<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Tales from the Technoverse &#187; GSA</title>
	<atom:link href="http://www.ourownlittlecorner.com/tag/gsa/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ourownlittlecorner.com</link>
	<description>Commentary on social networking, technology, movies, society, and random musings</description>
	<lastBuildDate>Thu, 26 Jan 2012 21:14:06 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Why FedRAMP Is Worth Caring About</title>
		<link>http://www.ourownlittlecorner.com/2011/12/12/why-fedramp-is-worth-caring-about/</link>
		<comments>http://www.ourownlittlecorner.com/2011/12/12/why-fedramp-is-worth-caring-about/#comments</comments>
		<pubDate>Tue, 13 Dec 2011 03:25:43 +0000</pubDate>
		<dc:creator>Daniel</dc:creator>
				<category><![CDATA[CIO]]></category>
		<category><![CDATA[cloud computing]]></category>
		<category><![CDATA[cyber-security]]></category>
		<category><![CDATA[government 2.0]]></category>
		<category><![CDATA[CFO]]></category>
		<category><![CDATA[cio]]></category>
		<category><![CDATA[DHS]]></category>
		<category><![CDATA[dod]]></category>
		<category><![CDATA[federal news radio]]></category>
		<category><![CDATA[FedRAMP]]></category>
		<category><![CDATA[francis rose]]></category>
		<category><![CDATA[GSA]]></category>
		<category><![CDATA[OMB]]></category>
		<category><![CDATA[powertek corporation]]></category>
		<category><![CDATA[Steven VanRoekel]]></category>
		<category><![CDATA[technology]]></category>
		<category><![CDATA[Veterans Administration]]></category>

		<guid isPermaLink="false">http://www.ourownlittlecorner.com/?p=375</guid>
		<description><![CDATA[Reposted from AOL Government, http://gov.aol.com/2011/12/12/why-fedramp-is-worth-caring-about/. If you have been at a recent Washington Capitals hockey game when the opponent scores a goal, you know the crowd routinely shouts out &#8220;Who cares!&#8221; Last week, Steven VanRoekel, Federal CIO, released the long awaited OMB plan for the Federal Risk and Authorization Management Program, or FedRAMP; which reminds me to be [...]]]></description>
			<content:encoded><![CDATA[<p><em>Reposted from AOL Government, <a href="http://gov.aol.com/2011/12/12/why-fedramp-is-worth-caring-about/">http://gov.aol.com/2011/12/12/why-fedramp-is-worth-caring-about/</a>.</em></p>
<p>If you have been at a recent Washington Capitals hockey game when the opponent scores a goal, you know the crowd routinely shouts out &#8220;Who cares!&#8221;</p>
<p>Last week, <a href="http://gov.aol.com/tag/Steven+VanRoekel,/">Steven VanRoekel,</a> Federal CIO, released the long awaited OMB plan for the Federal Risk and Authorization Management Program, or FedRAMP; which reminds me to be thankful for pronounceable acronyms. The purpose of FedRAMP per the implementing <a href="http://www.linkedin.com/pub/steven-vanroekel/12/96b/964">OMB memorandum</a>, is to &#8220;provide a cost-effective, risk-based approach for the adoption and use of cloud services&#8221;.</p>
<div>This blog entry is my attempt to answer the question &#8220;Who cares!&#8221;</div>
<p><span id="more-375"></span><br />
So were I a federal CIO, which I was, or an executive working for a provider to the Federal Government, which I am, what are the short- and long-term implications?</p>
<p>First, and most important, I think there <em>are</em> short- and long-term implications, which is not always the case with long awaited announcements and OMB produced memoranda.</p>
<p>However, I suggest the longer term implications tie more to the general topic of infrastructure rationalization than focusing specifically on the ever popular and impossible to avoid ongoing cloud frenzy.</p>
<p>It has long been my contention that while the IT focus in commercial organizations should be top-down to be most effective, in federal government it is the opposite: better off focused on a bottoms-up approach.</p>
<p>This difference reflects how funding, or revenue, is achieved.</p>
<p>In a commercial company revenue comes in from customers, is filtered through a sales organization and the decisions are controlled by executive leadership. IT leadership focuses on using the defined strategic goals to drive derived IT goals down into the rest of the organization.</p>
<p>In a government entity, funding comes through the appropriations process, and except in very rare circumstances, such as the Veterans Administration, is associated with the individual components that make up larger agencies or department, rather than with the overall mission of the department.</p>
<blockquote><p><img src="http://o.aolcdn.com/os/corp/images/Industry/em-quote" alt="" />The real value of initial cloud implementations is they represent the next big step in allowing federal CIOs to get a handle on what IT provisioning is going on within the organizations.&#8221;</p></blockquote>
<p>Because of this, the first hurdle for government CIOs is overall situation awareness; discovering what IT assets exist and figuring out how to put in place configuration management to keep track of those IT assets.</p>
<p>To just take one example, when OMB started pushing to consolidate data centers, it took months or longer to get an accurate inventory of how many data centers there were, let alone put together a plan to consolidate them.</p>
<p>Reducing costs is a reasonable goal to associate with cloud computing. Be warned that recent articles question whether cost savings will be large as some are articulating. See, for example, the discussion I participated in this last Friday on the <a href="http://www.federalnewsradio.com/86/2664084/Federal-News-Radio-Countdown-Cloud-computing-banning-email-and-USPS-budget-woes.">Federal News Radio Countdown</a>, hosted by <a href="http://gov.aol.com/tag/Francis+Rose/">Francis Rose</a>.</p>
<p>The real value of initial cloud implementations is that they represent the next big step in allowing federal CIOs to get a handle on what IT provisioning is going on within the organizations. Every application that is moved to the cloud is one that now is visible to and can be managed and measured by the CIO. Consistent security approaches can be taken. And it is the inconsistencies, not whether an application is internally hosted or externally hosted, that lead to security weaknesses.</p>
<p>There are a few additional specifics from the OMB memorandum that I wanted to note.</p>
<p>First, the process still has some time before it will be put into place. The goal is to have the FedRAMP PMO, to be run by GSA, operational no later than 180 days from issuance. This follows interim steps including establishing formally the list of security controls, creating a Concept of Operations, and creating a charter for the Joint Authorization Board (run by DoD, DHS, and GSA) dealing with governance.</p>
<p>Second, it will interesting to see how robustly the effort will be funded over the next few years. Congress has not been consistently supportive of shared service implementations. From my stint at DOT, I remember the difficulties that OMB had keeping the various eGovernment initiatives sufficiently funded.</p>
<p>While outside the scope of this write-up, I contend that one reason that DoD continues to make progress in this area is because of the existence of a home, what I refer to as a &#8220;center of gravity&#8221;, for managing the resulting shared infrastructure, namely DISA. While I have nothing but the greatest admiration for Richard Spires and Casey Coleman, running shared services is not currently the primary mission of either DHS or GSA respectively.</p>
<p>Third, I found it interesting that both the CIO and the chief financial officer need to certify together the list of all cloud services that cannot meet FedRAMP security authorization requirements within their agency. The dividing line between what is expected from CIO&#8217;s and CFOs regarding program management is not always clear cut, and is made even less clear when the CIO has been folded underneath the CFO.</p>
<p>In April, 2009, I asked the question &#8220;Why are 42 or so different procurements now looking at clouds?&#8221; I was <a href="http://gcn.com/articles/2009/04/20/internaut-mccarthy-on-civilian-disa.aspx">quoted as saying</a> that I thought that instead cloud computing could be offered in a way &#8230; in which any federal agency can access a handful of major &#8230; contracts.&#8221;</p>
<p>And now a little over 2 ½ years later, we are only six months away from saying &#8220;You can.&#8221;</p>
<p><a href="http://gov.aol.com/tag/Daniel+Mintz/">Daniel Mintz</a><em> is chief operating officer of </em><a href="http://gov.aol.com/tag/Powertek+Corp./">Powertek Corp.</a><em> He served as CIO of the Department of Transportation from </em><em>2006-2009.</em></p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.ourownlittlecorner.com%2F2011%2F12%2F12%2Fwhy-fedramp-is-worth-caring-about%2F&amp;title=Why%20FedRAMP%20Is%20Worth%20Caring%20About" id="wpa2a_2"><img src="http://www.ourownlittlecorner.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.ourownlittlecorner.com/2011/12/12/why-fedramp-is-worth-caring-about/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DISA and Open-Source</title>
		<link>http://www.ourownlittlecorner.com/2010/01/26/disa-and-open-source/</link>
		<comments>http://www.ourownlittlecorner.com/2010/01/26/disa-and-open-source/#comments</comments>
		<pubDate>Tue, 26 Jan 2010 12:11:56 +0000</pubDate>
		<dc:creator>Daniel</dc:creator>
				<category><![CDATA[government 2.0]]></category>
		<category><![CDATA[2.0]]></category>
		<category><![CDATA[Casey Kasem]]></category>
		<category><![CDATA[Countdown]]></category>
		<category><![CDATA[DISA]]></category>
		<category><![CDATA[francis rose]]></category>
		<category><![CDATA[GSA]]></category>
		<category><![CDATA[open-source]]></category>
		<category><![CDATA[wfed]]></category>

		<guid isPermaLink="false">http://www.ourownlittlecorner.com/?p=150</guid>
		<description><![CDATA[In an earlier post, I talked about the radio show Countdown hosted by Francis Rose on WFED at 2pm Friday’s. The deal was that Francis would have three people select their top Government-related stories of the week and present them in sort of a Casey Kasem 3-2-1 countdown. I was on January 15th, you can [...]]]></description>
			<content:encoded><![CDATA[<p>In an earlier post, I talked about the radio show Countdown hosted by Francis Rose on WFED at 2pm Friday’s. The deal was that Francis would have three people select their top Government-related stories of the week and present them in sort of a Casey Kasem 3-2-1 countdown.</p>
<p>I was on January 15<sup>th</sup>, you can listen to the entire show that week at <a href="http://www.wfed.com/index.php?nid=17&amp;sid=1865007">http://www.wfed.com/index.php?nid=17&amp;sid=1865007</a>.</p>
<p>In this post, I wanted to briefly touch on the second of the two articles I discussed, <em>DISA expands access to ProjectForge cloud environment</em>, <a href="http://gcn.com/articles/2010/01/13/disa-projectforge-collaboration.aspx">http://gcn.com/articles/2010/01/13/disa-projectforge-collaboration.aspx</a>.</p>
<p>The article illustrates the greater comfort level that Government has with using open-source software produced by non-Governmental organizations. While not explicitly mentioned, this increased involvement is leading to open-source development going the other direction; being produced by Government and then placed into the greater community.<span id="more-150"></span></p>
<p>Just to make sure that everyone is on the same page, I should explain a few terms.</p>
<p>DISA, which stands for Defense Information Systems Agency, provides an increasingly large part of the Information Technology infrastructure for the Department of Defense; <a href="http://www.disa.mil/">http://www.disa.mil/</a>.</p>
<p>As I have mentioned in a number of venues before, I believe there needs to be a Civilian version of DISA to serve a similar purpose. The most logical candidate to me for this is GSA, though historically GSA has done a better job of managing contracts than managing the implementation of contracts. Regardless, as the Government increasingly understands the value of centralizing the provisioning of infrastructure, allowing the Program staff to focus on their program mission, DISA has increased its responsibilities; not without growing pains but that is a different blog entry.</p>
<p>The article talks about DISA expanding its ProjectForge effort associated with Cloud Computing, this effort is part of its forge.mil program. The word ‘forge’ comes from the original efforts to develop Open-source software.</p>
<p>Open-source software typically is created by crowd sourcing, which is with the participation of many contributors often in a fairly loosely coupled fashion. The process and the resulting source code is presented transparently. Companies typically make money around open-source efforts by selling training, consulting, and/or support contracts of one sort or another.  For more details, see <a href="http://opensource.org/">http://opensource.org/</a>.</p>
<p>There has been a continuing argument within Government over the proper place for open-source software. Some people are uncomfortable with the thought that the software has no single creator or owner.  Open-source advocates would argue that the gains achieved by making the source code completely visible are significant. Security experts tell me that security that is premised largely on secrecy ultimately fails. In the same way, the power of exposure, at least in theory, reduces the possibility of bugs and/or trapdoors which cause security vulnerabilities in a software application.</p>
<p>Fundamentally this discussion represents the much broader issue of the real-world value or power of crowd sourcing versus classical hierarchically produced results. I plan to talk more about this in later blog entries a bit more.</p>
<p>Returning to the article I presented, it is clear that the argument over Government use of open-source is being largely decided in favor of use. Here we have one of the largest providers of IT in the Federal Government with an active open-source effort both in concept and execution within the Federal Government.</p>
<p>The article also illustrates one of the under-reported stories; that of Government produced open-source software. It is increasingly common that the Government makes use of privately produced open-source software. But there are an increasing number of situations where the Government is creating open-source software and either making it available to a larger community for usage or even setting up relationships with non-Governmental organizations to manage the resulting open-source community.</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.ourownlittlecorner.com%2F2010%2F01%2F26%2Fdisa-and-open-source%2F&amp;title=DISA%20and%20Open-Source" id="wpa2a_4"><img src="http://www.ourownlittlecorner.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.ourownlittlecorner.com/2010/01/26/disa-and-open-source/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

