Zero Trust is a logical evolution of security in a world where remote access to networks and applications is more common than being on-site with an organization's data center. From cloud applications to the explosion of remote work, the traditional "castle and moat approach" simply does not scale or protect networks that are constantly being accessed by outside users.
The Biden Administration recently issued its request for 2022 spending. This practice is really more of a policy effort than actual budgeting, but serves to illustrate administration priorities to inform agencies as to what is likely to get approved in the final budget. The 2022 budget request has a number of IT-specific priorities, starting with the funding of the Technology Modernization Fund (TMF) at another $500 million for fiscal 2022. This would be in addition to the $1 billion that was invested as part of the American Rescue Plan Act--money that helped support the ongoing effort to digitize government services and operations.
The $58.4 billion in IT spending includes marked increases in the IT budgets of the Treasury Department, Department of Veterans Affairs, and the Department of Homeland Security. NASA and the Department of Commerce had small reductions to its IT budgets.
Both of these documents define the specific roles and responsibilities of data officers and provide a framework for working with and securing data. Of course, each agency has unique requirements and missions, leaving the CDO to work out how to apply this guidance and standards to their organization.
Agencies are meeting these guidelines and integrating CDOs in different ways. The Department of Homeland Security (DHS) recently announced a department-level CDO office to better integrate data into its operations and those of other agencies. The need for this level of coordination was underscored as DHS launched a department-wide COVID-19 vaccination campaign in partnership with the Department of Veterans Affairs health centers. DHS needed to identify, contact and manage responses from workers, which meant collecting and reconciling many different datasets from across the department.
Shared Services in government is nothingnew. The idea began in the 1980s with the consolidation of payroll and some other administrative functions. In the '90s the focus was on creating entities that could provide common business functions across government and, in that effort, become a cost center.
The 2000s saw the rise of the term 'Line of Business' that looked at common business functions across government to identify opportunities to transform, streamline and share. The Obama Administration looked specifically to IT as a shared service, releasing the Federal IT Shared Services Strategy that provided federal agency chief information officers and key stakeholders guidance. This guidance focused on the implementation of shared IT services as a key principle of their efforts to eliminate waste and duplication, with the intention to reinvest in innovative mission systems.
The Department of Homeland Security's Continuous Diagnostic Mitigation Program (CDM) was developed as a guideline process for agencies to fortify their ongoing cybersecurity plans and tactics. Agencies have worked through the stages of the program, first identifying what and who is on their network and then looking at what is happening on the network - really identifying the who, what, when, and where. Today, the focus is to put all that information to work in developing plans that address the "how" of secure networks including:
Reduce agency threat surface
Increase visibility into the federal cybersecurity posture
Improve federal cybersecurity response capabilities
Streamline Federal Information Security Modernization Act (FISMA) reporting
According to a recent survey, in the seven years since its inception, the CDM program has met its mission of making government IT systems more secure. But this success does not mean the work is done. Legislation has been introduced that will make CDM permanent and expand its reach to meet the ongoing cyber threats that face government agencies. Moving forward, the CDM will help agencies focus on taking what has traditionally been a piecemeal approach to cybersecurity and creating a more integrated approach that ties to the an overall cyber strategy.