Feds at the Edge

Feds at the Edge

By FedInsiderTechnologyGovernment
Download on the App Store

Feds at the Edge episodes

  • Ep. 119 Threat Intelligence Sharing in a Complex Threat Landscape

    One of the challenges of raising a child is teaching them how to share; one of the challenges of federal information technology professionals is teaching them to share.

    Today we take a look at organizations that encounter cyber threats and their efforts at sharing threat information.

    Sharing cyber threat information isn’t a recent idea -- Executive Orders have encouraged sharing for years.

    February 13, 2015, talks about the goal of creating robust information sharing related to cybersecurity risks and incidents.

    May 12, 2021 “Removing barriers to threat sharing” that encourages the sharing of information across federal agencies.

    In the commercial world, people are afraid to share cyber threat information because it may make them look weak to customers. If they share that data with competition, then their commercial opponents may have a leg up on them.

    The federal world is just resistant but for different reasons.  If a vulnerability is announced, there is a threat that federal systems that aren’t patched will be vulnerable to attack.

    This is the challenge addressed in today’s interview with federal CISOs and a commercial expert. 

    Jonathan Feibus from the NRC looks at budget -- smaller agencies may not be able to afford to get commercial data on threats.

    Companies like Mitre make available public Common Vulnerabilities and Exposure (CVE) lists for free. The most recent list includes 210,558 vulnerabilities.

    It is indeed possible for a commercial company to have systems where vulnerabilities can be identified and remediated before they makes the CVE list. 

    29 min
  • Ep. 118 Cybersecurity: Protect & Personalize User Experience

    Executing the mission, abstracting complexity, driving for speed

    The Biden administration didn’t just release Executive Order 14-058 to make federal websites look good, the practical aspect of user experience is making sure citizens can access information in a speedy, and safe manner. 

    Conrad Bovell from HHS makes a strong statement when he states the reason for cybersecurity is to secure the mission of the agency.  For his agency, it is quite a large mission.

    During the interview, he casually mentions that HHS has a #1.68 trillion annual budget. 

    The obvious method is to lock everything down, however, the functioning of the agency means that he and his team must assess risk to when funding research.  The challenge is to get both: good experience and speed.

    The HHS complex in suburban Maryland is quite extensive and complex, but nothing compared to the geographically remote and secure networks the military must operate in.  Randy Young gives the perspective of a trusted partner who assists in making the network easy to use and secure.  He maintains the way to support the warfighter drives better technology outcomes on the user’s terms, not the terms of whatever new technology is available. 

    Putting yourself in the end user’s boots can make security experts understand how to manage risk and deliver the speed needed all the way to the feds at the edge.

    Twitter:  @FedInsider

    LinkedIn:    https://www.linkedin.com/company/fedinsider/

    Facebook:   https://www.facebook.com/FedInsiderNews

     

    30 min
  • Ep. 117 Zero Trust Security Transformation: A “How To” Guide

    Compliance, maturity levels, edge computing

    Some people think the television phrase, “Set it and forget it” applies to Zero Trust. Today’s discussion throws that notion out the window.

    The interview takes a deep dive into how an agency can move to a Zero Trust Architecture.  Three experts discuss compliance, maturity levels, and the role of edge computing. The conclusion is obvious: Zero Trust is a serious, constantly evolving methodology and federal leaders must take advantage of every resource possible to gain a thorough understanding of the process.

    Jennifer Franks from the GAO points out that Zero Trust is not a new concept and the federal government has all kinds of reference materials to support leaders. She lists information from DISA, NIST, the DoD as well as the OMB. She reminds listeners that there is a maturity model associated with Zero Trust change --  and leaders must be aware of revisions to these documents.  Jennifer reminds the audience of the recent upgrade to the DISA model that adds more maturity levels.

    Guidance is nice, but where to start? During the interview, Wayne Rogers talks about looking at your respective agency’s situation and doing a gap analysis. Once that is complete, then one can set priorities.  For example, when he used this process, his agency identified a weakness in their VPN system.  He prototyped a transition to Secure Access Service Edge and then deployed it across the agency.

    Probably the best quote from this interview was provided by Akamai’s Tony Lauro. He said, “Security has to work despite users.”  He is referring to the base concept behind Zero Trust – an automated system that can identify threats and provision resources with appropriate access levels that can have nothing to do with end users acting themselves. 

    Ron Popeil’s catchphrase may work on television, but not in today’s federal government. 

     

    Twitter:  @FedInsider

    LinkedIn:    https://www.linkedin.com/company/fedinsider/

    Facebook:   https://www.facebook.com/FedInsiderNews

    33 min
  • Ep. 116 Cybersecurity in a Post-Pandemic World

    Technology maturing, constant attacks, automated responses

    For the last ten years, everybody in federal software has been discussing the maturity model. We all know that a system must start, be managed, and be optimized.  Unfortunately, only recently have advances in hardware and software allowed this process to take place. 

    Today, we listen to a conversation between a federal technology expert and a commercial subject matter expert with a focus on cybersecurity in a post-pandemic era.  Covid kickstarted the ability for federal leaders to be able to be transparent and to collaborate securely.  Perhaps this is a story about the technology maturing to give the ability to have an observability in a system with high compliance.

    For example, Brian Dennis, Principal Technologist Public Sector, Akamai points out that micro-segmentation has always been known to prevent malicious actors from moving into the network.  For years, this process has been clunky and woefully inadequate.  Brian suggests that modern systems can make micro segmentation, and its impact on zero trust, easy and flexible.

    Today’s federal agencies are under constant attack and must be adaptable enough to accomplish configuration and change management. Automation may hold the method to accomplish this complicated goal. 

    Many agencies have billions of actions a day and no human can keep up with responding to attacks.  Today, systems are available where threats can be responded to in a rapid, automated, manner.  

    34 min
  • Ep. 115 Innovation in Federal Networks: What's Now, What's Next

    Network visibility, remote access, leveraging artificial intelligence.  

    Predictions are almost impossible in the rapidly changing world of military communications.  Despite that, our tech leaders will offer ideas on visibility, a uniform defense network, and eliminating lateral movement in these networks. If you look at the past twenty years, an argument can be made that the DoD has responded quickly to attacks; however, the solution really hasn’t had resilience or redundancy in mind. 

    Today’s interview gives three ways the DoD is accomplishing the task of remediating some of these issues.  The experts discuss software defined networks, network visibility, and applying artificial intelligence to these concerns.

    Bill Urig observes that we have reached the human limit to understanding a complex network. One can’t apply any sophisticated preventative measures, like software defined networks, unless they have a deep and through knowledge of the network.

    To this end, he has used tools from Red River and Akamai that can provide exact information to system administrators to identify the digital terrain. That information will tell systems analysts the difference between a failed server or nefarious activity.

    During the interview, Col. Joseph Pishock addressed the issue of the future of Identity Credentialing, and Access Management. From his point of view, ICAM has always been a siloed approach. They may be able to take advantage of specific tools, but Secure Access Service Edge is best deployed when using a consolidated platform.  

    All are optimistic that the general trend of understanding the network can give a better response to an attack.

     

     

     

    1 hr 2 min
  • Ep. 114 Pathway to Zero Trust Part 2 of 3

    Trusting your network, sharing information, leveraging new tools.

    The DoD has targeted 2027 as the date to make the transition to Zero Trust. The initiative includes 91 activities and 7 pillars; additionally, it wants the result to be flexible beyond 2027.  This is an interview that includes a Major from the Army and a commercial subject matter expert who look at challenges and solutions to achieving that goal.

    The discussion focuses on three areas: role of constant communications, inter service communication, and the concept of fabric at the edge for improved communications. 

    During the discussion, Major Cory Dombrowski mentioned the challenge of identifying people at the edge.  In a world of constant communications, identification is the first step. If it takes a week to complete authentication, it may comply with the zero trust principles, but have no value.  

    If the Army gets attacked, they should be able to share that information with other branches of the military. In the interview, the participants talk about needing open lines of communications to be able to use data across departments.

    However, parts of the DoD have made remote zero trust a reality. New systems have allowed segments to take in data, apply rules, and apply remediation. Edge based fabric allows them to authenticate remotely and optimize speed. 

     

    28 min
  • Ep. 113 CyberThreats 2023: DoD & Civilian Agencies Working to Adapt Part 1 of 3

    Maintaing operations while under attack

    Today we have the first part of a three-part series with a focus on Cyber Threats 2023 in the DoD. This initial interview looks at high level considerations: cloud, identity management, and maintaining a secure network while undergoing improvement.

    An argument can be made that in the past 20 years the DoD has responded to attacks in a siloed manner. In other words, they may have gotten a solution that worked, but it may not have interoperated with other aspects of the DoD.

    Today’s threats are so overwhelming that focusing on a silo will make you vulnerable. Enterprise organizations are always difficult to change; the DoD is no different. Attacks have become so rampant that the DoD has had to review where they are, how they go there, and produce a plan to remediate concerns.

    Cloud-based systems begin with identity management and can achieve the goals of quick response, reaching endpoints securely, and adapting to a rapidly changing attack environment. Proof of concept is an idea called Secure Access Service Edge. It allows the military to score access to any point in the globe. The success of this program showed that the military can leverage the cloud to secure the edge.

    This is not being done in a theoretical environment, there is an initiative that a zero-trust architecture must be implemented by 2027.

    Twitter:  @FedInsider

    LinkedIn:    https://www.linkedin.com/company/fedinsider/

    Facebook:   https://www.facebook.com/FedInsiderNews

     

     

    46 min
  • Ep. 112 The Amazing Story of a Federal Effort to Find, Grow & Develop Tech Talent

    When you hear of scouts giving scholarships, you think of the University of Alabama discovering a defensive lineman in rural Georgia. 

    This is a story of the long-term result of the federal government discovering and developing talent. This effort had a tremendous long-term impact on improving cybersecurity in the government and commercial sector as well.

    Today we have Travis Ross, the new CTO Federal for Rubrik. During the interview, you will learn about his fascinating career. Somewhat of a “Doogie Howser,” Travis was spotted early in his schooling to be a whiz at solving puzzles.

    DISA saw his potential and helped him with a scholarship and training to leverage these unique skills to solve some perplexing problems. The amazing part is that his scholarship letter arrived on September 10, 2001. The incident the next day set the stage for his career.

    He engaged in the early days of DoD PKI and the Public Key Encryption Program. After a distinguished federal career, he moved on to commercial organizations. He has chosen to work for Rubrik because he can apply the full spectrum of his varied skill set to apply commercial innovation to federal concerns.

    If you are not hooked by now, you may want to know what his thoughts are on topics like compliance, software development, and continuous improvement. The overview is that compliance must be a continuous process and security must be “baked in” the code before it ever gets released.

    Great perspective from a person who has sat in the federal and commercial seat helping federal leaders overcome major challenges.

    Twitter:  @FedInsider

    LinkedIn:    https://www.linkedin.com/company/fedinsider/

    Facebook:   https://www.facebook.com/FedInsiderNews

     

     

     

    36 min
  • Ep. 111 Tackling the Challenge of Operational Technology Security

    = = = =

    What happens if a patch means replacing a $500,000 piece of equipment?

     

    Malicious actors are equal-opportunity attackers. Of course, they will go after federal agencies in the cloud; they will also attempt to penetrate systems through good old-fashioned industrial equipment, assets, and processes – what has gotten the label “Operational Technology.”

     

    We take it for granted that when an exploit is discovered we can patch our systems, whether in the cloud or on-premises. There is a much different story when we switch from patching Information Technology to Operational Technology.

     

    Today’s interview brings together observations on reducing risk in operational technology from experts as varied as the NSA, CISA, and industry experts.

     

    Tony DiPietro from NSA highlights facts like OT can be widely dispersed geographically. Further, many of these systems are not as flexible as an app in the cloud. In other words, you cannot rule out a patch and correct the patch the next day. Some OT systems take a long time to propagate. Further, because of the high degree of variability, one patch will not work for all OT systems.

     

    The good news is that organizations like CISA have teams looking for vulnerabilities in OT. For example, Brandon Tarr discusses the fact that CISA has a five-phase method to seek out OT vulnerabilities. They work with over 3,000 independent researchers and that occurs across six hundred different vendors.

     

    Marty Edwards suggests that many software applications are designed to look for vulnerabilities in standard IT systems, but few for OT. He reiterates the assertion that you cannot protect what you cannot see. The idea is one must have a thorough understanding of all aspects of OT in the system you manage.

     

    One takeaway from the discussion is the dilemma that some organizations are facing. For example, what if you are in a hospital and have an MRI machine running Windows 95? The system cannot be patched and must be replaced. Can you justify a $500,000 expense for a new MRI?

     

     

    56 min
  • Ep. 110 DoD’s Roadmap for Zero Trust Strategy

     “We already have Zero Trust,” what to do when broke, and Beyond Thunderdome

    Today, we look at how the DoD is implementing Zero Trust Architecture.  We will see some areas that deployed ZTA before it was mandated; some teams that couldn’t afford ZTA, and finally, a look at something called Thunderdome that may allow the department to reduce the adoption time from five years to one year.

    Rick Simon is the cyber portfolio manager at the Defense Innovation Unit in Mountain View, California. Their mission is to reach out to commercial organizations and seek innovative ways to solve problems in the DoD.  Because of the risk of connecting to outside environments, since its inception, the DIU has always implemented Zero Trust principles before they were released into an initiative. 

    When you listen to the interview, Robert Kimball describes a group in the Army that wanted to move to Zero Trust because they were constantly failing penetration tests.  They had no money, so they did a “field expedient” and assembled the tools they had and, with this new configuration, managed to resist a red team penetration test.

    The military never fails to impress with names for projects, DISA’s project Thunderdome fits the bill.

    Rick Simon explains how it is a prototype that combines secure access with a wide range of technologies using Zero Trust as the approach to security.  This project can allow the military to drastically reduce the time to implement Zero Trust.

    Captain Patrick Thompson from the Coast Guard reinforces the concept that the cloud will give leaders the tools to move to zero trust, allowing people to get their jobs done at the speed of need even in areas of denied movement.

    The concept of Zero Trust is confusing, listen to the interview to get several approaches; one may work for your agency.

    Twitter:  @FedInsider

    LinkedIn:    https://www.linkedin.com/company/fedinsider/

    Facebook:   https://www.facebook.com/FedInsiderNews

     

    1 hr 28 min

About Feds at the Edge

From the publisher's feed

The federal government is changing the way it handles data. It is transitioning from an on premises data center approach to the cloud. Further, it is getting data from a wide ranging number of…