GSA / GSA/modernization

Comment from email: comments on White House IT Modernization Plan

Open
#91 0 comments 0 reactions 0 assignees View on GitHub
Public comment
Dominant language
CSS
Stars
59
Forks
8
PR merge metrics
No merged PRs in 30d

Description

_[Editor's note: The original richly formatted email didn't translate well to text/Markdown, so I have also attached a .docx version based on a copy/paste of the email's original formatting. The comment author did not create the .docx, but it best replicates the formatting and is the most readable.]_

-----

[Dan Prieto - comments on White House IT Modernization Plan.docx](https://github.com/GSA/modernization/files/1323153/Dan.Prieto.-.comments.on.White.House.IT.Modernization.Plan.docx)

Thank you for the opportunity to comment on the proposed draft Plan for Federal IT Modernization. 

My comments are based on my prior experience in the Obama
Administration, where I served at various times as Director for
Cybersecurity Policy on the National Security Council staff, with a
focus on both privacy and federal network protections, and as Chief
Technology Officer in the office of the DoD CIO. The comments,
observations, and recommendations below reflect solely my personal
opinions as a private citizen and do not represent the opinion or
interests of any companies, organizations, or institutions with which I
am affiliated.

Sincerely, 

Daniel B. Prieto

 

1)      The report makes a notable and constructive innovations as
regards policy development.  At various points it calls for “an agile
process which will enable us to iteratively update policy and technical
guidance” and “piloting new implementation approaches, and using these
test cases to inform rapid policy updates.” Such an ongoing and
iterative policy process would be highly preferable to the current
approach that relies on occasional “big bang” batch updates to
policy.  For example, agile and continuous improvement in TIC and other
cloud security policies would be highly preferable to waiting years
between policy updates, which result in well-intentioned policies that
inadvertently impede progress.

> a.       ****Recommendation:****  ***In addition to informing policy
> changes based on case studies, use cases, and data calls from
> departments and agencies, the White House should establish a parallel
> and complementary process that allows industry to submit use cases and
> recommendations that can serve as inputs for the proposed “agile
> process” of “rapid policy updates”.***
>
>  

2)      In the section on enabling use of commercial cloud services and
infrastructure, there is a requirement that within 30 days, OMB issue a
data call “requesting that agencies identify systems that may be ready
for cloud migration and can be migrated securely but have not yet
migrated due to perceived or encountered difficulties.”

> a.       ****Recommendation:  It would be valuable to alter the
> language of the requirement so that the focus is not on “systems”, but
> rather on “systems or system components, functions, processes, and
> capabilities that may be ready for cloud migration.”  I would
> recommend a conforming change, as appropriate, in any other areas of
> the document that reference “systems” that might be amenable to cloud
> migration.****
>
> b.      The concern with the language as written is that while an
> entire “system” may not be ripe for cloud migration, various aspects
> of a system might be.  Focusing on entire systems may create too high
> a bar, result in reluctance or opposition to consider cloud
> options,  and lead departments and agencies to fail to nominate a
> system, even though certain components or aspects of that system might
> be amenable to cloud migration.  The proposed language modification
> would allow departments and agencies to think more flexibly and
> creatively, shift their focus from entire IT systems and programs, and
> increase the likelihood that component parts and layers of those
> systems and programs might move to the cloud.

 

3)      While the document explicitly mentions “current ATC supported
efforts to improve the Authority to Operate (ATO) process”, I do not
believe that it proposes reforms and improvements to the FedRAMP
certification process. 

> ***a.***      ****Recommendation:  The authors of the White House IT
> Modernization Plan should consider having the Plan direct an effort to
> reform the FedRAMP certification process. ****

 

4)      The Report contains a 120 day recommendation on updating the
Cloud First policy with a focus on developing contract clauses with
requirements for security, privacy and access to data. These clauses
will ensure uniformity in contract language and provide rigor to
standard Government terms, “which would be particularly valuable to
agencies lacking relevant technical, legal, or acquisitions expertise to
craft, out of whole cloth, such language in their cloud procurements.”

> ***a.***      ****Recommendation: It would make sense to expand the
> range of uniform clauses and contract language beyond security,
> privacy and access to include:****
>
>                                                               ***i.***      ***Property
> and ownership interest in agency information***
>
>                                                             ***ii.***      ***Confidentiality,
> non-disclosure and government interests***
>
>                                                           ***iii.***      ***Notice,
> authorization and referral provisions, and***
>
>                                                            ***iv.***      ***Direct
> damages, indemnification and other remedies***
>
> ***b.***      **** Recommendation: The White House IT Modernization
> Plan should consider creating a process that allows industry to submit
> proposed model contract language.****

 

5)      In the section on existing and additional shared security
services, recommendations to improve continuous monitoring focus largely
on tweaks to DHS’ CDM program. 

> a.       ****Recommendation: The White House IT Modernization Plan
> should propose and promote the increased adoption of continuous
> monitoring capabilities outside of implementation the CDM
> program.  ****For example, continuous monitoring capabilities could be
> provided by commercial cloud providers rather than by the adoption by
> departments and agencies of on-site tools provided via existing CDM
> program awardees.
>
> ***b.***      ****Recommendation: The White House IT Modernization
> Plan should recommend and seek the modification and update of existing
> continuous monitoring policy.  Such modifications and updates should
> require that departments and agencies possess, in real or near-real
> time, the capability to comprehensively and in an automated fashion,
> interrogate, identify, map, and inventory all hardware assets,
> software assets, and organizational communications and data flows.****
>
>                                                               i.      Current
> policy on information system continuous monitoring (ISCM) stems from
> 2011, NIST SP 100-87.  Per NIST 100-87, ISCM entails “maintaining
> ongoing *awareness of information security, vulnerabilities, and
> threats* to support organizational risk management decisions.”  This
> requirement is at a sufficient level of generality and abstraction
> that, in practice, it fails to require departments and agencies to
> possess real-time or near-real-time visibility -- comprehensively and
> at a granular level -- into the entirety of an organization’s IT
> assets and IT environment.  Similarly OMB A-130 contains the
> requirement that departments and agencies maintain an inventory of
> systems, but, as written, OMB A-130 does not require comprehensive and
> granular visibility, in real or near-real time, into an organizations
> IT assets and environment.  IT environments are fluid and dynamic, and
> any inventory becomes rapidly out of date.  In an incident,
> comprehensive, timely, and up-to-date visibility into all of a
> department or agency’s IT assets is critical. 
>
>  

6)      The Modernization report requires "OMB, working with the Federal
Acquisition Regulation (FAR) Council, GSA, and DHS will develop clauses
that define consistent requirements...which would be particularly
valuable to agencies lacking relevant technical, legal, or acquisitions
expertise." 

> ***a.***      ****Recommendation:  The White House IT Modernization
> Plan should consider proposing that OMB, the FAR Council, GSA, and DHS
> jointly be required to mandate education and training to ensure that
> agency technical, legal, and acquisition professionals are apprised of
> and up to date on the most recent policies and guidance regarding
> federal IT management, information security and cybersecurity, and
> privacy.  In addition, such training should reinforce with acquisition
> and related professionals that the FAR requires them to consider
> mission risk in their acquisition decisionmaking (for example, the
> risks that are posed to mission as a result of insecure IT, inferior
> IT, or delayed investments in IT), not just risks associated with
> acquisition processes (which is where most acquisition officials
> focus).****
>
> b.      There has been a significant amount of new policy on IT
> management, security, and privacy within the last 36 months.  The FAR
> requires that acquisition and acquisition-related professionals act in
> accordance with existing U.S. government policy.  Given the volume and
> complexity of the recent wave of new policy, it is likely that many
> acquisition and acquisition-related professionals have not kept pace
> with the breadth and complexity of new policy requirements (for
> example, the OMB A-130 guidance to not build new systems if such
> capabilities can be acquired commercially as services; or the positive
> requirement to encrypt medium and high impact data).  Lack of
> awareness or understanding of the most up-to-date policies could
> contribute to risk aversion by acquisition and related professionals
> when it comes to adopting innovative technology solutions or
> alternative IT-delivery models, such as cloud.

 

7)      Risk aversion or lack of education among contracting and related
officials can be a significant barrier to the adoption of innovative
commercial capabilities or non-traditional IT delivery models, including
cloud adoption.

> ***c.***       ****Recommendation: The White House IT Modernization
> Plan should consider recommending the creation of an IT advisory or
> “appeals” board -- comprised jointly of members of the CIO Council,
> CISO Council and the Chief Acquisition Officers Council -- to ensure
> that requirements setting and acquisition decisions are appropriately
> meeting the goal of modernization.****
>
>                                                               i.      Such
> a board could provide a known escalation and validation process that
> allows IT buyers and contracting officers to seek additional
> subject-matter expertise on IT and contracting, especially in
> situations where there might be disagreements regarding the design and
> direction of an IT project or as regards the award.  Such a board
> could provide useful “top cover” for contracting officers so that they
> might feel less at risk and more at ease when making creative or
> non-traditional IT acquisition decisions.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.