
Sign up to save your podcasts
Or


In January of 2021, Executive Order 13985 titled Advancing Racial Equity and Support for Underserved Communities Through the Federal Government was released. Today’s discussion shows how agencies are responding to that mandate around identity management.
It would seem there should not be a problem. The goal here is to make sure everyone has access to benefits, loans, and even FEMA support. In an ideal world, a citizen accesses a federal website, gets identified, and continues through the process. However, we have people get frustrated with the digital process of identification to the point where they abandon their requests.
Today’s discussion looks at the NIST's special Publication 800-63 and its fourth draft revision, which mentions advancing the equity of identity management.
David Temoshok is one of the experts at NIST who drafted the document. He explains some of his thoughts about how to manage large numbers of people trying to get identified. He explains some of the challenges in digital credentials and some advances made, referencing login.gov. From a broader perspective, he thinks that a federated approach to identity management may be the solution.
The 2017 NIST 800-63 included multi-factor identification, the current draft tries to take this concept to the next level. It suggests ways to make MFA phishing resistant. One of the weaknesses of making identification “frictionless” is the risk of overprovisioning.
Bryan Rosensteel from Ping brings a good perspective to the challenges of digital identification, he thinks that it is an exciting time to be involved in the world of identification, especially in one new aspect like automation and identity lifecycle management. He mentions topics like military systems that are disconnected, yet still must maintain credentials.
Twitter: @FedInsider
LinkedIn: https://www.linkedin.com/company/fedinsider/
Facebook: https://www.facebook.com/FedInsiderNews
What do you do when your daily log entries increase by a factor of fifty?
Shane Barney, USCIS describes that prior to the cloud he had about 200GB of log data a day; after the move to the cloud, this was multiplied by 50, they are at 10TB a day. Obviously, it is not possible to use old tools for a workload this large.
Everyone reading this knows that when the federal government made the move to the hybrid cloud, they became deluged with data. The solution discussed today is something called Cloud Security Posture Management. This is an approach that automates identification and remediation of risks across cloud infrastructures.
During the interview, the federal leaders gave examples of how they have gone through a digital transition and assumed everything was configured properly. After the transition, the error became obvious. One takeaway is that pilots have checklists, and systems administrators need an automated checklist to look for compliance issues and misconfigurations.
Jeffrey Lush, U.S. Air Force, summarizes the need clearly: there is a gap between what you know and what you don’t know.
Each expert observed that managing a cloud network gives better visibility, for instance, being alerted to when there are open ports, open potentially exposed to the Internet. Further, an approach that includes CSPM can give administrators monitoring, validation, and compliance specifically tied to many areas of the Zero Trust. The net result is early threat detection.
In a rare instance of validation of a digital transformation, Shane Barney estimates that his agency saved $25 million in savings through deploying a Cloud Security Posture Management system.
Twitter: @FedInsider
LinkedIn: https://www.linkedin.com/company/fedinsider/
Facebook: https://www.facebook.com/FedInsiderNews
Getting exhausted after 4, 294,967,296 addresses.
If you have been around federal technology for the last fifteen years, you have heard people warning ad infinitum about what happens when we run out of IPv4 IP addresses. Somehow, we humans have managed to take the existing IPv4 system and apply duct tape and wire to make it endure.
Listen to today’s interview to hear the clarion call about IPv6. The federal government is finally getting serious about systems being compliant with IPv6. There is a wake-up call to have 50% compliance by 2025.
In November of 2020 the OMB issues memorandum M-21-07 which details the strategic intent to operate its networks and access the services of others using only IPv6.
Today’s interview focuses on many of the observations to this transition made by Robert Sears. He is the chair of the federal IPv6 Task Force. He leads the efforts to get agencies together and try to bring folks to discuss various topics on technology, transition, planning, and we also work with the private sector to help them understand how they can help the government meet its requirements to move to IPv6.
Robert Sears provides guidance with the technical as well as the regulatory impact of this transition. He makes the sage observation that the noble goals from fifteen years ago can finally be accomplished with the powerful new tolls available.
Cricket Liu expands the discussion to include consideration of applications. Federal leaders must realize some legacy applications may not be prepared to run over IPv6.
Listen to the discussion to see the weakness of the current dual mode of operating and learn best practices to make the transition.
Twitter: @FedInsider
LinkedIn: https://www.linkedin.com/company/fedinsider/
Facebook: https://www.facebook.com/FedInsiderNews
This episode will remind you of the old McDonald’s slogan, “millions and millions” served.
Did you know . . .
5.0 million open jobs in cybersecurity?
$1.0 billion was allocated by the federal government for grants to improve cybersecurity standards for state, local, tribal, and territorial agencies?
$1.6 trillion in Accounts Receivable at the Department of Education?
$10.5 trillion is the estimate for ransomware attacks by 2025.
When listening to this episode, you will learn approaches to these questions from all over the map and everyone from a federal official to a subject matter expert from Rubrik. By now, most government leaders know of the upcoming funding under the infrastructure funding. The overriding theme is how to be good stewards of this new funding.
Further, this distinguished group delves into topics like security awareness, Multi-Factor Authentication, and encryption.
One observation from Steve Hernandez, Department of Education is that today, we finally have the technology to deliver on the promise of zero trust.
Samy Bouhaouala, Accenture Federal Services observes that threat actors have the same machine language and artificial tools we have. This means we must be careful how we set up new systems.
You will be shocked when you learn of the increases in cyber insurance States have seen. There are reports of increases of as much as 500 million dollars for an annual policy. Ray Yepes, of the State of Colorado, conducted a survey and discovered that most States were self-insured.
Adding to this increase is the fact that some insurance companies are not including ransomware in their coverage.
This interview will give you specific figures to understand the cost and challenges in the future of government cybersecurity.
Twitter: @FedInsider
LinkedIn: https://www.linkedin.com/company/fedinsider/
Facebook: https://www.facebook.com/FedInsiderNews
Right now, we are in the hype cycle for AI, Gartner calls it the “peak of inflated expectations.” Representations are made and many surprises are unearthed. This is an interview that focuses on definitions, reliability, and automation about applying AI to problems warfighters face.
What is AI?
Years ago, Alan Turing came up with the baseline definition of artificial intelligence – being able to mimic human responses under specific conditions. Some individuals in the episode argue we haven’t even approached artificial intelligence. A statement is made that just because you call it AI doesn’t make it AI.
Is the data reliable?
Years ago, the colloquial phrase was, “garbage in; garbage out.” Today’s massive data stores reinforce this concept. However, the phrase becoming more and more popular is, “authoritative data source.” Each thought leader in the discussion has ideas on cleaning data.
What is the role of automation?
During the interview, Michael Pomatto NAVAIR suggests that today’s interpretation of artificial intelligence has ramifications in the systematic processing of information. Robotic Process Automation is the first step. When machine learning is added, he calls it hyper-automation. What does it mean to do mundane office tasks?
What does the future hold?
Jaime Fitzgibbon, Defense Innovation Unit makes a provocative statement when she asks how technology leaders can plan ten years out when game-changing technology hasn’t been invented yet.
Future interviews will expand into topics like scaling, the amount of data needed, and bias built into the algorithm. These experts set the baseline for a fascinating future.
Twitter: @FedInsider
LinkedIn: https://www.linkedin.com/company/fedinsider/
Facebook: https://www.facebook.com/FedInsiderNews
Reference: https://www.ynetnews.com/article/sjg0qah83
What if you were responsible for a network of 80,000 users in 24 time zones? Just for fun, let’s make you responsible 24 hours a day and mistakes can be fatal. Your challenge: react in 90 minutes or less to an intruder.
Is it an incident or a cable cut? This can sound trivial until you realize that you are dealing with a life and-death situation.
This is the incredible challenge that faces the United States Special Operations Command.
Today, we hear the tactics and strategies from two colonels in the unenviable position of having responsibility. Listen to the interview to get a new perspective on handling an overwhelming number of signals in a lethal environment.
Col. Joseph Pishock talks about the “grey space.” We know the military has its proprietary secure networks – what happens when one needs to optimize by using commercial services?
Col. William Uhrig suggests that commercial companies may have a lead in understanding the cyber threat in this “grey” space. If that is the case, then the military will have to figure out a way to safely and securely take advantage of commercial capabilities.
Twitter: @FedInsider
LinkedIn: https://www.linkedin.com/company/fedinsider/
Facebook: https://www.facebook.com/FedInsiderNews
Here is the dilemma. On one hand, there is a constitutional mandate that American citizens have the right to petition the government; on the other hand, today’s leading attack tool, phishing, uses email as its primary attack vehicle. Traditional filters and gateway security have proven weak against this threat.
Today’s discussion gives you the best practices for managing this quandary and leaving your federal agency open to communication from citizens as well as keeping it safe.
Keep listening and you will find more challenges to deploying mandated solutions. Randall Vickers from the U.S. House of Representatives notes that they do not play by the same rules as the rest of the government. They are not mandated to comply with standard cyber regulations, and members of the House own their data. This combination makes it important to have a deep and thorough understanding of security practices, and the flexibility to apply them in this unique environment.
When listening you will find out that cyber security is not as simple as locking down a system. Let us take the many recommendations about cybersecurity collaboration. We know that federal agencies should share information about threats. When this encrypted information is sent from one agency to another, it is normally decrypted, inspected, and then encrypted and sent on its way. However, there may be compliance issues that prevent this inspection.
Zero trust and information sharing sure look good when they are proposed on a whiteboard. This is an interview that opens up some of the practical aspects of lofty federal mandates.
Twitter: @FedInsider
LinkedIn: https://www.linkedin.com/company/fedinsider/
Facebook: https://www.facebook.com/FedInsiderNews
Can segmentation limit the impact from a blast zone?
Early cyber attackers would enter a system and then roam about, a virtual “land and expand.” Once it was detected, it could be isolated; the area impacted was termed the “blast zone.”
One approach to containing damage is to limit the “blast zone” by structuring your network into modules, or segment that would restrict movement. Some draw the analogy to a submarine that has compartments that would prevent sinking.
In the inevitable game of cat and mouse, malicious actors countered by commandeering the apps that run on the network, this would effectively override any network segmentation.
Illumnio suggests that if you segment the apps themselves, you draw boundaries around components, regardless of whether the network infrastructure is segmented or not. You will be able to minimize the impact.
Listen to the interview to see how to stop attacks that go beyond network segmentation.
High-speed Internet has been so much a part of the typical listener’s life that few remember the construction crew in your neighborhood when you got high speed Internet. Contrasted to that, we all know about the massive infrastructure bill that is attempting to level the high-speed Internet playing field for everyone in the United States.
Lisa Von Bargen from the Alaska broadband office presents a nightmare scenario for trying to give Internet to rural areas. When describing the geography of the last frontier, she states much of Alaska is roadless. What will come as a shock is, in some parts of rural Alaska, it can cost as much as a million dollars a mile to cover that final distance!
Geographic considerations are forcing Lisa and her staff and technology partners to be more creative about offering high-speed connections. Listen to experts from states like Michigan and companies like Federated Wireless show how they are being forced to be flexible and creative in their approach.
One topic brought up was a solution called a 5G Private Network. If you have a rural area and can get fiber to one part of it, there are systems today that can set up wireless services to that geographic area. This “5G Private Network” provides options for redundancy and security that others don’t provide.
Speaking of flexibility, when it comes to Citizen Band Radio, we normally think of truck drivers. Innovation has come to the Citizen Band Radio Service. Listen to how Federal Wireless and AWS are using new parts of the spectrum to provide Internet to remote tribes.
Twitter: @FedInsider
LinkedIn: https://www.linkedin.com/company/fedinsider/
Facebook: https://www.facebook.com/FedInsiderNews
Lessons from episode number one of Feds at the Edge can be applied to the ninety-nine that follow
At first glance, it is an interview about a tragic fire that befell the world-famous Notre Dame Cathedral in 2019; however, looking deeper you will see that the description risk management can be applied to the life of every federal information professional.
The federal government sits on a legacy system that has proven to be successful for decades. The Notre Dame Cathedral was built in 1163. Our federal system is encased in impregnable data centers, much like the limestone of the cathedral.
As evidenced by a plethora of Executive Orders, acknowledgment is given to make changes, like Zero Trust, to reduce risk. During the interview, you will find that the cathedral had a fire protection plan put together by experts. Unfortunately, it was not deployed for fear of the transition to a safer environment was too risky in itself.
From the perspective of a federal project manager, it is a case study of concepts like risk management, probability, and monitoring. What assumptions are you making about a black swan event and your security system?
“During our case study, today, we are going to look at some of the assumptions, factors, and components that shaped the fire protection plan. And that may have ultimately led to its failure.” Dr. Natalie K. Houghtby-Haddon, Associate Director GW CEPL & Assistant Professor, GW College of Professional Studies
“That public tweet occurred before the fire department arrived at Notre Dame” Dr. Natalie K. Houghtby-Haddon, Associate Director GW CEPL & Assistant Professor, GW College of Professional Studies
Petabytes of data and forests of trees: “And it was called that because the wooden beams that made up that attic dated back to the 12th and 13th century, and wood for more than 1300 trees were cut down and used in building that attic.” Dr. Natalie K. Houghtby-Haddon, Associate Director GW CEPL & Assistant Professor, GW College of Professional Studies
Firewalls are standard practice for all computer systems today. “Officials chose not to alter the attic with any modern fire safety measures measures such as sprinklers, or firewalls” Tom Brandt, Chief Risk Officer, U.S. Internal Revenue Service
“What is risk appetite, it's the type and amount of risk that an organization is willing to accept in pursuit of values.” Tom Brandt, Chief Risk Officer, U.S. Internal Revenue Service
Risk Management does not just apply to moving to the hybrid cloud. “So, as you're accepting risk, are you accepting something that's high likelihood? And if it were to occur? Are you accepting something that's high impact?” Alice Miller, Chief Risk Officer, Millennium Challenge Corporation
Twitter: @FedInsider
LinkedIn: https://www.linkedin.com/company/fedinsider/
Facebook: https://www.facebook.com/FedInsiderNews
From the publisher's feed