By now, most federal information technology professionals have heard of the concept of Zero Trust. They may have it on a long-term plan, but recent security events have put the deployment of Zero Trust to the top of the list for agency goals.
This is an interview with three federal technology leaders who have deployed Zero Trust, they are joined by a representative of a company, Tenable, who has extensive experience in partnering with agencies to apply Zero Trust principles in a wide range of federal environments.
The discussion is divided into four areas: technology definitions, federal guidelines, best practices for deploying Zero Trust, and challenges in a federal environment.
One key concept for Zero Trust is identification. Glenn Pendley from Tenable frames the topic by starting with the origin of how the popular system from Microsoft, Active Directory (AD), developed over the years. Glenn calls AD “a big hairy beast.” However, it is the de facto way users are managed in an enterprise environment.
Glenn states a federal agency needs identity and authentication systems that are in a posture to do Zero Trust. Additionally, he recommends that an agency defines goals and breaks them into manageable tasks.
Blair Hauserman from NIST is in a curious position. His agency is tasked with developing standards for federal agencies to use Zero Trust; at the same time, he is implementing Zero Trust at NIST. He provides NIST document feedback for the standards developers – real implementation of a Zero Trust in a federal environment.
Gregory Edwards from FEMA puts Zero Trust in perspective in that he says it can’t be isolated but must be part of a more general digital transformation. The other aspects that must be taken into consideration are the device, the network, as well as the application and data layer.
FEMA’s challenge is to prepare before, during, and after a disaster. Moving beyond people at FEMA, one component many don’t think about is opening FEMA for survivors to get information on the situation.
Dovarius Peoples highlights the fact that the Army Corps of Engineers has an extremely heterogeneous environment. He must worry about Zero Trust in everything from dams to data centers.
To view this webinar: Moving Federal Agencies Toward Zero Trust.
Featured Speakers:

Dovarius Peoples
Chief Information Officer,
Army Corps of Engineers

Blair Heiserman
Chief Information Security Officer,
NIST

Gregory Edwards
Acting Chief Information Security Officer, Federal Emergency Management Agency

Glen Pendley
Deputy Chief Technology Officer,
Tenable

