DOD Zeros in on Culture For Zero Trust Buy-In

Identity management and culture are two of the biggest challenges facing federal agencies as they deploy zero-trust architectures.
At GovCIO Media & Research’s CyberScape: ID event, Navy CTO Jane Rathbun called out identity management as key to a robust zero trust framework.
The COVID-19 pandemic presented the Navy with an opportunity to begin leveraging a zero-trust framework through implementation of Microsoft Office 365, she said. The old system had multiple security, management and latency problems, which prompted the Navy to pivot to a new one designed with zero trust in mind.
Protecting data hasn’t always been a major focus for the Navy, but it will be the new priority under an identity-driven, zero trust approach to security.
“We have always been about protecting the perimeters,” Rathbun said during the event. “Protecting the data — it hasn’t been the focus. That pivot to protecting data, tagging data and knowing who should have access to that data — those are going to be the big challenges.”
Angelica Phaneuf, CISO at the Army Software Factory, said identity management is the foundation for zero trust architecture, but it can be challenging in the DOD environment, which requires zero trust interoperability.
“Finding an identity solution to a centralized identity that is approved and authorized and is flexible enough for a true zero trust identity management is extremely difficult,” she said.
Identity, credential and access management (ICAM) solutions are the core of a zero trust structure.
“ICAM doesn’t work in isolation, you can come up with a strong ICAM solution, but without things like policy enforcement points, you haven’t gotten across the interim finish line for zero trust,” said Fortinet Federal CISO and Vice President Jim Richberg at the event.
Gerald Caron, CIO of the Department of Health and Human Services Office of the Inspector General, echoed Richberg’s comments emphasizing identity as the primary pillar of zero trust.
“Identity is about right information of the right people at the right time,” Caron said. “We have to be judicious about it, we rely on data every day to make decisions, and that’s what we are trying to protect at the end of the day.”
Rathbun believes the Navy’s federated approach to identity solutions has played a critical role in helping prepare the Navy for zero trust.
“When it comes to executing identity and managing identity and managing identity solutions for our customer base, we need to federate that down to the service level so they have the freedom of maneuverability for their mission sets,” Rathbun said.
The Army’s digital transformation strategy, led by CIO Raj Iyer, has been vital for helping the Army pivot to zero trust.
Paul Puckett, director of the Army’s Enterprise Cloud Management Agency (ECMA), said the group has been a pruning ground for what the Army’s zero-trust framework needs to look like.
“[We’re] looking at a software-defined perimeter that not only enforces critical components of zero trust, but also allows us to expand how we connect globally especially with a distributed workforce,” Puckett said during the event. “How do we start to get more insurances when it comes to the people and devices accessing the applications and services in a secure manner from unknown and untrusted networks and having the control when it comes to data and services being applied as an enterprise capability within those applications brokering real-time secured access to information?”
The agency’s zero trust pilot, Project Drawbridge, takes the old “castle-and-moat” approach to cybersecurity and updates it within the context of the cloud.
“Taking what is learned in Project Drawbridge and implementing that as the core components of the enterprise cloud environment that we call cARMY,” Puckett said. “Enabling this transitional architecture that moves from network perimeter security model that we have today and move toward a cloud app to security edge to service edge model when it comes to distributed users and systems accessing data in a secure manner globally.”
The importance of culture when implementing zero trust continues to be a high priority throughout DOD. Phaneuf feels culture is critical to ensuring zero trust is utilized and trusted by the DOD community in an interoperable way.
“When you can affect change in the culture, you can affect the change of how the entire community operates, ultimately allowing you to impact new solutions and new technology with immediate buy-in from your community,” Phanuef said.
Many agencies have discovered that culture and strategy with identity solutions can help move the needle on federal cybersecurity.
“We are pivoting from the concept cybersecurity to the concept of cyber readiness, where it’s a continuum where every day you earn your right to operate because your capability is cybersecure and you’ve done the things you need to do,” Rathbun said. “In the Navy, we have a CISO office, acquisition organization and CIO organization, and everyone has to work together to articulate that North Star of the operating culture we want to create and then take that and define the policies, process changes, role changes and articulate this to industry as our strategic partner.”
This is a carousel with manually rotating slides. Use Next and Previous buttons to navigate or jump to a slide with the slide dots
-
VA CIO Targets Modern IT and Smarter Workforce Alignment
Agency leaders told lawmakers they are focused on trimming legacy systems and restructuring its workforce to streamline operations.
3m read -
Pentagon's $200M AI Contracts Signal Broader Effort to Transform Talent
The Army is leveraging Silicon Valley, reservist programs and new hiring strategies to integrate critical digital skills in its ranks.
5m read -
AI Foundations Driving Government Efficiency
Federal agencies are modernizing systems, managing risk and building trust to scale responsible AI and drive government efficiency.
43m watch -
Inside DOD’s Push to Grow the Cyber Workforce Through Academia
Diba Hadi gives her first interview since becoming principal director of the DOD’s Cyber Academic Engagement Office.
15m listen -
Agencies Tackle Infrastructure Challenges to Drive AI Adoption
Federal agencies are rethinking data strategies and IT modernization to drive mission impact and operational efficiency as new presidential directives guide next steps.
5m read Partner Content -
Generative AI Demands Federal Workforce Readiness, Officials Say
NASA and DOI outline new generative AI use cases and stress that successful AI adoption depends on strong change management.
6m read -
The Next AI Wave Requires Stronger Cyber Defenses, Data Management
IT officials warn of new vulnerabilities posed by AI as agencies continue to leverage the tech to boost operational efficiency.
5m read -
Federal CIOs Push for ROI-Focused Modernization to Advance Mission Goals
CIOs focus on return on investment, data governance and application modernization to drive mission outcomes as agencies adopt new tech tools.
4m read -
Fed Efficiency Drive Includes Code-Sharing Law, Metahumans
By reusing existing code instead of rewriting it, agencies could dramatically cut costs under the soon-to-be-enacted SHARE IT Act.
5m read -
Agencies Push Data-Driven Acquisition Reforms to Boost Efficiency
New initiatives aim to increase visibility of agency spending, improve data quality and create avenues to deploy solutions across government.
5m read -
Data Transparency Essential to Government Reform, Rep. Sessions Says
Co-Chair of the Congressional DOGE Caucus Rep. Pete Sessions calls for data sharing and partnerships to reduce waste and improve efficiency.
5m read -
DOD Turns to Skills-Based Hiring to Build Next-Gen Cyber Workforce
Mark Gorak discusses DOD’s efforts to build a diverse cyber workforce, including skills-based hiring and partnerships with over 480 schools.
20m listen