The Open Source Revolution in Government

Open source technology accounts for a significant portion of most modern applications, with some estimates going as high as 90%, and it is the foundation of many mainstream technologies. Its strength lies in the fact that a vibrant ecosystem of developers contribute to and continually improve the underlying code, which keeps the software dynamic and responsive to changing needs. Enterprise open source software further augments these community-driven projects by providing enterprise-grade support and scalability, while retaining the innovation and flexibility driven by the open source development model. By providing the best of both worlds, such solutions represent a powerful arsenal of tools for addressing government’s most pressing challenges. In a recent pulse survey of FCW readers, 93% of respondents said they were using open source technology. And more than half of respondents to FCW’s survey see open source as an integral resource for strengthening cybersecurity. That number reflects a positive trend toward a better understanding of open source software’s intrinsic approach to security. The power of enterprise open source technologies lies in a combination of collaboration, transparency and industry expertise. As agencies expand their use of such technologies, they maximize their ability to achieve mission success in the most secure, agile and innovative way possible. Learn how the combined power of community-driven innovation and industry-leading technical support is expanding the government’s capacity for transformation in Carahsoft’s Innovation in Government® report.

 

Why Open Source is a Mission-Critical Foundation  

IIG FCW Open Source Revolution November Blog Embedded Image 2022“Open source transforms the way agencies manage hybrid and multi-cloud environments. The most critical technology in the cloud, across all providers, is Linux. Everything is built on top of that foundation — both the infrastructure of the cloud and cloud offerings. Given the right partner, the promise of Linux is that it provides a consistent technology layer for agencies across all footprints, including multiple cloud providers, on-premises data centers and edge environments. From that foundation, agencies and their partners can build portable architectures that leverage other open source technologies. Portability gives organizations the ability to use the same architectures, underlying technologies, monitoring and security solutions, and human skills to manage mission-critical capabilities across all footprints.”

Read more insights from Christopher Smith, Vice President and General Manager of the North America Public Sector at Red Hat.

 

How Open Source is Expanding its Mission Reach

“The real power of open source technologies was revealed when they cracked the code on being highly powered, mission-specific, distributed systems. That’s how we are able to get insights out of data by being able to hold it and query it. Today, open source innovation is being accelerated by the cloud, and the conversation is still changing, with people now demanding that their open source companies be cloud-first platforms. Along the way, the open source technologies that start in the community and then receive a boost of commercial innovation have matured. The most powerful ones are expanding their ability to address more of the government’s mission needs. They are staying interoperable and keeping the data interchange non-proprietary, which is important for government agencies.”

Read more insights from David Erickson, Senior Director of Solutions Architecture at Elastic.

 

The Open Source Community’s Commitment to Security  

“A central tenet of software development is visibility and traceability from start to finish so that a developer can follow the code through development, testing, building and security compliance, and then into the final production environment. Along the way, there are some key activities that boost collaboration and positive outcomes, starting with early code previews, where developers can spin up an application for stakeholders to review. Other activities include documented code reviews by peers to ensure the code is well written and efficient. In addition, DevOps components such as open source, infrastructure as code, Kubernetes as a deployment mechanism, automated testing, and better platforms and capabilities have helped developers move away from building ecosystems and instead focus on innovation.”

Read more insights from Joel Krooswyk, Federal CTO at GitLab.

 

The Limitless Potential of an Open Source Database

“One of the most important elements of any database migration is ensuring that proper planning and due diligence have been performed to ensure a smooth and successful deployment. In addition, there are some key considerations agencies should keep in mind when moving to open source databases. It is essential to start with a clear understanding of the business case and objectives for adopting an open source approach. Agencies also need to decide how the database should function and what it should do to support their digital transformation. Then they must choose the optimal method to deploy the database.”

Read more insights from Jeremy A. Wilson, CTO of the North America Public Sector at EDB.

 

Modernizing Digital Services with Open Source

“A composable, open source digital experience platform (DXP) enables agencies to overcome those challenges. Open source technology is continuously contributed to by a community of developers to reflect a wide array of needs across organizations in varying industries and of varying sizes. A composable approach allows agencies to assemble a number of solutions for a fast, efficient system that is tailored to their needs. When agencies combine a composable DXP with open source technology, they have access to best-of-breed software and the ability to customize the assembly to suit their requirements. An enterprise DXP will enable agencies to achieve a 360-degree view of how constituents are engaging with their digital services and gain valuable data to understand how to enhance their experience. Finally, a composable, open source DXP provides a proactive approach to protecting against security and compliance vulnerabilities.”

Read more insights from Tami Pearlstein, Senior Product Marketing Manager at Acquia.

 

Creating Secure Open Source Repositories

“Protecting the software supply chain requires looking at every single thing that might come into an agency’s environment. To understand that level of visibility, I like to use the analogy of a refrigerator. All the ingredients necessary to make a cake or pie are in the refrigerator. We know they are of good quality, and other teams can use them instead of having to find their own. At Sonatype, our software equivalent of a refrigerator is the Nexus Repository Manager. A second aspect of our offering, called Lifecycle, allows us to evaluate the open source components in repositories at every stage of the software development life cycle. One piece of software can download a thousand other components. How do we know if one of those components is malicious?”

Read more insights from Maury Cupitt, Regional Vice President of Sales Engineering at Sonatype.

 

Better Data Flows for a Better Customer Experience

“A more responsive and personalized customer experience isn’t much different from the initial problem set that gave birth to Apache Kafka. When people interact with agencies, they want those agencies to know who they are and how they’ve interacted in the past. They don’t want to be asked for their Social Security number three times on the same phone call. They also expect that the information or service they receive will be the same whether they are accessing it over the phone, via a mobile app and on a website. To elevate the quality of their service, agencies must be able to stream information in a low-friction way so different systems are consistent with one another and up-to-date at all times, regardless of the communication channel an individual uses. President Joe Biden’s executive order about transforming the federal customer experience is based on this capability. The most successful companies across industries have figured out how to do it, and for the most part, they’ve done it with open source software.”

Read more insights from Jason Schick, General Manager of Confluent US Public Sector.

 

An Open Source Approach to Data Analytics

“For the past 40 years, agencies have used data warehouses to collect and analyze their data. Although those warehouses worked well, they were limited in what they could do. For instance, they could only handle structured data, but by some estimates, 90% of agencies’ data is unstructured and in the form of text, images, audio, video and the like. Furthermore, proprietary data warehouses can show agencies what has happened in the past but can’t predict what might happen in the future. To achieve the government’s goal of evidence-based decision-making, agencies need to be able to tap into all their data and predict what might come next.”

Read more insights from Howard Levenson, Regional Vice President at Databricks.

 

Download the full Innovation in Government® report for more insights from these open source thought leaders and additional industry research from FCW.

Next-Generation DevSecOps for the Public Sector

The cyberthreat landscape is constantly shifting at a time when government agencies face a growing demand for digital services. Agencies can balance those competing priorities by embracing a methodology that speeds and strengthens every aspect of software development, including security. Known as DevSecOps, the methodology allows agencies to create, deploy and maintain apps that are targeted to users’ needs, easily updated and continuously monitored for security purposes. In a recent survey of FCW readers, 68% of respondents said the changing cybersecurity landscape is driving the adoption or evolution of DevSecOps at their agencies. With security concerns expanding at all levels of government, DevSecOps is a prerequisite for achieving digital transformation. Learn how your agency or municipality can adopt DevSecOps to balance to manage all aspects of developing and deploying secure, modern apps, they will build trust between the government and the people it serves, while also boosting employee engagement and productivity in Carahsoft’s Innovation in Government® report.

 

Accelerating Secure App Development for Low-Code SaaS Platforms

“Unlike traditional DevSecOps, a low-code DevSecOps platform offers a user-friendly experience through built-in security and governance controls that make it easy for nontechnical administrators to handle automated testing. Agencies can respond faster, achieve higher levels of software quality, deliver more digital services and scale to meet unprecedented demands — all while reducing the need for coding experience. Such platforms maximize the value of low-code/no-code software as a service and let agencies focus on and accelerate building experiences that drive citizen trust and engagement.”

Read more insights from Copado’s Senior Director of Product Line Management, Andrew Storms, and Radiant Infotech’s Director of the Salesforce Practice, Sarvinder Sandhu.

 

Automation: The Key to Secure App Development

IIG FCW DevSecOps July Blog Embedded Image 2022“Application software is front and center in the drive to provide high-quality services to citizens and organizational customers. That, in turn, is fueling the need for a different culture, method and tooling capability within agencies. Those realities are accelerating the adoption of DevOps, which helps organizations be agile in determining what to deliver, how to deliver it and then delivering it. The primary strategic benefit is a significant increase in change/transformation velocity. However, that velocity amplifies the opportunity for human errors that result in security vulnerabilities.”

Read more insights from CloudBees’ CISO, Prakash Sethuraman.

 

 Building Better Data Pipelines for DevSecOps

“Building data pipelines from scratch and managing all the integrations can take a significant amount of effort and time, perhaps as long as a year. By contrast, agencies can buy a product from a trusted partner and be up and running in days or weeks, with the added benefits of built-in observability tools and ongoing expert support. In digital transformation, there are no prizes for second place. All government agencies should have the ability to move forward quickly and securely to provide the apps and digital services their users need.”

Read more insights from Cribl’s Senior Director of Market Strategy, Nick Heudecker.

 

Achieving a More Secure Software Supply Chain

“There is a lack of transparency in how much open-source software is being used throughout the federal government. A disconnect between developers and security teams makes it difficult to rectify this. But in today’s world, understanding what’s in the supply chain is critical to national security. All government and contractor software developers need to think critically and not only ask themselves “does the code have vulnerabilities?” but “could it have vulnerabilities?” and “how do we know either way?” Developers can’t answer those questions if they don’t know what code they’re using, which is why software bills of materials are critical to managing any software supply chain. An SBOM is a comprehensive list of a given product’s software components, open-source licenses and dependencies. It offers valuable insight into the software supply chain and potential risks.”

Read more insights from Sonatype’s Vice President of Product Innovation, Stephen Magill.

 

 The Benefits of Automated, Risk-Based Testing

“Agencies must be able to quickly identify vulnerabilities and mitigate any risks in their applications. Adding static application security testing (SAST) and dynamic application security testing (DAST) to software development workflows can help. SAST, also called white box testing, involves scanning an application for security vulnerabilities before the code is compiled. Those vulnerabilities include SQL injection, cryptographic failures, security misconfigurations and others in the Open Web Application Security Project’s list of the top 10 security risks. DAST, also known as black box testing, is used to identify certain vulnerabilities while an application is running in a production environment.”

Read more insights from Tricentis’ Vice President of Public Sector, John Phillips.

 

Incorporating Security into Mobile Apps

“As a first step, agencies should require a software bill of materials (SBOM) for the mobile applications they build and the applications employees use on agency-issued mobile devices. Furthermore, a dynamic SBOM can show the geolocations of API and network connections, which can help agencies know when an application connects or shares data with foreign countries. Agencies should also embrace modern software development practices and incorporate continuous security testing into their mobile DevSecOps environments to identify issues and fix them in the fastest way possible. This complex process boils down to a few key strategies.”

Read more insights from NowSecure’s Vice President of Public Sector, Jeff Miller.

 

Download the full Innovation in Government® report for more insights from DevSecOps thought leaders and additional industry research from FCW.