Comment from email: Microsoft's comments on IT Modernization Report
- Dominant language
- CSS
- Stars
- 59
- Forks
- 8
- PR merge metrics
- No merged PRs in 30d
Description
_[Below are comments sent in by email. Author details below.]_
-------
There are consistent points of emphasis from our review that have material impact on achieving the goals set forth in the report including:
* **Revising the FISMA and FedRAMP Certification Process.** Currently, there are three distinct challenges with the certification process necessary for agencies to contract for and deploy IT:
* **Agencies with similar risk profiles and security needs are unable to leverage each other’s work**—We believe that the case should be made for agencies being able to reuse other agency certification approvals.
* **The Certification Process is too long and cumbersome and not tuned to today’s technology**—Unless FISMA and FedRAMP radically redefine their certification models, it will be impossible for agencies to reap the benefit of perpetual evolution of the service because technology providers won’t be able to qualify newer versions fast enough.
* For example, FISMA’s approach to developing prescriptive security controls stifles government’s ability to take advantage of the latest security breakthroughs. Moving to an outcomes based approach, letting IT providers develop and continuously innovate on the methodology, and using clearly defined metrics to hold vendors accountable will better serve the government’s technology needs.
* **The government can and should rely on commercial certification processes when possible**—There is a potential opportunity for low risk estates to rely on commercial certification processes, like ISO standards, rather than reinventing a government specific standard.
* The resulting latency, redundancy, and lack of reciprocity amongst agencies for these approvals create a barrier to progress and is something that is ripe for improvement by exploiting the cloud and accelerating modernization. As you know, we have invested heavily in Government and Defense-certified cloud capabilities at all levels of compliance. The difference between agencies that are able to exploit cloud and those that cannot are often due to resources and process latency as a result of ATO paperwork. We are happy to cite specific opportunities and potential remedies that would allow the Administration to leverage cloud solutions immediately.
* **Review of the current Trusted Internet Connection (TIC) policy.** Again, we fully support the Administration's recognition that the TIC is not optimal for either the cybersecurity or modernization goals set forth in the draft report. We would again offer to contribute in any way to ideas for resolution.
* **Endpoint Modernization.** To drive the security posture the government wants, we recommend the report expressly reference endpoint modernization. To adopt a new security posture, agencies need a holistic, agile platform with security built-in. Agencies need to appropriately secure their identities, devices, applications, data, and infrastructure whether it is in the cloud, on-premises, or both. To do this you need to invest in technology across the entire platform focused in four key areas: Identity, Device, Apps & Data, and Infrastructure. Ideally, this would also include a more robust discussion of identity management, with potentially a nod to a complete overhaul and rethink of government wide identity management for both employees and citizens. One of our recommendations is to encourage a separate report on this issue alone.
The points above (as well as other factors) also impact the pace at which the Government can fully exploit existing investments across cybersecurity, shared services, collaboration, citizen services, datacenter consolidation, analytics, and innovation that truly drives transformation.
Ed Ingle
General Manager, Government Affairs
Microsoft Corporation
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.