Feds at the Edge

Feds at the Edge

By FedInsiderTechnologyGovernment
Download on the App Store

Feds at the Edge episodes

  • Ep. 70 Identity Management Lays the Foundation for Zero Trust

    This is a discussion that provides the listener with ideas of how agencies are adopting identification to enable to zero trust and gain some insight into the evolution of access control in the federal government.

    The federal government certainly is not a monolithic enterprise; it must manage mundane requests like access to National Parks as well as negotiate atomic energy agreements.

    NIST has reinforced the fact that identification is the first component of deploying Zero Trust. When a mandate comes from the White House to target Zero Trust, it makes sense that each agency will have a history of identification systems and have a different level of sophistication when it comes to identity management.

    Bryan Rosensteel from Ping gives a remarkable analysis of the evolution of Attribute Based Access Controls. His purview is immense. He begins by examining the historical application of Attribute Based Access Controls. He comments they were effective but tedious to deploy.

    To streamline this system, Role Based Access Controls were implemented. Unfortunately, today’s technical climate allows malicious actors to steal identities and defeat the RBAC method. Bryan Rosensteel argues that today’s dynamic system will have to revert to the precise controls that ABAC provides.

    The weakness of Multiple Factor Authentication is reviewed by David Temoshok, NIST. He suggests that when a person gets a code via SMS text message, it is transmitted via the public telephone system. He calls this weak MFA. This is another reason today’s Role Based Access Control, can provide the kind of security that some agencies require.

    FEMA’s needs for identification are broader than most. Dr. Gregory Edwards from FEMA understands the complexity of cryptographic identification models, but he also recognizes that he cannot give every flood victim a federally issued PIV card. Solutions must be provided where FEMA optimizes quick access to federal assistance while maintaining security controls so vital for federal information technology.

    Listening to this podcast will give the listener a terrific overview of innovations in access control and the variety of ways federal agencies are coping with identification with the new focus on Zero Trust Architecture.

    1 hr 1 min
  • Ep. 69 Compliant Data is the Universal Fuel for Agencies

    Some will argue that COVID has forced federal agencies to move to the cloud and drastically increased remote access.  One of the unintended consequences of this transition is a realization that the data that is created in these environments must be managed much better than in traditional, on-premises circumstances.

    If agencies are all on the same page with classifying and managing data, that will reduce friction and allow agencies to get the maximum benefit of all this data and understand patterns and trends.

    Hannah Hunt is the Chief Product and Innovation Officer for the Army Software Factory.  They are the leading edge at agile software development in a highly secure environment. To rapidly develop solutions, they may spin up environments where data exists for an hour.  Given those constraints, it only makes sense to have continuous security and continuous compliance with the data.

    One obstacle to being able to work with data sets in an extremely flexible environment is starting with effective data management.

    Unfortunately, in the commercial world and the federal government, a lot of data management is still manual.  No systems administrator would pause to automate the production of a new virtual environment, but eyebrows are raised when data is managed in an automated manner.

    During the discussion, the topic of Shadow IT was brought up.  For example, if a system is set up for compliance and it takes days to get answers.

    Human beings, as they will, will find ways to circumvent these compliance models and subvert the system.

    That is why Dan Graves from Delphix suggests that if you produce a data management system that is compliant and fast, that will reduce the temptation for end users to set up apps that are independent of the compliance requirements.

     

    59 min
  • Ep. 68 Reimagining Higher Education to meet Post Pandemic Imperatives

    The COVID pandemic has impacted society in many ways, this discussion looks at aspects of change in higher education in learning environments, IT transformation, and protecting the infrastructure. Companies like Nutanix offer tools and systems to reduce cost and improve cybersecurity in this transition.

    Before the COVID crisis, considerations were given to online learning, but the focus was on traditional, classroom teaching. Higher education led the way in adapting to the new environment. Paul Padley from Rice University shows how his university had to drastically increase video capabilities for teaching.

    Logically, the university had to buy more storage for these videos.

    College systems had to learn how to manage this increase in storage. The result was the hybrid cloud world we live in today. Systems had to be improved to focus on speed and had to enhance governance to prevent cyber-attacks.

    While the systems administrators had to worry about the structure of the data storage systems, the academics had to concern themselves about the structure of the classes offered. Students started to trend older with an interest in seeking new short-term credentials.

    An increase in online offerings challenged leaders to improve identity access and management.  Traditional systems expected full-time students to be on campus with network access; now, we see remote students with few classes expecting the same access to college learning systems.

    The federal government has responded to these needs by offering grants that can assist universities in this transition.  Many of these grants include requirements to increase cybersecurity before the aid is transferred. 

    Some universities are applying virtualization to accomplish this task. Systems can be configured to allow for a “virtual” desktop.  This means that a student will be allowed access to a limited environment where strict controls are placed in a designated area. This allows Role

    56 min
  • Ep. 67 Advancing Data Protection in the Cloud

    Cloud Service Providers have no problem sharing with you the number of data centers they own, the flexibility of options, and the ease to start in the cloud. However, what is never overtly stated is that the federal technology manager is responsible for the security of their data if it is on the server down the hall or in the cloud.

    The conversational phrase is, “they are not on the hook for the security of your data.” 

    Today, we have several perspectives on understanding how to protect federal data in the cloud. Experts from three areas provide their views on data protection, standards, and working in a cloud environment.

    When it comes to protecting data in the cloud, Skip Bailey from the U.S. Census Bureau thinks that one needs to approach it strategically first. Each of the three main Cloud Service Providers has proprietary ways of handling aspects of data control. If you think you are going into a multiple cloud environment and plan or relying on one set of rules, you are mistaken. You will need staffing to support these multiple clouds.

    As in other endeavors, standards bodies can provide guidance that can assist in coming to terms with handling heterogeneous environments, in this case, varying cloud providers. Craig Hurter from the State of Colorado suggests that one should get comfortable with ISO specifications like the ISO 17789 as well as some of the general guidelines from the Cloud Security Alliance. That way, you can compare the terms of service for each Cloud Service Provider with whatever standards you choose.

    It seems likely that a multi-cloud world is where federal data lives. If that is the case, then it would behoove managers to be able to evaluate each Cloud Service Provider’s capabilities. Each cloud may have options to allow control, the key is to understand how those cloud provider’s proprietary offerings compare to commercial ones.

    Sterling Wilson suggests that you start with three questions. What happens if you delete data. How easy is it to deploy Multi-Factor Authentication? What about the security of data in transit?

    One concept that Craig Hurter brings up is the idea of architecting data storage in depth. The idea is that the initial system is solid, but, over time, something called “drift” takes place. Updates may not all be installed promptly; other maintenance can be delayed. What may happen is you can lose security over time, while still holding to the initial design specifications.  You may have “drifted” without knowing it.

    57 min
  • Ep. 66 Digital Transformation as Infrastructure

    An argument can be made that the Infrastructure Investment and Jobs Act of 2021 is a once-in-a-lifetime opportunity to ensure the viability of the American dream for the next several generations. This is an interview with a group of federal and state leaders who are serious about using the money effectively to optimize this long-term investment.

    The discussion begins with an observation that COVID forced rural communities to realize that their children couldn’t attend school without broadband access. Broadband access also could improve telemedicine and business.

    The IIJA addresses this disparity by improving broadband to rural areas.

    Lee Jones from the USDA identifies the Rural Partners Network as a pioneer in connecting rural communities to foster economic growth. They help with navigating federal programs and listening to the community for guidance on projects. The IIJA will, by necessity, include information technology to manage the funding effectively. 

    There will be rural participants who fear this concept and may not have the trust in the federal government that others have.  Shannon McCarthy from the State of Alaska understands these concerns and has incorporated ways to deal with this reluctance, including ways for citizens to be anonymous.

    Everything involves risk, especially multi-million-dollar federal projects. One unfortunate circumstance is when COVID increased everyone’s online presence, there was a corresponding increase in cyber-attacks.  If the Rural Partners Network can help rural communities with understanding federal programs, then CISA also helps with understanding cyber risk.

    Free information about preventing a cyber-attack is provided by CISA. Dr. David Mussington from CISA details the free tools that are available to understand these new attacks and ways to prevent organizations from digital-born disasters.

    1 hr
  • Ep. 65 Basic Cyber Hygiene & Zero Trust Principles

    Federal mandates are strongly encouraging agencies to apply Zero Trust. You do not just put on a pair of shoes and run the Boston Marathon; in a similar vein, you do not flip a switch, and the next day your agency has applied Zero Trust Principles. You should understand how your system needs to be prepared, then design a plan that will make the transition timely and effective.

    Today’s guests give guidelines on this “hygiene” and what transition concepts to keep in mind.

    Alvin "Tony" Plater, U.S. Department of the Navy, suggested that just because you are compliant, does not mean that your system is acceptable. Of course, he recognizes the value of regulations, but he thinks a well-structured system should go beyond compliance. For example, he views the importance of data integrity as a key component of maintaining existing systems.

    Zero Trust requires you to assign access to people based on many characteristics, one being their role. Nothing new here, Role Based Access Control has been around for decades, but its implementation has been cumbersome at best. Consider role-based controls that give ease of use for system administrators.

    Another aspect of hygiene is to make sure your existing systems all have user-supported versions. Using an older system that is about to go out of service has been called a “secretive vulnerability.”  Unfortunately, one unexpected consequence of this maintenance could be more vulnerabilities. The basic hygiene concept is you cannot go to Zero Trust without a clean start.

    From an architectural standpoint, you should know all your endpoints as well as have an enterprise architecture that can lock a malicious actor’s exploits into a limited area, what some call a “limited blast radius.”

    The U.S. Patent and Trademark Office (USPTO) was a pioneer in remote work, even before COVID. Leadership at the agency recognizes the fast change in technology, even in the past three years. For this reason, the USPTO is changing to a Secure Access Service Edge initiative that will increase the ability to dynamically filter endpoint activity.

    Humans have a dominant role in this transition. Each of the participants agrees that getting the right people behind the tools is the fastest way to increase security through Zero Trust.

     

     

    1 hr 2 min
  • Ep. 64 Bringing New Applications to Federal Financial Oversight

    Professional sports broadcasters frequently use the phrase, “taking it to the next level.” Well, when it comes to improving application development in the federal world, taking it to the next level can involve some new concepts presented in this discussion.

    This is an interview with three professionals who have worked on many federal projects. They provide the listener with guidelines for making the transition with minimal expense and maintaining federal security standards.

    The discussion opens with a contrast between the traditional method of developing software and the way it is done today. Chris Moran from GDIT estimates 90% of systems generated today are comprised of third-party applications. In other words, it is assembled rather than coded line for line. This new method allows for flexibility and rapid development.

    Two other methods for deploying software were introduced in this discussion. When multiple applications are deployed over multiple clouds, a person dedicated to reliability must be included in the team, usually referred to as a “Site Reliability Engineer.”  This person is tasked with maintenance, patching, and increasing automation for those responsibilities.

    1 hr 2 min
  • Ep. 63 Securing Citizen Data

    The last few years have presented a “perfect” storm for malicious actors to tap into sensitive data.  It’s one thing to opt into something like Facebook and have them lose your data.  It is quite another when a state or federal organization has your data, and it is compromised.  No blame on the citizen in this case.

    That is why people who are employed by the state, local, and federal agencies take the concept of securing citizen data seriously. This sense of responsibility is evidenced in the interview between a technology leader from the State of Colorado and a technical expert from Rubrik.

    Today’s discussion ranges from best practices for securing data, zero trust in the cloud, realistic concerns, and the realities of a post-COVID world. One of the dominant parts of the conversation is the move to the cloud.

    Sterling Wilson from Rubrik details three aspects of a cloud transition that must be considered.

    First, which data will be moved to the cloud?  If the data is compromised and transferred to the cloud, you are merely moving a problem from one area to another.  It could be a ticking clock with malware waiting to launch.

    Secondly, many don’t realize that when an agency chooses a cloud service provider, there is no implied responsibility to back up that data.  To secure citizen data, technical leaders must realize that this concept must be addressed.

    Finally, will the cloud solution provide the same security that you have in your on-premises application?

    Access to this data was also presented in the discussion.  Yvette Florez mentions the Fast Identity Online Standard as a common approach that many governmental organizations can take advantage of when seeking to bolster their authentication process.

    57 min
  • Ep. 62 The Cybersecurity Effect How to Mitigate Risks, Safeguard your Network, and Plan for a Future of Constant Change
    So many federal information technology professionals have been hit by cyberattacks that they know it is a never-ending battle.  The real question is – what is the most effective way to implement a digital transformation to react to this constant attack?

    Today’s discussion brings together two people who have been responsible for managing highly visible networks, a cybersecurity expert from the FBI, and an expert from a technical partner that can bring an overview to the discussion.

    Clarice Kent from the U.S. Marine Forces Cyberspace Command begins the discussion with a valid point – you can’t take advantage of leading-edge technology with legacy infrastructure.  Rather than a full swoop approach, the Marines are approaching the network upgrade systematically.

    After she observes existing technology, she extends her remarks to the security stack.

    59 min
  • Ep. 61The Role of Digital Technology in Successful Public Infrastructure Project Management

    Last year the monumental Infrastructure Investment and Jobs Act was passed by Congress. It has $450 billion earmarked to renew existing programs and $550 billion designated for new federal spending. As the name implies, most money will go to roads & bridges, railways, and other public projects.

    The question is – how can this enormous amount of money be efficiently distributed, managed, and audited? Today’s discussion gives the listener seven perspectives on answering these important questions. The topics reviewed include expanding access to this appropriation, digital transformation, and risk management.

    Study after study has shown the number one priority for rural citizens is access to broadband connections. The question is – where to start? Xochitl Torres Small from the USDA opens the discussion by claiming that, up until now, many of the maps that show coverage are not accurate.

    1 hr 26 min

About Feds at the Edge

From the publisher's feed

The federal government is changing the way it handles data. It is transitioning from an on premises data center approach to the cloud. Further, it is getting data from a wide ranging number of…