FedRAMP 20x Keeps Government Cloud Use Moving

Earlier this year, the General Services Administration (GSA) announced a significant update to the Federal Risk and Authorization Management Program (FedRAMP). Named FedRAMP 20x, the focus of this initiative is on introducing automation to increase the pace of authorizations.

The Phase One pilot of this effort trialed a new approach to FedRAMP Low authorization. This automated process focused on Key Security Indicators (KSIs) rather than the traditional NIST SP 800-53 narrative control set. Vendors meeting the KPIs were granted a 12-month FedRAMP Low authorization. Using this process, the first FedRAMP authorizations were issued in just four months.

The GSA is now kicking off Phase Two, which will look at granting FedRAMP Moderate authorizations. Participation in this pilot is by invitation only, in order to ensure the small FedRAMP staff concentrates efforts on participants that are well-positioned to achieve Moderate authorization. The focus of this phase, "quality, not quantity,"-- is aimed at fine-tuning automated processes, with a target of 10 approved solutions. Continue reading

Improving Service. Improving Trust.

Improving customer service (or in the case of the government, citizen service) has been a focus of the Federal government for the past several administrations, most recently being named a key goal of the Biden-Harris President's Management Agenda (PMA). Despite this focus, citizen satisfaction with government service has remained low, but a 2022 report shows that the tide may be turning.

The American Customer Satisfaction Index's (ACSI) Federal Government Report 2022 showed that citizen satisfaction with Federal government services increased by 4.6 percent in 2022. Report authors attribute the increase to improved availability of digital services (spurred by the PMA and the Customer Service Executive Order) and major government initiatives including the distribution of free COVID-19 tests. Continue reading

FITARA Report Looks to Future Evolution

The 15th Federal Information Technology Acquisition Reform Act (FITARA) scorecard was issued in December 2022 to provide a look at how agencies are meeting modernization goals. Much like the 14th report, all measured agencies improved their scores or stayed the same indicating that changes are needed to ensure the report fully reflects today's modernization goals that have shifted from data center consolidation to cloud usage, and onward to Zero Trust cybersecurity strategies. The committee overseeing the scorecard, as well as industry groups, are looking at ways to better align modernization activities with the report.

FITARA 15 Findings

Currently, the seven active grading categories on the scorecard are: 1) progress in transitioning to EIS contracts; 2) CIO authority enhancements; 3) transparency and risk management; 4) portfolio review; 5) data center consolidation; 6) Modernizing Government Technology (MGT) Act; and 7) cybersecurity/FISMA. Continue reading

Facing the Future of Biometrics

With many of us using our faces to "open" our phones, biometric technology has become an everyday consumer technology. Capitalizing on the comfort and ease of use of facial recognition, government agencies are looking to incorporate it (and other biometric methods) into their modern cybersecurity plans and approaches but are realizing implementation in a government setting raises a host of complications.

Interest in facial recognition is strong

The U.S. Government Accountability Office (GAO) released a report in August of 2021 that detailed current and planned use of facial recognition technology by federal agencies. In a survey of 24 departments and agencies it found that 18 reported using the technology and 10 reported plans to expand their use of it. Continue reading

Are We There Yet? The Future of Modernization

There's no shortage of mandates and guidance related to modernization-PMA, Technology Modernization Fund, FITARA, Cyber EO, CX EO-pushing the government to update how they deliver services online, but what does it really mean, and what is involved?

Modernization in government began with transforming data centers and integrating cloud computing into government IT architectures and moved on to improving customer experience. Agencies have made inroads in all areas. The recent FITARA scorecard showed that data center consolidation goals have been completed. Cloud efforts have moved from Cloud First to Cloud Smart in an effort to ensure cloud was just not a checkbox but was being used to transform how the government consumes and distributes IT services. Citizen Experience (CX) has been a priority across three administrations with the next generation of CX efforts outlined in an executive order. These modernization efforts have resulted in billions of dollars in cost savings and increased efficiency for a government workforce that is now telework friendly, but the work is not done. Continue reading