Cyber-attacks are front-page news and, increasingly, the target is the federal government. It is time to get an overview of the threat landscape and learn about federal efforts to remediate the distressing situation.
Today, we host a discussion of internationally known Dr. Ron Ross from NIST and his federal colleagues Brandon Bokan from CISA and Steve Wallace from DISA. Industry veterans Michael Coleman and Bill Church from F5 Networks bring commercial expertise into the cybersecurity discussion.
It is always good to evaluate current security issues to look beyond. Dr. Ron Ross begins with a surprising analysis. Many would think that the biggest risks are Advanced Persistent Threats or securing data in transit, but Ron Ross opens the discussion by saying the biggest risk is complexity.
Today’s intertwined world starts with the traditional on-premises system and then layers public, private, and even hybrid clouds. If you add thousands of new endpoints daily, we are at a point where a systems administrator’s primary job is to understand interdependencies.
Ron suggests that making systems simpler and more visible will assist in applying any of the solutions that will be examined later in the discussion.
Experts from F5 Networks observed that the state of today’s federal information systems can rely on outdated tools. Michael Coleman has seen older penetration tests being used, lulling current system administrators into a false sense of security. Further, each agency seems to have a varying portfolio of capabilities that may produce gaps in cyber coverage.
One proposed solution to the current situation is an improvement on the federal Trusted Internet Connection (TIC). The current iteration is called TIC 3.0. As the name implies, it is the third iteration of the federal government’s attempt to control undocumented connections. TIC 3.0 has an emphasis on promoting IT modernization. Essentially, it allows a direct user connection to the cloud in a secure manner.
Another major concept discussed is called Cloud Smart. This is a federal approach that does not assume everything should be migrated to the cloud. Its focus is on security, procurement, and workforce.
The final big topic under discussion was Zero Trust. Steve Wallace explains that Zero Trust is a set of design principles, not a checklist item. The concept is that trust is never implicitly granted. Branko Bokan adds that there is a need for all federal systems to understand organizational business data to deploy Zero Trust.
Dr. Ron Ross has seen it all – he sums up the discussion with the importance of looking at boundary protection. These have been breached so many times, Ron Ross assumes the bad guy is inside the perimeter. Federal systems administrations need to focus on disaster recovery and resiliency.
To view this webinar: Federal Security Trends: 2021 & Beyond.
Featured Speakers:

Ron Ross
Sr. Computer Scientist & Fellow,
NIST

Steve Wallace
Systems Innovation Scientist,
DISA

Michael Coleman
Solution Architect,
F5

Bill Church
Chief Technology Officer,
US Federal Solutions, F5

Branko Bokan
Cyber Services Liaison,
CISA

![FIDT-Logo-2020-Color[1]](https://www.fedinsider.com/wp-content/uploads/2020/03/FIDT-Logo-2020-Color1.png)
