Governance, Risk and Compliance, Zero trust, Security Strategy, Plan, Budget, Security Architecture
Zero-trust strategy will likely be different for each federal agency
As the federal government’s zero-trust journey continues, cybersecurity officials say they are working to review individual agency plans, harmonize implementation guidance and set up alternative standards to judge the progress of smaller agencies and offices.Chris DeRusha, the federal government’s chief information security officer, said now that agencies have submitted their plans for moving to a zero-trust architecture, they will need to go through an Office of Management and Budget review, a process that is likely to lead to further changes and refinement.“What we’re doing right now is going through those plans and making sure that they align to what we asked [agencies] to do in the memo, making sure that they’re sound plans working with the budget side to make sure that they have awareness, as well,” DeRusha said in an interview Wednesday after speaking at an event hosted by Institute for Critical Infrastructure Technology.Agencies have been naming a mixture of CIOs, CISOs and other officials as their leads for implementation, and part of OMB’s process is evaluating whether those designated officials are the best fit for the job. The agency is also incorporating technical input from staff at the Office of the National Cyber Director.Cybersecurity and Infrastructure Security Agency, the NSA, the National Institute for Standards and Technology and military agencies like the Defense Information Systems Agency publishing or in the process of developing zero-trust guidance and strategy documents for downstream agencies to follow.While some of these documents are meant to serve specific purposes (for example, CISA’s guidance is meant to help agencies reconcile their zero-trust tasks with the technical and cybersecurity maturity of their IT environment), they have also created a mash of documentation for agencies to ingest and some confusion.According to CISA Deputy Director Nitin Natarajan, that diversity of resources is by design and part of a broader effort to collaborate with other stakeholders and achieve buy-in for the work ahead.“The federal civilian enterprise is a wide-open space. A lot of people perceive it to be we just reach out to a bunch of CIOs, say ‘do X’ and it happens,” Natarajan said. ”But realistically, that’s not the reality that we’re in, so how do we make sure that we can talk about … where we need to go, what is the best way to get there and then how do we invest in that?”Like DeRusha, he reflected on the need for a process that is measured and can take into account the unique budgetary, staffing and technology needs at each agency.“You know, there’s not a magic checkbook in government, so how do we make sure that we’re resourcing these things effectively to get to success?” he said. “If we’re not resourcing correctly, we can’t get there from here. And the federal budget process is [slow], so how do we make sure we can get investments where we need them to be to really be on the forefront of that? It’s going to take some time, it’s going to take some prioritization and some commitment.”
Where possible, zero-trust items have been incorporated into respective agency budgets, but DeRusha said OMB and the White House designed the zero-trust mandates with a general three-year deadline in order to maintain enough flexibility to work through each agency’s unique IT environment.“A reminder of why we did it this way as opposed to setting concrete deadlines for all the tasks in the memo is we wanted to be mindful of this [reality]," DeRusha said. “We understand that every agency is in a different spot in their journey across these five pillars in the strategy, and we really want to make sure that we have this opportunity to develop strong points.”There’s also a challenge in synthesizing all the different guidance that agencies are receiving. OMB is leading the implementation of zero trust in the civilian federal government and has put out its own zero-trust outline that agencies must follow. Others have also weighed in, with the Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds