GSA / GSA/modernization

Comment from email: Comment on the "Report to the President on Federal IT Modernization"

Open
#37 0 comments 0 reactions 0 assignees View on GitHub
Public comment
Dominant language
CSS
Stars
59
Forks
8
PR merge metrics
No merged PRs in 30d

Description

We reviewed the Report to the President on Federal IT Modernization with great interest. SteelCloud has been involved in IT modernization projects across the federal government for more than a decade. This report is an impressive document. There are, however, two key areas that do/will have tremendous impact on the IT modernization effort that we believe were not adequately evaluated/discussed in the report. Both concern implementation.

Procurement/Acquisition – Federal IT modernization, as described in this report, can be characterized as variety of very large and small acquisitions. While the Federal Information Technology Reform Act made great strides in ‘fixing” some high-level procurement issues (DoD excluded), it actually did little to speed up the procurement process. Larger consolidated acquisitions geometrically increase the acquisition time, as they require RFI development/publication, RFP development/publication/bidding, and actual contracting. Projects can take years to acquire, and that is after the government has decided on requirements. Much of this complexity is because the government tends to purchase integrated “projects” or “programs” rather than products. Serious discussion about IT modernization must include realistic acquisition reform when contemplating substantially increasing the rate of IT modernization progress.

Accreditation Automation – It makes no sense to modernize IT with implementations that are inherently insecure. The government’s well thought out ATO (Authorization to Operate) accreditation process with RMF should be adhered to in the modernization process to ensure secure environments. RMF, FISMA, and FedRAMP all mandate that endpoints be hardened in compliance with either STIG or CIS controls. The issue that should be acknowledged in this report is that the hardening process takes weeks/months per application and there are not enough qualified IA (Information Assurance) personnel resources within the whole of the federal government and its mission partners to execute manual hardening activities for the IT modernization described in the report. The government has made stabs at fixing the problem with “Gold Disk” and secure images with little successful impact. The only reasonable solution to the STIG/CIS IA dilemma is hardening automation. Automated STIG/CIS remediation technology does exist. SteelCloud has implemented our ConfigOS patented STIG hardening/remediation automation technology in programs across the DoD, as well as within DHS, HHS/CMS, and the Dept. of Energy. All the benefits of IT modernization will be for naught if the new technology cannot be moved into production on a reasonable timetable. The STIG/CIS hardening process is a major headwind to getting applications through accreditation and into production.

We at SteelCloud would welcome the opportunity to make a productive contribution to this critical initiative. Please contact us for additional information and/or meeting on automating STIG/CIS compliance remediation in order to raise the government’s IT agility.

Regards,

Brian H. Hajost

President and CEO

SteelCloud

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.