GTRA

The number of reported cybersecurity incidents involving federal information networks continues to increase while the posture of federal agencies to defend against them appears to be weakening in 2012, according to projected data from a Congressional watchdog agency.

The Government Accountability Office’s director of information security issues, Greg Wilshusen, in a presentation to federal and industry security officials, said that the rate of reported security incidents, which had leveled off in 2011 after a steady four-year climb, was expected to jump again in 2012. Keep reading →


The Environmental Protection Agency (EPA) has contracted with Lockheed Martin and Microsoft to migrate the email and collaboration systems supporting approximately 25,000 employees to Microsoft’s cloud-based Office 365 system, according to a joint announcement released by Lockheed Martin and Microsoft today.

The collaboration and communication service is expected to improve EPA employees’ access to communications and mobility tools and result in expected savings of $12 million over the four-year contract period. Keep reading →

Several weeks back, at a GTRA Council Meeting, I heard my former CIO at EPA, Malclom Jackson, talk about “Developing a Secure Mobile-First Culture – the EPA’s Story.”

Among other points, he announced an “aggressive and accelerated procurement for new EPA collaboration tools”: one month to advertise, one month to decide, and four months to implement, so it is ready by November. Malcolm deserves credit on a number of fronts for pushing these ideas forward and quickly.

But it also reminded of a point about government that I experienced many times during my 30-plus years of government service at EPA: namely, senior managers in government repeat work that has been done in the past either because they do not know about it or choose to ignore it and start from scratch again.

I asked him if he was also working on the two functions that I had found important in my experience with doing this, provisioning content and dealing with limited bandwidth, and he said they were.

But I know from my experience at EPA that those two things are not going to happen in a short period of time. It took me three years to prepare EPA’s best content in a collaboration tool that supports limited bandwidth use on both desktop and mobile devices.

In my government experience, the 90-9-1 rule applies… only 1% will really use (new tools) and be doers and evangelists.”

I would have also felt better about what Jackson announced if he had mentioned it supported and followed the standards outlined by Federal CIO Steve VanRoekel in his Building a Digital Government Strategy.

One can do these things from the top down: That is, respond to the need for collaboration tools for an agency that work on mobile devices, procure them and hope that the employees put their content in them.

Or one can work from the bottom up: Use what employees are already using to put their content in to collaborate with others and see if those tools will scale up and federate.

We have all seen organizations procure yet another set of collaboration tools, only to then have a massive migration problem with legacy content and users still continue to use their tools of choice. For example, mobile has evolved from “This is the only tool we offer” (e.g. BlackBerry) to now Bring Your Own Device (BYOD) (e.g. iPhones, iPads, etc.)

So what should Malcolm and others in his situation do?

First, I would go around asking and looking for what has already been done and ask the real productive people at EPA, who are collaborating with others inside and outside the agency, what they are using (at EPA or outside of EPA) or would use if they had permission, and encourage others at EPA to try those pockets of excellence first.

Keep reading →

In one of his first public appearances since being officially named CIO at the Department of Energy, Robert Brese called for greater efforts to develop a skilled cybersecurity workforce, and stressed the importance of responding to cyber threats, not merely being prepared to prevent and recover from them.

In a series of wide-ranging remarks on the state of cybersecurity in the federal government, Brese highlighted six factors shaping the evolution of federal cybersecurity policy, but concluded that despite many challenges, the federal government is “doing a better job than a majority of the private sector” in defending its networks. Keep reading →

Environmental Protection Agency Chief information Officer Malcolm Jackson has embarked on a six-month, rapid-deployment plan to contract and implement a new email and collaboration platform to help improve work processes for EPA employees.

“We’re ripping the Band-aid off,” declared Jackson, acknowledging the initiative “is aggressive; it’s really aggressive.” Keep reading →


One of the many benefits of being the director of research at GTRA is that it offers the opportunity to speak candidly and off the record with countless executives from Defense, Intelligence and Civilian agencies who share what they really care about, not what mandates and initiatives tell them to focus on.

The result is a real-time snapshot of the most frequently made comments by federal IT executives, some of which may come as a surprise. Among the most frequently uttered comments I’ve received over the past few months, which may or may-not come as a surprise: Keep reading →

What you don’t know about your mobile technology can harm you–and your organization–warned a long-time federal intelligence executive now helping the U.S. Army’s leading logistics provider.

That was the impetus behind a new seven minute video developed for the 70,000 employees of the Army Materiel Command, but which offers a primer for virtually anyone using a mobile smart phone or laptop for work. Keep reading →