which to measure their efforts. Ideally, this should focus on the changes the lines of business would need to implement.</p>



<p class="wp-block-paragraph">For example, a policy principle related to data quality as data is moved across an enterprise might state that data must be complete and maintain its integrity as it moves from one system to another or ingested from an outside source. The compliance program could set criteria that data must be monitored for completeness and integrity such as not incurring any unintended transformations.</p>



<p class="wp-block-paragraph">The compliance program would further identify any technology performing data movement (including automated data quality monitoring) that would meet this compliance standard, as well as alternative processes a program could implement that would constitute appropriate monitoring of data movement.</p>



<p class="wp-block-paragraph">This type of information not only paints a clear picture for the program of how they can comply, but also gives them enough information to assess how much effort the program will need to meet the compliance criteria.</p>



<h2 class="wp-block-heading">‘Easy path’</h2>



<p class="wp-block-paragraph">It is worth noting that the technology and processes cited by a compliance program do not mean that other solutions a program may develop to demonstrate compliance are not to be considered. Rather, the cited technology and process can be examples of an “easy path” to compliance that programs can either adopt or know they already have in place.</p>



<p class="wp-block-paragraph">In situations where a program develops an alternative approach, the compliance program could evaluate that approach against its criteria—in this case being able to demonstrate that data is moving completely and with integrity.</p>



<p class="wp-block-paragraph">If the evaluation finds that the program has developed an effective approach, this approach can be added to the compliance program’s list of accepted technologies or processes and shared with other programs as a best practice or, if you will, an additional “easy path” to compliance.</p>



<p class="wp-block-paragraph">When data governance policy is completed with the publication of a policy document, they can leave program and business leads without direction on prioritization, timelines, and the necessary level of effort and resources needed for implementation.</p>



<p class="wp-block-paragraph">In many cases, the absence of this information can cause what was previously a willing coalition of business support for better data governance to get cold feet and hinder the passage of new data policies.</p>



<p class="wp-block-paragraph">A compliance program can help program and business leads set priorities, determine timelines, and plan resources to ensure compliance by adopting and publishing clear criteria for what compliance looks like, as well as a risk-based schedule for its compliance reviews and setting.</p>



<p class="wp-block-paragraph">Reducing uncertainty for programs regarding how they will be evaluated and what will constitute successful compliance will not only keep a coalition supporting data governance together, but will also drive implementation and change.</p>



<p class="wp-block-paragraph"><i>Joah Iannotta is Senior Data Governance Expert at ABSG Consulting Inc. Part 2 of this series will explore the practices that data governance compliance programs can adopt to help drive change management.</i></p>
]]></content:encoded>
	</item>
		<item>
		<title>Securing the backbone of our nation: critical infrastructure</title>
		<link>https://one.sightlinemg.com/federaltimes/opinions/2024/06/25/securing-the-backbone-of-our-nation-critical-infrastructure/</link>
					<comments>https://one.sightlinemg.com/federaltimes/opinions/2024/06/25/securing-the-backbone-of-our-nation-critical-infrastructure/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Tue, 25 Jun 2024 15:44:53 +0000</pubDate>
				<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Home]]></category>
		<category><![CDATA[IT & Networks]]></category>
		<category><![CDATA[Opinion]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2024/06/25/securing-the-backbone-of-our-nation-critical-infrastructure/</guid>

					<description><![CDATA[Collaboration can minimize the risk of cyberattacks on U.S. critical infrastructure.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/opinions/2024/06/25/securing-the-backbone-of-our-nation-critical-infrastructure/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">27918</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/GettyImages-1755800777.jpg.jpg" width="4032" height="2268" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">In the wake of escalating threats to critical sectors, such as the discovery of <a href="https://www.c4isrnet.com/cyber/2024/04/30/volt-typhoon-hacks-likely-to-inspire-copycats-cnmfs-mahlock-says/">Volt Typhoon</a>, government officials are sounding the alarm over the unprecedented risk of potential mass disruption to our country – including Jen Easterly, Director of the Cybersecurity and Infrastructure Security Agency, <a href="https://www.scmagazine.com/news/chinas-attacks-on-critical-infrastructure-tip-of-the-iceberg">who described these attacks</a> as “the most serious threat to the nation.”</p>



<p class="wp-block-paragraph">Recognizing that critical infrastructure owners and operators often lack significant resources and struggle to implement basic cyber protocols, the federal government is prioritizing protecting this sector, with the new <a href="https://www.whitehouse.gov/briefing-room/presidential-actions/2024/04/30/national-security-memorandum-on-critical-infrastructure-security-and-resilience/">National Security Memorandum</a> on Critical Infrastructure and updated <a href="https://www.whitehouse.gov/wp-content/uploads/2024/05/National-Cybersecurity-Strategy-Implementation-Plan-Version-2.pdf">National Cybersecurity Strategy Implementation Plan</a>.</p>



<p class="wp-block-paragraph">Federal agencies need to serve as role models for secure and resilient systems by bridging the gap between outdated technology and modern security processes; lest critical infrastructure sectors remain easy targets and the prospect of devastating disruptions to essential services will grow.</p>



<h1 class="wp-block-heading"><b>Back to basics</b></h1>



<p class="wp-block-paragraph">To protect critical infrastructure, a vital part of the NSM and <a href="https://therecord.media/anne-neuberger-interview-deputy-national-security-adviser-cyber">other federal plans</a> that involve sector risk management is “ensuring critical services have minimum cybersecurity practices in place.” Existing protections and processes have been unable to keep up with a mushrooming attack surface due to resource constraints, which means critical infrastructure owners and operators need to be in alignment with the federal government.</p>



<p class="wp-block-paragraph">With 85 percent of critical infrastructure owned or operated by <a href="https://cdn.govexec.com/media/gbc/docs/gbc_boozallen_smartdata_ib_designed_final.pdf">the private sector</a>, public-private collaboration has now become a necessity in order to establish minimum requirements and help critical infrastructure organizations achieve basic cyber hygiene.</p>



<p class="wp-block-paragraph">Greater collaboration with the private sector can also help ease the gaps in resources and expertise needed to address the challenges associated with growing and more sophisticated cyber threats.</p>



<p class="wp-block-paragraph">The updated NCSIP <a href="https://govciomedia.com/cyber-strategy-2-0-stresses-critical-infrastructure-protections/">emphasizes</a> that in order for the federal digital ecosystem and critical infrastructure stakeholders to grow their cyber posture, they need to share information and best practices. This is a cornerstone of a whole-of-government cybersecurity approach where federal, state, and local governments collaborate closely with private industries to create a unified cybersecurity framework.</p>



<p class="wp-block-paragraph">Sharing information and best practices facilitates open and transparent communications between public and private sectors, enabling quicker dissemination of threat intelligence, streamlined responses, reduced downtime, and more agile operations.</p>



<p class="wp-block-paragraph">Not only does this approach break down inefficient, risky silos, but it also allows for a unified response to cyber incidents and the pooling of resources, expertise, and intelligence for real-time sharing and faster decision-making.</p>



<h1 class="wp-block-heading"><b>Accelerating digital modernization</b></h1>



<p class="wp-block-paragraph">The combination of insecure internet-facing connections, legacy tech, and traditional security approaches make critical infrastructure easy targets for malicious actors. Improving critical infrastructure resilience is more than just IT and security; it’s about looking at the bigger picture to reduce downtime and risk to people and property.</p>



<p class="wp-block-paragraph">The federal government should continue pushing technology developers to use <a href="https://www.cisa.gov/securebydesign">secure-by-design tactics</a>, ensuring “out of the box” security and significantly reducing the strain placed on infrastructure owners and operators.</p>



<p class="wp-block-paragraph">In addition, the adoption of zero trust architectures emerges as a crucial step to harden remote access to <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-265a">industrial control systems (ICS)</a> that rely on a mix of IT and operational technology (OT) assets.</p>



<p class="wp-block-paragraph">Zero trust is inherently designed to reduce a network’s attack surface, prevent lateral movement of threats, and lower the risk of a data breach. This model leverages least-privileged access controls, granular microsegmentation, and multifactor authentication (MFA) to provide continuous verification of identities and devices, regardless of location, type, or network connection. Crucially, these controls are dynamic and happening continuously.</p>



<p class="wp-block-paragraph">Historically, OT assets were not designed with security in mind. And almost always, Internet of Things (IoT) devices cannot be modified to accommodate security stack: software, agent, etc. But most critical infrastructure organizations still depend on these antiquated technologies to monitor and control industrial processes.</p>



<p class="wp-block-paragraph">Considering the unique nature of OT assets, coupled with their specific requirements for operational safety and reliability, owners and operators have strong business justifications for operating older equipment that are incompatible with zero trust security.</p>



<p class="wp-block-paragraph">Yet, in the absence of zero trust capabilities, these assets have become key attack vectors for malicious actors. While IoT devices may not be the first compromised, they become a “land bridge,” often allowed through by traditional firewalls, to critical backend servers and data centers. Secure digital modernization is therefore essential.</p>



<h1 class="wp-block-heading"><b>Overcoming challenges</b></h1>



<p class="wp-block-paragraph">When it comes to critical infrastructure, the risks are limitless, but the resources aren’t.</p>



<p class="wp-block-paragraph">Requiring and enforcing minimum resilience and security requirements, as well as encouraging minimum cyber hygiene requirements and information-sharing, reinforce that safeguarding national infrastructure is a shared responsibility.</p>



<p class="wp-block-paragraph">While OT presents challenges to implementing zero trust and modern security, a whole-of-government approach in support of greater collaboration, modern technology with zero trust capabilities, standardization, and accountability – is the only way to secure our critical infrastructure ecosystem and mitigate the risk of disruptive and destructive cyberattacks.</p>



<p class="wp-block-paragraph"><i>Hansang Bae is Public Sector Chief Technology Officer at Zscaler, a California-based cloud security company.</i></p>
]]></content:encoded>
	</item>
		<item>
		<title>Know your customer – as long as it’s not China</title>
		<link>https://one.sightlinemg.com/federaltimes/opinions/2024/04/18/know-your-customer-as-long-as-its-not-china/</link>
					<comments>https://one.sightlinemg.com/federaltimes/opinions/2024/04/18/know-your-customer-as-long-as-its-not-china/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Thu, 18 Apr 2024 20:02:42 +0000</pubDate>
				<category><![CDATA[Artificial Intelligence]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Home]]></category>
		<category><![CDATA[Inside the Agencies]]></category>
		<category><![CDATA[IT & Networks]]></category>
		<category><![CDATA[Leadership]]></category>
		<category><![CDATA[Opinion]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2024/04/18/know-your-customer-as-long-as-its-not-china/</guid>

					<description><![CDATA[A proposed 'Know Your Customer' rule seeks to stop adversaries from getting their hands on advanced U.S. cloud and AI technologies.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/opinions/2024/04/18/know-your-customer-as-long-as-its-not-china/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">27379</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/635974226572691762-chinese-us-flagjpg.jpg" width="3000" height="2176" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">Secretary of Commerce Gina Raimondo made American policy clear this week when discussing the role major technology companies have to play in the United States’ strategic competition with China.</p>



<p class="wp-block-paragraph">“When it comes to emerging technology,” she<a href="https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.nytimes.com%2F2024%2F04%2F16%2Fbusiness%2Fdealbook%2Fwashington-microsoft-ai-deal.html&#038;data=05%7C02%7Ccary.oreilly%40mco.com%7Cde69e9cab0f04dfdfcc208dc5fa36a8e%7C1d5c96e57ee2446dbed8d0f8c50edea5%7C1%7C1%7C638490402719995802%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&#038;sdata=HSkbwsCUwRCLsTKnwTvsmLSB7pReQvtjk%2BF4m0%2Bj4IE%3D&#038;reserved=0"> said</a>, “you cannot be both in China’s camp and our camp.”</p>



<p class="wp-block-paragraph">Those are powerful words as the secretary’s agency seeks comments on a proposed Know-Your-Customer, or KYC, <a href="https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Faboutbgov.com%2Fbct3&#038;data=05%7C02%7Ccary.oreilly%40mco.com%7Cde69e9cab0f04dfdfcc208dc5fa36a8e%7C1d5c96e57ee2446dbed8d0f8c50edea5%7C1%7C1%7C638490402720007037%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&#038;sdata=yUPSzOqfsy8QGhOtJPrlLGnjcvizGIQywmLlJ0q%2BnbU%3D&#038;reserved=0">rule</a> designed to keep valuable U.S. technology out of the hands of countries like China and Russia. In that spirit, one critical concern should be closing a significant loophole in the proposed rule that would allow some of the U.S. government’s largest cloud service providers to continue pursuing profits in China at the risk of compromising U.S. national security.</p>



<p class="wp-block-paragraph">Commerce’s proposed rule would require U.S. cloud companies to identify and disclose instances where “foreign malicious actors” might use their products and services to undermine national security. It would also authorize the U.S. government to audit companies’ processes and procedures in these instances and recommend/enforce remediation measures to prevent future issues.</p>



<p class="wp-block-paragraph">Where the Commerce rule falls short is the exemption of independent subsidiaries that operate as overseas arms of U.S. companies. Even if the proposed rule compels Microsoft or Amazon to proactively shrink their operations in China to avoid long, drawn out audits, their de-facto foreign subsidiaries will allow them to continue profiting off the sale of products and services to the Chinese government. The KYC rule may paradoxically help the Chinese by making it harder for the U.S. government to know the details of some U.S. cloud providers’ customers and operations in China. This omission is not consistent with the overall goal of the KYC rule to enhance national security .</p>



<p class="wp-block-paragraph">Companies have faced few repercussions for allowing China and other adversaries to use their advanced technologies <a href="https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fthehill.com%2Fopinion%2Ftechnology%2F4532937-big-techs-trouble-in-china-new-work-secrets-law-could-force-tough-choices%2F%23%3A~%3Atext%3DNow%252C%2520a%2520revision%2520to%2520China%2527s%2Crelevant%2520to%2520its%2520national%2520security.&#038;data=05%7C02%7Ccary.oreilly%40mco.com%7Cde69e9cab0f04dfdfcc208dc5fa36a8e%7C1d5c96e57ee2446dbed8d0f8c50edea5%7C1%7C1%7C638490402720017011%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&#038;sdata=fokzdoL3JG7BDIku285jWDFFU%2FX8vxneU%2BUZPOMwP%2Fs%3D&#038;reserved=0">to undermine U.S. interests</a>. That’s despite <a href="https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fnypost.com%2F2024%2F03%2F23%2Fbusiness%2Fmicrosofts-china-business-poses-national-security-risks-gop-rep-fallon%2F&#038;data=05%7C02%7Ccary.oreilly%40mco.com%7Cde69e9cab0f04dfdfcc208dc5fa36a8e%7C1d5c96e57ee2446dbed8d0f8c50edea5%7C1%7C1%7C638490402720027698%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&#038;sdata=R%2FFYtw8hFyIP%2F00kOO8JERnGz%2F3tETi3AjE4bUXWB9Y%3D&#038;reserved=0">mounting criticism in Washington</a> –While the proposed rule aims to address these risks, it can’t be truly effective unless it scrutinizes the murky relationships U.S. cloud companies enter into with foreign-owned companies.</p>



<p class="wp-block-paragraph">One example is 21Vianet which <a href="https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.theregister.com%2F2023%2F04%2F03%2Fmicrosoft_teams_come_to_china%2F&#038;data=05%7C02%7Ccary.oreilly%40mco.com%7Cde69e9cab0f04dfdfcc208dc5fa36a8e%7C1d5c96e57ee2446dbed8d0f8c50edea5%7C1%7C1%7C638490402720037517%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&#038;sdata=onSV99DKt6z3bJsgX%2Fht3slNdX9v4CMZ2WamYMoRfa4%3D&#038;reserved=0">serves China’s government</a>, <a href="https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.uscc.gov%2Fsites%2Fdefault%2Ffiles%2FResearch%2FDGI_Red%2520Cloud%2520Rising_2014.pdf&#038;data=05%7C02%7Ccary.oreilly%40mco.com%7Cde69e9cab0f04dfdfcc208dc5fa36a8e%7C1d5c96e57ee2446dbed8d0f8c50edea5%7C1%7C1%7C638490402720047149%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&#038;sdata=pMerRr2U9aVWcojNp6HqAnaTd2EKN0YA5cF1GbKbaJE%3D&#038;reserved=0">enables its military, and aids and abets its oppressive surveillance regime</a>. 21Vianet, is a Chinese company operated by the holding company <a href="https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fir.21vianet.com%2Fsec-filings%2Fsec-filing%2F20-f%2F0001104659-22-050369&#038;data=05%7C02%7Ccary.oreilly%40mco.com%7Cde69e9cab0f04dfdfcc208dc5fa36a8e%7C1d5c96e57ee2446dbed8d0f8c50edea5%7C1%7C1%7C638490402720056798%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&#038;sdata=fQ4LiNrDzzXXG4tu3Q9xGwBAuIlcAokGFFVzHodm4f8%3D&#038;reserved=0">VNET Group, Inc.</a>, and is the <a href="https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.marketscreener.com%2Fquote%2Fstock%2FVNET-GROUP-INC-7855123%2Fnews%2FMicrosoft-Corporation-and-21Vianet-Group-Inc-Announce-Licensing-Agreement-39225906%2F&#038;data=05%7C02%7Ccary.oreilly%40mco.com%7Cde69e9cab0f04dfdfcc208dc5fa36a8e%7C1d5c96e57ee2446dbed8d0f8c50edea5%7C1%7C1%7C638490402720066392%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&#038;sdata=tZ9HB8XtplM%2FlibZb44Ovech5vw1uhVUMBywWHeU%2Bmo%3D&#038;reserved=0">exclusive</a>operator of Microsoft’s cloud computing platforms in China. 21Vianet brought Microsoft’s <a href="https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.azure.cn%2F&#038;data=05%7C02%7Ccary.oreilly%40mco.com%7Cde69e9cab0f04dfdfcc208dc5fa36a8e%7C1d5c96e57ee2446dbed8d0f8c50edea5%7C1%7C1%7C638490402720076103%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&#038;sdata=8%2F3tGyK53ADXXAYxvtVsan8tg3hXlDGIU72U5XZhMXY%3D&#038;reserved=0">Azure cloud platform</a> to China and has expanded its services to the <a href="https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fnews.microsoft.com%2Fzh-cn%2F%25E7%2594%25B1%25E4%25B8%2596%25E7%25BA%25AA%25E4%25BA%2592%25E8%2581%2594%25E8%25BF%2590%25E8%2590%25A5%25E7%259A%2584microsoft-teams%25E6%2590%25BA%25E5%2588%259B%25E6%2596%25B0%25E5%258A%259F%25E8%2583%25BD%25E6%25AD%25A3%25E5%25BC%258F%25E5%258F%2591%25E5%25B8%2583%25EF%25BC%258C%25E5%25A4%25AF%25E5%25AE%259E%2F&#038;data=05%7C02%7Ccary.oreilly%40mco.com%7Cde69e9cab0f04dfdfcc208dc5fa36a8e%7C1d5c96e57ee2446dbed8d0f8c50edea5%7C1%7C1%7C638490402720085290%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&#038;sdata=H9UT0BdKmTeNoXQV2lYSuaS4sJrh72U0GUtyIGVAF7w%3D&#038;reserved=0">Chinese government</a>, operating as a Microsoft subsidiary in virtually every function but its name.</p>



<p class="wp-block-paragraph">Amazon operates similar partnerships, including with <a href="https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fpartners.amazonaws.com%2Fpartners%2F0010L00001rCaF1QAK%2FNingxia%2520Western%2520Cloud%2520Data%2520Technology%2520Co.Ltd&#038;data=05%7C02%7Ccary.oreilly%40mco.com%7Cde69e9cab0f04dfdfcc208dc5fa36a8e%7C1d5c96e57ee2446dbed8d0f8c50edea5%7C1%7C1%7C638490402720095866%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&#038;sdata=uWxhoMSMgovioh%2BvTSZRjCLZkC4LZ4zKkL0vIvXV5z0%3D&#038;reserved=0">Ningxia Western Cloud Data Technology Co.</a>, which is partially state-owned. Through the company, <a href="https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.amazonaws.cn%2Fen%2Fnew%2F2017%2Fwhats-new-announcing-partnership-between-aws-and-nwcd-availability-of-ningxia-region%2F&#038;data=05%7C02%7Ccary.oreilly%40mco.com%7Cde69e9cab0f04dfdfcc208dc5fa36a8e%7C1d5c96e57ee2446dbed8d0f8c50edea5%7C1%7C1%7C638490402720105951%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&#038;sdata=pn2IsvFRItCFPai3y%2FtXqhu3Ne7vTLxxSDz4QbdQ2yM%3D&#038;reserved=0">AWS</a> delivers <a href="https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fspacenews.com%2Fchinese-commercial-rocket-firm-launches-26-satellites-sets-national-record%2F&#038;data=05%7C02%7Ccary.oreilly%40mco.com%7Cde69e9cab0f04dfdfcc208dc5fa36a8e%7C1d5c96e57ee2446dbed8d0f8c50edea5%7C1%7C1%7C638490402720116337%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&#038;sdata=FbpDVxkzru1j%2FFkK%2FPUQzgHdbkJ0ZR8DJn989AG8jX0%3D&#038;reserved=0">cloud services</a> for Chinese state and defense agencies, yet another example of a China-based company that exists only to sell the products of a single U.S. tech company and operates almost entirely at the direction of its U.S. tech “partner.”</p>



<p class="wp-block-paragraph">Despite their vast presence and robust partner networks in China, U.S. cloud companies are all too aware of – and public about – the risks that China and our other adversaries pose to U.S. national security. And the technology being marketed by U.S. companies in China is enabling the country to attack U.S. interests.</p>



<p class="wp-block-paragraph">Recently, Microsoft disclosed that it has <a href="https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.reuters.com%2Ftechnology%2Fcybersecurity%2Fmicrosoft-says-it-caught-hackers-china-russia-iran-using-its-ai-tools-2024-02-14%2F&#038;data=05%7C02%7Ccary.oreilly%40mco.com%7Cde69e9cab0f04dfdfcc208dc5fa36a8e%7C1d5c96e57ee2446dbed8d0f8c50edea5%7C1%7C1%7C638490402720126635%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&#038;sdata=8D7JehB%2BVx%2BpZAYGL8tT9ZaFWl8Mnk2AySV9Bu3FRzI%3D&#038;reserved=0">caught</a> China, Russia and Iran using its AI tools to hone malicious hacking campaigns and <a href="https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fcyberscoop.com%2Fmicrosoft-ai-election-taiwan%2F&#038;data=05%7C02%7Ccary.oreilly%40mco.com%7Cde69e9cab0f04dfdfcc208dc5fa36a8e%7C1d5c96e57ee2446dbed8d0f8c50edea5%7C1%7C1%7C638490402720136644%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&#038;sdata=eO9zaX3kHFVgDmGYEEf6vTNQKuSpqyNiBY5r9YUf9FY%3D&#038;reserved=0">warned</a> that China may use its AI technology to influence the 2024 election. Both <a href="https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fapnews.com%2Farticle%2Fmicrosoft-russian-hack-email-svr-breach-edc1acfc23827e5ae24cce69b95dde4d&#038;data=05%7C02%7Ccary.oreilly%40mco.com%7Cde69e9cab0f04dfdfcc208dc5fa36a8e%7C1d5c96e57ee2446dbed8d0f8c50edea5%7C1%7C1%7C638490402720146565%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&#038;sdata=0SormhuWwwNJDhRPILtNN%2F8Bj9m9ADVoLuEL%2Fyh8uzs%3D&#038;reserved=0">Microsoft</a> and <a href="https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.darkreading.com%2Fvulnerabilities-threats%2Fscarleteel-hackers-worm-into-aws-cloud&#038;data=05%7C02%7Ccary.oreilly%40mco.com%7Cde69e9cab0f04dfdfcc208dc5fa36a8e%7C1d5c96e57ee2446dbed8d0f8c50edea5%7C1%7C1%7C638490402720156377%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&#038;sdata=D15v%2B%2FBus%2BnNZ0M5s7tLtsYM9urHbiDtuOItywkZhc0%3D&#038;reserved=0">Amazon</a>have repeatedly <a href="https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.washingtonpost.com%2Ftechnology%2F2024%2F03%2F08%2Fmicrosoft-hack-email-russia%2F&#038;data=05%7C02%7Ccary.oreilly%40mco.com%7Cde69e9cab0f04dfdfcc208dc5fa36a8e%7C1d5c96e57ee2446dbed8d0f8c50edea5%7C1%7C1%7C638490402720165843%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&#038;sdata=BaMpDqVTSrfm76mtYf3G26gWsXRK0bHNj%2F8bBwaMolk%3D&#038;reserved=0">warned</a> about increasing sophistication of hackers from the likes of Russia and <a href="https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.cnbc.com%2F2023%2F05%2F24%2Fmicrosoft-warns-that-china-hackers-attacked-us-infrastructure.html%23%3A~%3Atext%3DMicrosoft%2520warned%2520Wednesday%2520that%2520Chinese%2CMicrosoft%2520said%2520in%2520an%2520advisory.&#038;data=05%7C02%7Ccary.oreilly%40mco.com%7Cde69e9cab0f04dfdfcc208dc5fa36a8e%7C1d5c96e57ee2446dbed8d0f8c50edea5%7C1%7C1%7C638490402720175426%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&#038;sdata=bwOV%2B9ggmxVkvrhupYAsnm0osqZUnocy3BdGH6UpmVU%3D&#038;reserved=0">China</a>.</p>



<p class="wp-block-paragraph">Last year, the <a href="https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.americansecurityproject.org%2Fwp-content%2Fuploads%2F2023%2F10%2FRef-0287-Code-War-How-Chinas-AI-Ambitions-Threaten-US-National-Security.pdf&#038;data=05%7C02%7Ccary.oreilly%40mco.com%7Cde69e9cab0f04dfdfcc208dc5fa36a8e%7C1d5c96e57ee2446dbed8d0f8c50edea5%7C1%7C1%7C638490402720185508%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&#038;sdata=o7cy1yOE1iU30nTABNmyeyn4P1wQ0nd37C0XHTb2IoI%3D&#038;reserved=0">American Security Project</a> released a report detailing the sprawling web of exclusive, independent partners and affiliates that Microsoft, Amazon, other U.S. companies like Oracle, use to sell their products in mainland China, including to the Chinese government and its military.</p>



<p class="wp-block-paragraph">The structures of these arrangements are intentionally murky, strategically employed by the companies to avoid U.S. regulations while complying with China’s increasingly stringent laws governing foreign-owned companies. The partners – de-facto Microsoft and Amazon subsidiaries – are prone to <a href="https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.securityweek.com%2Fmicrosoft-china-flaw-disclosure-law-part-zero-day-exploit-surge%2F&#038;data=05%7C02%7Ccary.oreilly%40mco.com%7Cde69e9cab0f04dfdfcc208dc5fa36a8e%7C1d5c96e57ee2446dbed8d0f8c50edea5%7C1%7C1%7C638490402720195432%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&#038;sdata=uXWrEz1IRHQdVXkTcnyjgpK5EGRROUYf%2FpOSfpEr3XA%3D&#038;reserved=0">cyber intrusion</a> because of source code and vulnerability disclosure requirements and <a href="https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fthehill.com%2Fopinion%2Ftechnology%2F4532937-big-techs-trouble-in-china-new-work-secrets-law-could-force-tough-choices%2F&#038;data=05%7C02%7Ccary.oreilly%40mco.com%7Cde69e9cab0f04dfdfcc208dc5fa36a8e%7C1d5c96e57ee2446dbed8d0f8c50edea5%7C1%7C1%7C638490402720205401%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&#038;sdata=70fCZO%2BhriY8esD7a65vMDOrMFXWooVx1AZeX4sIilU%3D&#038;reserved=0">compliance</a> with arbitrary “state secrets” laws that are known to have compromised the U.S. government’s data security.</p>



<p class="wp-block-paragraph">The proposed KYC rule seeks to directly address such issues by stopping adversaries from getting their hands on advanced U.S. cloud and AI technologies. Regulators cannot miss this opportunity to compel Microsoft, Amazon and their peers to prioritize U.S. interests instead of chasing profits with our adversaries. If not now, when? We must act before it’s too late.</p>



<p class="wp-block-paragraph"><i>Paul Rosenzweig is the founder of Red Branch Consulting PLLC, a homeland security and cybersecurity consulting company, and a Senior Advisor to The Chertoff Group. Mr. Rosenzweig formerly served as Deputy Assistant Secretary for Policy in the Department of Homeland Security. He is currently a Professorial Lecturer in Law at George Washington University, and a Senior Fellow in the Tech, Law &amp; Security Program at the American University, Washington College of Law.</i></p>
]]></content:encoded>
	</item>
		<item>
		<title>How to boost customer experience with secure cross-agency data sharing</title>
		<link>https://one.sightlinemg.com/federaltimes/opinions/2024/04/15/how-to-boost-customer-experience-with-secure-cross-agency-data-sharing/</link>
					<comments>https://one.sightlinemg.com/federaltimes/opinions/2024/04/15/how-to-boost-customer-experience-with-secure-cross-agency-data-sharing/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Mon, 15 Apr 2024 14:38:29 +0000</pubDate>
				<category><![CDATA[Artificial Intelligence]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Contracting]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Home]]></category>
		<category><![CDATA[Inside the Agencies]]></category>
		<category><![CDATA[IT & Networks]]></category>
		<category><![CDATA[Opinion]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2024/04/15/how-to-boost-customer-experience-with-secure-cross-agency-data-sharing/</guid>

					<description><![CDATA[The Federal Data Strategy directs agencies to assess and proactively address the procedural, regulatory, legal and cultural barriers to sharing data.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/opinions/2024/04/15/how-to-boost-customer-experience-with-secure-cross-agency-data-sharing/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">27658</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/GettyImages-691574497.jpg.jpg" width="5500" height="3667" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">Across nearly every public support mission, federal agencies are responsible for harnessing vast amounts of data. As government services are increasingly digitized, the massive amount of data retained by individual agencies can be overwhelming. However, when leveraged effectively, this data becomes a foundational component of effective, timely decision-making and improved customer experience, or CX, across the public sector.</p>



<p class="wp-block-paragraph">To leverage data effectively and securely, the <a href="https://strategy.data.gov/practices/">Federal Data Strategy</a> directs agencies to “assess and proactively address the procedural, regulatory, legal and cultural barriers to sharing data within and across federal agencies and with external partners.” As such, the importance of data sharing and cross-agency collaboration took center stage at the Census <a href="https://coilsummit2024.splashthat.com/?utm_campaign=&#038;utm_content=">Open Innovation Summit</a> earlier this year.</p>



<p class="wp-block-paragraph">The Census Bureau serves as the nation’s leading provider of data and insights about its people and economy, which means optimal data utilization and sharing is fundamental to its mission.</p>



<p class="wp-block-paragraph">Like many data-rich or data-dependent agencies, the Census Bureau must balance maximum utility and security. In the case of the decennial census, the Bureau is expected to share the data it collects to improve a myriad of federal programs, employee experience, and overall CX. These objectives are critical but cannot come at the expense of privacy and confidentiality.</p>



<p class="wp-block-paragraph">The key is determining which barriers to data-sharing are redundant or unnecessary and which are essential to preserve the security of sensitive personal and government information. To strike this balance, agencies such as the Census Bureau will need to engage in continuous, extensive discussions with one another and with industry partners.</p>



<h2 class="wp-block-heading">Means to an end</h2>



<p class="wp-block-paragraph">As a starting point, agencies should look at data as a means to an end. Data users must assess their final desired outcomes and determine the minimally invasive data elements that meet them.</p>



<p class="wp-block-paragraph">Too often, data recipients, especially in cross-agency data-sharing relationships, want the flexibility of receiving raw data to process and utilize to meet their changing needs. While this is an understandable desire, it must be balanced against the paramount need for personal data security. Starting with the desired outcome is an effective approach to resolving this conflict; asking data providers to contribute insights and outcomes rather than raw data makes it far easier to resolve data privacy concerns.</p>



<p class="wp-block-paragraph">For example, while the Census rightfully protects individual data, aggregated data can often be just as useful while preserving privacy. It is challenging to decide what data best meets desired outcomes and what degree of risk is acceptable to meet them. Fortunately, differential privacy and other approaches can provide structured ways for determining how much and what type of aggregated data or insights can be shared while mitigating individual privacy risks.</p>



<p class="wp-block-paragraph">Data governance around sensitive and non-sensitive data can significantly reduce data-sharing barriers. Agencies that distinguish appropriately between sensitive and non-sensitive data and label accordingly foster interoperability and help agencies make decisions about their data faster. By working with trusted industry partners to create a data governance strategy, agencies can be more deliberate about data integration and security decisions, breaking down inter-agency and intra-agency siloes.</p>



<p class="wp-block-paragraph">In addition to privacy concerns, cybersecurity risks must be considered. The federal government is subject to a barrage of cyberattacks daily. As such, agencies adhere to stringent cybersecurity protocols, which can restrict data access. All federal data architectures should be shrouded in cybersecurity measures that account for requirements such as zero trust and the Evidence Act.</p>



<p class="wp-block-paragraph">Fortunately, there are innovative solutions to keep data secure yet accessible. Data fabrics or data meshes allow agencies to leave data where it is and expose it through APIs. This allows the information to remain secure and be analyzed to illuminate critical insights and enable effective decision-making.</p>



<h2 class="wp-block-heading">Focus on efficiency</h2>



<p class="wp-block-paragraph">Once agencies and their private-sector partners account for privacy requirements and security concerns, the next objective is to efficiently sort, analyze and share the data to extract meaningful value. While the amount of data available to agencies has multiplied, so too have the tools available to analyze them and provide insights. Artificial intelligence and machine learning can play important roles and, when used appropriately, save time and deliver valuable insights.</p>



<p class="wp-block-paragraph">In concert with good CX practice, agencies and their industry partners should connect their analytics initiatives directly to mission outcomes to accelerate the use of data as a strategic asset throughout the federal government</p>



<p class="wp-block-paragraph">Data platforms that are loosely coupled and tightly integrated can address hindrances to data sharing across agencies. This creates open architectures that allow federal employees and the public to access the information they need while putting enough controls in place to ensure the data is not misused.</p>



<p class="wp-block-paragraph">Standardization is another powerful tool to accelerate data sharing. When systems are not interoperable, the transfer of information is hindered. Standardizing methodologies and technologies whenever possible can speed up and enhance these transactions. For example, DataOps, which leverages DevSecOps principles for secure data analysis, will solve inefficient data generation and processing problems by improving data quality and applying controls in an automated manner.</p>



<p class="wp-block-paragraph">Federal agencies like the Census Bureau have access to massive amounts of data that will transform how the government interacts with and supports the nation’s residents. However, before agencies can capitalize on the full potential of that data, agency leaders must collaborate with one another and with their vendors to establish comprehensive strategies and procedures for effective data usage and management.</p>



<p class="wp-block-paragraph">To ensure the appropriate and secure use of data, agencies must account for many competing priorities. Resolving those can be challenging, but when all parties focus on the outcome that the data serves, potential conflicts become collaborative solutions. When multiple parties work toward commonly understood goals, their unique challenges can be overcome to enhance constituent service and safety.</p>



<p class="wp-block-paragraph"><i>Evan Davis is Executive Managing Director, Business Process Services, at Maximus.</i></p>
]]></content:encoded>
	</item>
		<item>
		<title>National Cybersecurity Strategy compliance requires a modernized cloud</title>
		<link>https://one.sightlinemg.com/federaltimes/opinions/2024/03/25/national-cybersecurity-strategy-compliance-requires-a-modernized-cloud/</link>
					<comments>https://one.sightlinemg.com/federaltimes/opinions/2024/03/25/national-cybersecurity-strategy-compliance-requires-a-modernized-cloud/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Mon, 25 Mar 2024 18:17:41 +0000</pubDate>
				<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Home]]></category>
		<category><![CDATA[Inside the Agencies]]></category>
		<category><![CDATA[IT & Networks]]></category>
		<category><![CDATA[Opinion]]></category>
		<category><![CDATA[cyber]]></category>
		<category><![CDATA[opinion]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2024/03/25/national-cybersecurity-strategy-compliance-requires-a-modernized-cloud/</guid>

					<description><![CDATA[At the outset, there’s a need to blend legacy standards and practices with modern components to ensure all systems can communicate effectively.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/opinions/2024/03/25/national-cybersecurity-strategy-compliance-requires-a-modernized-cloud/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">27987</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/Cloud-computing-1.jpg-1.jpg" width="4800" height="3000" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">A year removed from the delivery of the Biden Administration’s National Cybersecurity Strategy, federal agencies continue working to mature their IT architectures to comply with enhanced standards for cloud modernization. Fortunately, these new federal mandates on what had previously been recommended guidelines are driving agencies in a direction they should be going anyway – toward more optimized cloud infrastructures that enable stronger performance and better cost management.</p>



<p class="wp-block-paragraph">As the name implies, the National Cybersecurity Strategy’s main objective is to enhance cybersecurity across the government. However, these new rules also directly affect how cloud architectures should be modernized and configured. For example, cloud infrastructures capable of doing so must support more robust digital identity solutions to foster a “safe and efficient digital economy.” As another example, new regulations for IoT governance require more traceability and control for sensors and other devices, including better automated systems for patching and upgrades.</p>


	<aside class="smg-interstitial-link wp-block-smg-interstitial-link">
		<a href="https://one.sightlinemg.com/c4isrnet/battlefield-tech/it-networks-battlefield-tech/2024/03/25/pentagon-inks-dozens-of-jwcc-orders-with-more-in-the-pipeline/" class="smg-interstitial-link__inner">
							<div class="smg-interstitial-link__media">
					<img loading="lazy" decoding="async" width="300" height="200" src="https://one.sightlinemg.com/wp-content/uploads/2026/08/GettyImages-140705053.jpg.jpg?w=300" class="smg-interstitial-link__image wp-post-image" alt="" />				</div>
						<div class="smg-interstitial-link__content">
				<span class="smg-interstitial-link__kicker">Related</span>
				<h3 class="smg-interstitial-link__title">Pentagon inks dozens of cloud contract orders, more in the pipeline</h3>
									<p class="smg-interstitial-link__excerpt">Cloud is often seen as a means to get the right data to the right people at the right time — a pillar of Combined Joint All-Domain Command and Control.</p>
							</div>
		</a>
	</aside>
	


<p class="wp-block-paragraph">These and other imperatives will shape the to-do list of federal cloud development teams for years to come as they seek to evolve their architectures to be more agile, interconnected, and automated. While some agencies choose to modernize by relying on hybrid environments, like cloud-native networks working with storage and compute architectures on-prem, others have already made major progress moving assets to the cloud.</p>



<p class="wp-block-paragraph">For instance, the Defense Logistics Agency has moved the <a href="https://federalnewsnetwork.com/cme-event/federal-insights/level-up-in-the-cloud/">majority of its assets</a> to the cloud in recent years, leaving just two applications on-prem.</p>



<p class="wp-block-paragraph">Whatever the specific IT landscape, the transformation imperative is for agencies to ensure compliance, security, observability and maximum return on investment and efficiency as they transfer data and applications to and from the cloud. Of course, this is easier said than done. At the outset, there’s a need to blend legacy standards and practices with modern components to ensure all systems can communicate effectively.</p>



<p class="wp-block-paragraph">There’s also a need for more government-wide consensus on zero trust – a lynchpin element of the strategy whose standards can vary in domain focus and level of centralization, depending on the agency.</p>



<p class="wp-block-paragraph">Additionally, cost management remains an issue, especially given the number of <a href="https://www.mckinsey.com/capabilities/strategy-and-corporate-finance/our-insights/how-covid-19-has-pushed-companies-over-the-technology-tipping-point-and-transformed-business-forever">under strategized</a> migrations that public and private sector organizations pursued in the frenzied pandemic era to adapt to remote work scenarios quickly. Consider the impact of double infrastructure costs for an application whose front end was moved to the cloud, with the back end left back on-prem, for instance.</p>



<h2 class="wp-block-heading">Ensuring compliance with the right strategy</h2>



<p class="wp-block-paragraph">Solving the above challenges requires cloud modernization teams to conduct thorough research and planning from both a performance and cost standpoint. The best methodologies embrace a cloud-first approach to software developement, data organization and application refactoring – regardless of whether these activities are happening in the cloud or on-prem, and regardless of which direction a migration may be going between these destinations.</p>



<p class="wp-block-paragraph">To support such an approach, agencies must ensure strong data standards, auditing and availability across the IT estate; and they should thoroughly utilize containers, microservices and other cloud native DevOps techniques– not just in the cloud, but also on prem and even with support from SaaS providers, MSPs or other third-party partners. Furthermore, the odds of success can be increased by embracing four key priorities in the planning and implementation phases:</p>



<p class="wp-block-paragraph">— <i>Adopt an outcome-focused mindset:</i> Conduct thorough analysis that includes both technical and domain specialists to clarify the desired outcome of a modernization task, and then architect toward that outcome with only the data and tools that are necessary to achieve it.</p>



<p class="wp-block-paragraph">— <i>Enforce open standards and interoperability:</i> No single technology solves every problem. This places a premium on interoperability across multiple best-of-breed technologies. Open standards and common protocols for ITSM, log management, patching and other critical functions are essential to enabling this interoperability.</p>



<p class="wp-block-paragraph">— <i>Take a direction-agnostic approach to migration: </i>The cost management examples mentioned previously underscore that migration is not a one-way street into the cloud. Rationalize the IT investment based on whichever destination – cloud, on prem or a third-party SaaS or MSP vendor – is the best candidate to resolve an issue with performance, security or cost.</p>



<p class="wp-block-paragraph">— <i>Ensure automation is grounded in knowledge management:</i> Automating an application or function without adequate business context applied to the underlying processes can limit the tool’s effectiveness at scale. Ensure knowledge management is part of the process by looping in domain experts and validating the business context before automation and scaling.</p>



<p class="wp-block-paragraph">The cloud adoption requirements stemming from the National Cybersecurity Strategy provide federal agencies an important opportunity to optimize their cloud configurations as they work to align with mandates. While every agency must customize its approach to suit its unique environment and mission objectives, a strong modernization strategy can ensure compliance through better visibility and management across all IT assets, processes and systems.</p>



<p class="wp-block-paragraph"><i>Lee Koepping is Chief Technologist, Public Sector at ScienceLogic</i></p>
]]></content:encoded>
	</item>
		<item>
		<title>Three steps to building an effective digital identity ecosystem</title>
		<link>https://one.sightlinemg.com/federaltimes/opinions/2024/02/26/three-steps-to-building-an-effective-digital-identity-ecosystem/</link>
					<comments>https://one.sightlinemg.com/federaltimes/opinions/2024/02/26/three-steps-to-building-an-effective-digital-identity-ecosystem/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Mon, 26 Feb 2024 20:48:38 +0000</pubDate>
				<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Home]]></category>
		<category><![CDATA[Inside the Agencies]]></category>
		<category><![CDATA[IT & Networks]]></category>
		<category><![CDATA[Opinion]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2024/02/26/three-steps-to-building-an-effective-digital-identity-ecosystem/</guid>

					<description><![CDATA[Prioritizing a modern digital identity ecosystem is long overdue.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/opinions/2024/02/26/three-steps-to-building-an-effective-digital-identity-ecosystem/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">27527</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/MIL-MILMONEY-031218.jpg.jpg" width="1198" height="627" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">A <a href="https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.seattletimes.com%2Fopinion%2Fim-a-college-professor-i-fell-for-a-scam-that-drained-my-life-savings%2F&#038;data=05%7C02%7Ccary.oreilly%40mco.com%7Cd1fb9fc9554b468d2b7908dc34a84976%7C1d5c96e57ee2446dbed8d0f8c50edea5%7C1%7C0%7C638443144619955309%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&#038;sdata=IeTKkuZg7KrKrq9LeQimS6P4fx6M%2BfET0mlzx7xhM48%3D&#038;reserved=0">college professo</a>r in Washington State received a call from the Federal Trade Commission. To protect against money launderers, she was told she must transfer her life savings, including her retirement funds, to the government. In the end, she turned over more than $400,000 to an imposter.</p>



<p class="wp-block-paragraph">Unfortunately, there are millions of similar stories across the country. According to a <a href="https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.ftc.gov%2Fnews-events%2Fnews%2Fpress-releases%2F2024%2F02%2Fnationwide-fraud-losses-top-10-billion-2023-ftc-steps-efforts-protect-public&#038;data=05%7C02%7Ccary.oreilly%40mco.com%7Cd1fb9fc9554b468d2b7908dc34a84976%7C1d5c96e57ee2446dbed8d0f8c50edea5%7C1%7C0%7C638443144619965602%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&#038;sdata=ErCnF2LreRux1nRGofSGvSc7%2BjzW8Os8KPf9TlwzVww%3D&#038;reserved=0">new report</a> from the FTC, American consumers lost a record $10 billion to fraud, including rampant imposter scams like this one, and filed more than 1 million reports of identity theft in 2023.</p>



<p class="wp-block-paragraph">The report underscores the pressing need to build a robust and trustworthy digital identity ecosystem. Doing so will prevent identity fraud without making it harder for legitimate people to access critical government services.</p>



<p class="wp-block-paragraph">Bad actors steal personal data, and then use it to commit identity fraud. They do this by targeting every part of the digital identity process from validation to verification to authentication.</p>



<p class="wp-block-paragraph">Recent <a href="https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.fincen.gov%2Fnews%2Fnews-releases%2Ffincen-issues-analysis-identity-related-suspicious-activity&#038;data=05%7C02%7Ccary.oreilly%40mco.com%7Cd1fb9fc9554b468d2b7908dc34a84976%7C1d5c96e57ee2446dbed8d0f8c50edea5%7C1%7C0%7C638443144619972884%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&#038;sdata=CxvuzE6POe0xcr1FtiF4xK5ofmHhfxiQqVKeibZrxR8%3D&#038;reserved=0">analysis</a> released by the Financial Crimes Enforcement Network found that of the 1.6 billion identity-related reports filed by financial institutions in 2021, 69 percent involved attackers impersonating others (validation); 18 percent involved attackers using compromised credentials (authentication); and 13 percent involved attackers exploiting insufficient verification checks (verification). In total, the agency identified $212 billion in suspicious activity related to identity in 2021 alone.</p>



<p class="wp-block-paragraph">Identity fraud is estimated to continue to increase in 2024 as fraudsters become more networked, data compromises become more prevalent, and massive amounts of personal identifiable information continue to be available on the dark web. Artificial intelligence is making it easier to either steal one’s identity or combine real and/or false information to create a new fake identity, called a synthetic identity.</p>



<p class="wp-block-paragraph">There has been progress toward this goal. But too many digital identity providers continue to rely on outdated approaches that keep legitimate people from receiving benefits while failing to prevent fraud.</p>



<p class="wp-block-paragraph">There are three steps our leaders in government can do to prioritize a strong digital identity ecosystem in 2024.</p>



<h2 class="wp-block-heading">A layered defense approach</h2>



<p class="wp-block-paragraph">First, government leaders should take steps to move away from relying solely on images of physical documents that are often lost, misplaced, stolen or fabricated. The pace of technology has made it far too easy for fraudsters to defeat unsophisticated systems that evaluate only images of these documents.</p>



<p class="wp-block-paragraph">Layered defenses which simultaneously evaluate document, device, and behavioral elements are essential for preventing deep fakes, fake IDs, and stolen and fabricated identities from intercepting government digital services and benefits. Congress should reintroduce, and pass legislation such as the <a href="https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.congress.gov%2Fbill%2F118th-congress%2Fsenate-bill%2F884&#038;data=05%7C02%7Ccary.oreilly%40mco.com%7Cd1fb9fc9554b468d2b7908dc34a84976%7C1d5c96e57ee2446dbed8d0f8c50edea5%7C1%7C0%7C638443144619980760%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&#038;sdata=09ozjrD5G6z5wpk2As%2FGwzjqVx%2B%2F1l26adySE6RD5sU%3D&#038;reserved=0">Improving Digital Identity Act </a>which would advance a government-wide effort to address the U.S.’ fragmented digital identity infrastructure.</p>



<h2 class="wp-block-heading">Beyond credit header data</h2>



<p class="wp-block-paragraph">Additionally, we must also move away from legacy approaches that rely on credit header data to verify identities. This is problematic because the same personal information used by credit bureaus to verify identities is too often compromised data that is easily acquired on the dark web.</p>



<p class="wp-block-paragraph">In addition, certain populations, including new-to-country individuals, young people, and underbanked communities, are more likely to have an insufficient credit history and have a more difficult, if not impossible, time receiving the benefits they are due. Instead, government leaders should work to incentivize the adoption of approaches that use the latest in AI technology to deliver more equitable outcomes.</p>



<h2 class="wp-block-heading">Advance transparency</h2>



<p class="wp-block-paragraph">Finally, government leaders must take steps to create a transparent reporting environment for the digital identity ecosystem. This can be accomplished through the long-awaited executive order on digital identity, through the creation of performance reporting standards, or inserted into contracts with digital identity providers. Government should also require digital identity providers to regularly publish their auto-approval rates, with a focus on coverage, accuracy, precision, and equity. And all data reported must be validated to ensure that we are clear on what is working and what is not.</p>



<p class="wp-block-paragraph">Prioritizing a modern digital identity ecosystem is long overdue. Doing so will help us stay ahead of bad actors who are only focused on lining their pockets, while simultaneously confirming that good people can be included in an ever increasing digital economy.</p>



<p class="wp-block-paragraph"><i>Jordan Burris is VP and Head of Public Sector Strategy at Socure. He is also a board member at the Identity Theft Resource Center and a former chief of staff to the Federal CIO.</i></p>
]]></content:encoded>
	</item>
		<item>
		<title>How interoperability benefits military, civil and commercial domains</title>
		<link>https://one.sightlinemg.com/federaltimes/opinions/2024/02/23/how-interoperability-benefits-military-civil-and-commercial-domains/</link>
					<comments>https://one.sightlinemg.com/federaltimes/opinions/2024/02/23/how-interoperability-benefits-military-civil-and-commercial-domains/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Fri, 23 Feb 2024 20:33:06 +0000</pubDate>
				<category><![CDATA[Cloud]]></category>
		<category><![CDATA[GovCon]]></category>
		<category><![CDATA[Home]]></category>
		<category><![CDATA[IT & Networks]]></category>
		<category><![CDATA[Opinion]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2024/02/23/how-interoperability-benefits-military-civil-and-commercial-domains/</guid>

					<description><![CDATA[By focusing on interoperability, new capabilities can be quickly adopted and rolled out without significant system redesign.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/opinions/2024/02/23/how-interoperability-benefits-military-civil-and-commercial-domains/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">27502</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/mg2.jpg_d3a540.jpg" width="5152" height="2557" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">As modern-day information systems become more complex, the importance of interoperability cannot be overlooked. Organizations across numerous industries rely on a myriad of software applications and devices to streamline operations, facilitate communication and drive innovation. However, without interoperability, the potential of these systems is hindered, which can lead to inefficiencies and barriers to collaboration.</p>



<p class="wp-block-paragraph">Whether applied to military, commercial or consumer domains, interoperability can benefit every step of the supply chain by reducing overall costs and enabling rapid integration, as well as by improving the long-term sustainability and maintainability of fielded systems. Interoperability promotes cohesion and efficiency across these diverse systems, and the most obvious beneficiary of this is the system integrator.</p>



<p class="wp-block-paragraph">Well-defined, standardized interfaces enable integrators to select “best in breed” capabilities from multiple potential suppliers without having to absorb the additional costs associated with proprietary or custom interfaces.</p>



<p class="wp-block-paragraph">In addition, the use of interoperable interfaces across subsystems and components lets integrators keep up with constantly improving technology and capabilities. In growth areas like unmanned systems, interoperability is critical to sustainability since the current “state of the art” can be quickly replaced by a next-generation breakthrough. By focusing on interoperability, new capabilities can be quickly adopted and rolled out without significant system redesign.</p>



<p class="wp-block-paragraph">Interoperability also can benefit industry vendors – particularly, small- and medium-sized ones. After all, modern systems have become too complex for a single vendor to excel in each of the system’s hardware, software, and mechanical requirements. Interoperable interfaces enable vendors to specialize their offerings and compete in niche areas, while targeting products toward a broad market.</p>



<p class="wp-block-paragraph">When the same interoperable interfaces are used across the military, civilian, and commercial spaces, vendors can offer a single product that can be integrated into each of these domains. This can foster a broader market and improve both quality and cost. We can look at standard interfaces in our everyday lives as proof of this, where well-supported, standardized interfaces like HDMI, USB and Ethernet gives consumers a robust set of choices across a broad market.</p>



<h2 class="wp-block-heading">Eliminating ‘vendor lock’</h2>



<p class="wp-block-paragraph">In addition, a system comprised of interoperable components, each offered by a vendor that specialized in that capability, is likely to perform better than a “stovepipe” solution created by a single supplier. Interoperable interfaces also help to eliminate “vendor lock,” where a single supplier can dominate a market with higher price points. They also prevent the vendor lock that occurs when a supplier draws customers into a service-based model around a proprietary core functionality while promising “interoperability” for certain peripheral features.</p>



<p class="wp-block-paragraph">The interoperability of products across market segments yields better options for vendors, system integrators, and acquisition agencies. For example, the Department of Defense (DoD) has made it clear that they seek to reduce costs by leveraging cost savings often seen within the larger scale of commercial markets. On the other hand, commercial organizations often balk at the high costs of research and development associated with fledgling technologies – costs the defense industry is more willing to tolerate. With interoperable interfaces, commercial markets can embrace the new capabilities developed for the defense sector while minimizing their R&amp;D budget. And the civilian market, often price conscious, benefits from both: emerging capabilities from the defense sector with lower price points often achieved in commercial markets.</p>



<p class="wp-block-paragraph">Achieving the benefits of interoperability is not without its challenges, however. Notably, achieving compliance with interoperability standards can come with significant one-time costs. Developing interfaces to standards often involves specialized knowledge and talent. Furthermore, getting those interfaces tested and validated can be costly as well. Despite these challenges, the cost-saving benefits of interoperability hopefully outweigh these start-up expenses over the long term.</p>



<p class="wp-block-paragraph">In addition, to be effective, interoperability and the standardization of interfaces are best applied at critical points in the lifecycle of a new technology. During the early stages of development, things are changing too rapidly, as researchers push boundaries in new directions. Attempting to apply interoperability standards at this stage is a fool’s errand, as any agreed-upon standard is likely to become immediately out-of-date with the next major breakthrough.</p>



<p class="wp-block-paragraph">On the other hand, attempting to apply standard interfaces to a mature and stable market can be equally as challenging, as organizations are unlikely to embrace an approach that might risk their market share. Consequently, interoperability standards often have a Goldilocks “just right” period in which all parties can benefit.</p>



<p class="wp-block-paragraph">These challenges are often addressed through a single common driver: market demand. Anyone with a junk drawer full of outdated cables and chargers knows that the push to USB-C has made life easier. We’re now seeing a similar push in the defense segment, where the DoD is pushing hard towards adoption of Modular Open Systems Approach principles to prevent the aforementioned “vendor lock.” A key component of MOSA is interoperability through well-defined, standardized interfaces.</p>



<p class="wp-block-paragraph">At the same time, standards organizations like SAE, IEEE, ISO, and ANSI have made it easier than ever for companies to collaborate on the development and publication of interoperability standards. Interoperability is almost impossible without compliant interfaces driven by industry standards. Still, even standards themselves are not enough to achieve interoperability; rather, vendors also need a way to verify and certify their products are compliant to that standard. Interoperability only works if both sides of any interface are compliant, and unambiguous standards and rigorous testing methods are the only way to ensure that. For organizations that are willing to embrace it, there are plenty of opportunities to join the effort to help steer and drive interoperability into the future.</p>



<p class="wp-block-paragraph"><i>David Martin is the Director of Software and Architecture at Neya Systems. Martin joined Neya Systems in 2011 and is the company’s subject matter expert on interoperability and extensible architectures, as well as principal Robotic Technology Kernel engineer. He has been a leading developer of JAUS standards since 2007, during which time the group transitioned from an informal working group to a formal SAE committee. In addition to his role at Neya, Martin currently serves as the Chair of the SAE International AS-4 (Unmanned Systems) Steering Committee.</i></p>
]]></content:encoded>
	</item>
		<item>
		<title>US should lead by example, not exception, on IT procurement</title>
		<link>https://one.sightlinemg.com/federaltimes/acquisition/2024/02/16/us-should-lead-by-example-not-exception-on-it-procurement/</link>
					<comments>https://one.sightlinemg.com/federaltimes/acquisition/2024/02/16/us-should-lead-by-example-not-exception-on-it-procurement/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Fri, 16 Feb 2024 17:39:56 +0000</pubDate>
				<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Contracting]]></category>
		<category><![CDATA[GovCon]]></category>
		<category><![CDATA[GSA]]></category>
		<category><![CDATA[Home]]></category>
		<category><![CDATA[Inside the Agencies]]></category>
		<category><![CDATA[IT & Networks]]></category>
		<category><![CDATA[Procurement]]></category>
		<category><![CDATA[Regulations]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2024/02/16/us-should-lead-by-example-not-exception-on-it-procurement/</guid>

					<description><![CDATA[The federal government is the largest consumer of goods and services in the world, including more than $100 billion on IT and cyber investments each year.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/acquisition/2024/02/16/us-should-lead-by-example-not-exception-on-it-procurement/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">27488</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/GettyImages-481986560.jpg.jpg" width="1200" height="877" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">It has been almost two years since the U.S. government joined 60 global partners to <a href="https://www.whitehouse.gov/briefing-room/statements-releases/2022/04/28/fact-sheet-united-states-and-60-global-partners-launch-declaration-for-the-future-of-the-internet/">call for</a> a single global internet and technology ecosystem that is truly open and fosters competition. And yet, a single vendor controls <a href="https://ccianet.org/news/2021/09/new-study-shows-microsoft-holds-85-market-share-in-u-s-public-sector-productivity-software/">85% </a>of the market for the government’s most commonly used technology. In an increasingly interconnected world facing a growing number of sophisticated threat actors, overreliance on any one technology vendor creates significant risks.</p>



<p class="wp-block-paragraph">A bold vision requires bold action, and the most effective way for the U.S. government to take the lead in realizing the change it and its partners seek in the digital world is to get its own house in order. To do so, it must prioritize ensuring that its marketplace reflects the values it promotes by addressing the risks that persist from its IT monoculture.</p>



<p class="wp-block-paragraph">The federal government is the<a href="https://www.whitehouse.gov/briefing-room/statements-releases/2022/07/26/fact-sheet-biden-harris-administration-advances-equity-and-economic-opportunity-through-federal-procurement-and-state-and-local-infrastructure-contracting/"> largest consumer</a> of goods and services in the world, spending roughly $600 billion each year—including more than<a href="https://www.gao.gov/products/gao-23-106414"> $100 billion</a> on IT and cyber investments. A <a href="https://ccianet.org/news/2021/09/new-study-shows-microsoft-holds-85-market-share-in-u-s-public-sector-productivity-software/">large majority</a> of these investments are directed toward Microsoft. Relying so heavily on a single IT provider not only increases<a href="https://omdia.tech.informa.com/-/media/tech/omdia/marketing/commissioned-research/pdfs/monoculture-and-market-share-the-state-of-communications-and-collaboration-software-in-the-us-government-v3.pdf?rev=8d41cc2d16de491b9f59d2906309fdaa"> the target profile of that provider</a>, but also limits the ability of the government to defend itself against future cyberattacks. As Sen. Eric Schmitt, R-Mo.,recently <a href="https://www.newsweek.com/senators-want-answers-microsoft-military-software-monopoly-it-antivirus-cybersecurity-1811799">stated</a>, “only meaningfully employing one vendor” creates a single point of failure that adversaries can exploit.”</p>



<p class="wp-block-paragraph">These concerns have been echoed across government agencies, including the U.S. Departments of <a href="https://www.newsweek.com/veterans-data-risk-after-cybersecurity-measure-removed-officials-say-1861620">Veterans Affairs</a> and <a href="https://www.newsweek.com/pentagon-hacking-fears-raised-microsoft-military-software-it-antivirus-monopoly-cybersecurity-1794369">Defense</a>. Current and former officials tied the VA’s move to go “all-in” on a single vendor to the accidental disclosure of 1,500 U.S. veterans’ personal data. Similarly, former DoD senior officials questioned the department’s decision to replace its long-running cybersecurity program with off-the-shelf tools from the same vendor providing the DoD’s software and cloud services, calling the move an “unacceptable level of risk” for the department.</p>



<p class="wp-block-paragraph">In December, with the<a href="https://www.defense.gov/News/News-Stories/Article/Article/3618367/congress-passes-fiscal-2024-defense-spending-bill-pay-raise-for-service-members/"> passage</a> of the 2024 National Defense Authorization Act came lawmakers’ agreement to a key insert to the act by Sen. Schmitt (<a href="https://docs.house.gov/billsthisweek/20231211/FY24%20NDAA%20Conference%20Report%20-%20%20FINAL.pdf">section 1553</a>) compelling the Department of Defense (DoD) to assess the cybersecurity capabilities of the technologies it uses so as to ensure competition and interoperability—the concern being that both competition and interoperability are hindered by the DoD’s overreliance on legacy vendors. Cybersecurity experts know that an impartial analysis will likely find the DoD’s overreliance on a single vendor is severely limiting competition and interoperability, and is as a result a threat to U.S. national security.</p>



<p class="wp-block-paragraph">The DoD represents the largest portion of the U.S. government marketplace, but the need to diversify IT and cybersecurity vendors extends across the government and aligns with the Biden Administration’s<a href="https://www.whitehouse.gov/wp-content/uploads/2023/03/National-Cybersecurity-Strategy-2023.pdf"> National Cybersecurity Strategy</a>. The strategy is rooted in two central themes: rebalancing the responsibility to defend cyberspace and realigning incentives to favor long-term investments. As part of this, the U.S. government and major technology providers are called on to protect data, assure the reliability of critical systems, and make cyberspace more resilient and defensible over the long term.</p>



<p class="wp-block-paragraph">The best place to start is in its own marketplace—where the U.S. government has the most control. For the government to best protect its systems and invest in a secure digital ecosystem, it must foster greater competition and diversify the vendors it relies on to provide and secure its digital ecosystem. Doing so would drive the values the administration seeks to realize in the broader digital world and enhance our national security posture. Additionally, such a move in the largest marketplace in the world would be a major incentive to drive change and almost certainly reduce the need for extensive regulation to enforce an open, free, interoperable market.</p>



<p class="wp-block-paragraph">Until the U.S. government’s marketplace exemplifies its vision for the broader digital world, it can’t expect to lead others in realizing such a vision—at home or abroad. The U.S. government should prioritize leading by example and ensure its IT marketplace fosters competition, privacy, and security, and ultimately by selecting a more diverse set of cybersecurity and IT vendors. In this way, the U.S. government will lead by example, not exception, in bringing about the global internet and technology ecosystem that it envisions at home and abroad.</p>



<p class="wp-block-paragraph"><i>Cory Simpson is the founder and CEO of Gray Space Strategies, Inc., a professional services and strategic advisory firm based in Washington, D.C., and serves as CEO of the Institute for Critical Infrastructure and as a Senior Advisor to the Cyberspace Solarium Commission.</i></p>
]]></content:encoded>
	</item>
	</channel>
</rss>
