Goodbye RMF, Hello CSRMC

The Risk Management Framework (RMF) was introduced in 2022 to create a standardized way to measure and manage cybersecurity risk in the federal government. Modeled with standards including the Federal Information Security Modernization Act and NIST Special Publication 800-53, the RMF was a repeatable, structured method to manage cybersecurity risk and ensure compliance with federal standards. The RMF allowed agencies to identify, understand, prioritize, and reduce risks to their information systems and missions. It informed leaders of security risks, allowing them to make educated decisions about trade-offs between security and mission needs.

While it was designed to be more than a checklist, in practice the RMF had become just that. Rather than engaging with it dynamically, agencies employed highly manual processes that slowed the adoption of much-needed solutions. The process could not keep up with the quickly evolving threat landscape. Continue reading

How Cyber Basics Make a Big Impact

October is a fitting month for cybersecurity awareness. Phishing emails can be even more deceptive than a convincing costume and ransomware attacks can feel like a jump scare in a horror movie. Each year, the National Cybersecurity Alliance and the U.S. Department of Homeland Security spearhead an educational campaign to ensure everyone knows their role in protecting the vast amounts of online data we depend on for daily life.

The 2025 theme is "Stay Safe Online" with a focus on four key steps everyone can take to improve online safety:

  • Use strong passwords and a password manager
  • Turn on multifactor authentication
  • Recognize and report scams
  • Update your software

These tactics are important at a personal as well as enterprise level. Agencies across government have taken these best practices and implemented new security measures to protect data. Continue reading

Out-of-this-World Geospatial Benefits

The applications of geospatial data are expanding beyond its original use for mapping. With mandates for government agencies to become increasingly data-driven, the ability to tie location data into planning has become a valuable asset. Integrating geospatial data into planning and operations helps agencies meet broad goals of efficiency, transparency, and preparedness.

Government Efficiency

Utilizing geospatial technology in conjunction with Internet of Things (IoT) sensors and cameras, agencies can automate field inspections. This means capturing changes in infrastructure (a crack in a bridge support, a building constructed without a permit, a leak in a water line) and passing on important information to the people who inspect and fix these assets. While a traditional on-site inspection can take 30-50 minutes (not counting travel time), If the bulk of the assessment is completed before arriving onsite, inspectors can spend less time there, examining only the captured changes or most critical elements of the assessment. Continue reading

Improved Technology Means Improved Citizen Service

A focus on government efficiency should benefit citizens by yielding improved service and better stewardship of tax dollars. Efforts have been underway across government for decades to improve service to the citizen. With the government embracing artificial intelligence (AI) and new security paradigms, the digitization of government continues to accelerate in support of citizen service.

Paperwork Reduction

The Paperwork Reduction Act of 1980 kicked off the government's focus on reducing both paperwork and manual effort. Now a new piece of legislation may accelerate efforts further. The ePermit Act was introduced to create an interagency data system to serve as a single point for tracking real-time data on environmental reviews. Currently, agencies have siloed systems that make it difficult to share information, even though permitting often spans multiple agencies. This act responds to the administration's desire to streamline regulatory compliance, easing burdens on industry. Continue reading

Blockchain’s Role in Blocking Fraud

Blockchain technology has gained traction across the U.S. government as a practical tool for multiple diverse purposes. From streamlining procurement to preventing fraud, agencies are increasingly exploring how blockchain can enhance transparency, security, and efficiency in federal operations. However, with innovation comes risk. The government is also looking into how to ensure the technology is not misused to conceal illicit activity, commit fraud, or obscure accountability.

Fraud Prevention

Since every transaction in a blockchain is recorded permanently, malicious actions are traceable, which increases accountability. Each transaction is unique and chronologically linked, meaning a record cannot be copied, altered, or duplicated without triggering detection. This level of traceability allows governments to confirm that payments are going to the intended recipients. For foreign aid, payments can be tracked not just to the intended country but as they continue on from there. In terms of domestic benefits, blockchain can verify the identities of welfare recipients, while simultaneously confirming their eligibility. Continue reading