Cybersecurity Initiatives from TechNet Cyber 2023

The global prominence of technology, cyber power and cybersecurity is vital to U.S. political and economic success. At TechNet Cyber 2023, a conference held in Baltimore, Maryland, Government, industry and academic partners discussed solving global security needs. This year’s conference, which took place May 2-4, focused on numerous topics including Zero Trust, multicloud and defense strategies against bad actors.

Thunderdome: The New Zero Trust Framework

Thunderdome is the new Zero Trust framework to improve cyber security and posture, created by the Defense Information Systems Agency (DISA), a combat support agency that provides information technology and communications support. Lieutenant General Robert Skinner, the director of DISA, attests that Thunderdome meets 131 of 153 key standards that were laid out by the Department of Defense (DoD) as a part of its strategy for Zero Trust. With that and further growth, Thunderdome is well on its way to being a vital part of Zero Trust cybersecurity.

Carahsoft TechNet Tradeshow Blog Embedded Image 2023However, Thunderdome is not a one size fits all solution, as its scalability and modularity will require ongoing assessment. At the event, Lieutenant General Skinner highlighted three key components to understanding where Thunderdome fits into agencies. They are known as the “three Ps:” posture, position and partnerships. The first part, posture, evaluates where an agency stands with its technology and processes in relation to its cyber posture. The second element, position, is the utilization of these resources to achieve the best results. And lastly, partnerships form the cornerstone of maximizing business capabilities. In relationships with allies and partners, all participants can help each other and ensure that they are all on the same page.

Much of this manifests in Thunderdome’s process of improving agency posture with regards to the workforce. Through education, the right training, retention and hiring those with the right skillsets, agencies can improve their industry posture. Lieutenant General Skinner stressed that to support the current workforce, it is vital for agency leaders to “know and understand what their capabilities are to move them in the right place.”

The Pentagon’s MultiCloud Environment

The Pentagon’s multicloud environment is designed to give practitioners access to the best of technology. However, the complexity of the multicloud environment can lead to issues if not managed correctly. To combat this, Armon Dadgar, HashiCorp’s CTO and Co-founder, recommends forming a consistent way for practitioners to set up cybersecurity infrastructure on other platforms. As agencies seek to decomplexify systems, one way to achieve this in both the public and commercial sector is by establishing a consistent approach to the multicloud. Agencies should be intentional about instituting abstraction layers and begin by defining a central platform team to create a common blueprint across environments. This way, there is an organized standard for future processes.

Threats to Cybersecurity

Wanda Jones, a principal cyber advisor of the U.S. Air Force, discussed how to protect against hackers with evolving threats. Bad actors are aggressive, always moving and attacking industry’s weak spots. The best way to defend capabilities is to detect threats early on and respond in a timely manner. Agencies must always be monitoring and improving to stay on the offensive. A solid start to improving the Zero Trust is improving security architecture and providing access to those with known identities within the agency.

With the continued focus on cybersecurity, the Federal Government maintains the public’s safety and security.

 

To learn more about the topics discussed at TechNet Cyber, View the full Fed Gov Today episode co-sponsored by Carahsoft.

*The information contained in this blog has been written based off the thought-leadership discussions presented by speakers at TechNet Cyber 2023.*

Driving Advancements for the U.S. Sea Services at WEST 2023

In the 21st century, technological security remains one of the most important features of any government agency. Military officials, Government leaders and industry professionals gathered at AFCEA’s WEST 2023, an annual and international Sea Services conference, to discuss the future of security and naval technology in the federal government. This year’s conference featured the Departments of the Navy, the Marine Corps and the US Coast Guard (USCG). At WEST, agencies showcased and reviewed IT initiatives and programs in the context of meeting the needs of the Sea Services.

Opportunities for the USMC

US Marine Corps (USMC) is an amphibious force that engages enemy forces, protects U.S. naval bases, combines armed service with their fleet and responds to global crises.

At WEST, the USMC elaborated on various steps to opportunities to ensure readiness to respond to various threats and challenges. It has:

  • Extended the MQ-9 flying range
  • Gained new approvals for bases
  • Increased funding for various subsets
  • Focused on retaining recruits

During the upcoming year, it aims to:

  • Obtain a minimum of 31 amphibious warships
  • Provide training in realistic conditions
  • Explore expeditionary contracting and pre-positioning
  • Secure continued support from Congress
  • Improve cybersecurity
  • Acquire more personnel

IT professionals from both industry and other government agencies can collaborate with the USMC to help it effectively meet these goals.

Carahsoft WEST 2023 Recap Blog Embedded Image 2023How DISA IT Initiatives Support the USMC

The Defense Information Systems Agency (DISA) is a United States Department of Defense (DoD) combat support agency that provides information technology (IT) and communications support to public officials. When creating security solutions for the USMC, DISA incorporates a variety of helpful features including having all migration efforts interoperable with Zero Trust best practices. This is especially important to gaining continued federal support, as Zero Trust is a vital security model in the federal government.

Over the last year, the pilot for Thunderdome, DISA’s application of the zero trust security model, came to fruition. While its implementation has been difficult, DISA hopes to use Thunderdome to improve the lack of endpoint credential solutions in the DoD by employing conditional access policies and application security stack requirements. Additionally, DISA plans to implement SOAR—Security, Orchestration and Automated Responses—solutions and tools to streamline security operations. Other similar security efforts include automating security validation, implementing endpoint management and advancing micro-segmentation. DISA plans to add multipurpose team collaboration and management tools that can fulfill multiple tasks at once. By channeling increased funding into these initiatives, the USMC can solidify its technological security.

Industry Professionals Driving Innovation

The Navy, and by extension, the USMC, have three main goals in the upcoming year: modernize the department of infrastructure, drive innovation and become more competitive. The tech industry can help the USMC achieve these goals through various technological advancements.

For example, transforming cybersecurity to be rooted in military readiness can help improve the USMC’s defense, speed capability delivery and insights. Quicker capabilities are especially helpful to its goal of acquiring more warships and shifting back to a focus on maritime services. Additionally, USMC must work with agencies that maintain its own Software-as-a-Service (SaaS) tools to implement additional agile tools that can expedite processes, freeing funding for other projects. Other initiatives are to expand the department’s satellite network capabilities beyond sole usage of the cloud, to enable the USMC to access toolkits from multiple systems and to advance internal innovation. These capabilities can help create comprehensive growth in the Navy.

Through a variety of security implementations, government agencies and the IT sector can work together to make the USMC, Navy and Coast Guard as safe and effective as possible. With continued and future partnerships between the government and technology industry, the Sea Services hope to achieve long-term support that will drive fundamental and vital development.

To learn more about AFCEA’s West 2023, visit Carahsoft’s Partners and Events Resource Hub.

*The information contained in this blog has been written based off the thought-leadership discussions presented by speakers at WEST 2023.*