Vertical
v1.5

Government & Defense

Government and defense cybersecurity operates under constraints that commercial sectors never face: classification levels, congressional oversight, acquisition timelines measured in years, and adversaries that include nation-state intelligence services with effectively unlimited budgets. A CISO in this space must master a dense web of overlapping mandates — FedRAMP, CMMC, CJIS, FISMA — while delivering security outcomes in environments where a single misconfiguration can compromise national security.

8 Lessons ~90 min read ● Free
How this content was produced

Content v1.5 · last revised 2026-08-31

This lesson is AI-generated and reviewed by a practitioner before publication. That review checks for accuracy and usefulness — it is not a formal audit, and no external body has certified this material.

Revised means the page changed on that date — not that every fact on it was re-verified then. Where an individual claim has been checked against a primary source, a "Verified" note appears next to it.

What that means for you: treat framework and regulatory detail here (GDPR, NIS2, the EU AI Act, NERC CIP, CMMC, HIPAA, PCI DSS and the rest) as a well-informed starting point, not as authority. Regulations change and AI-assisted text can state stale or subtly wrong specifics with complete confidence. Before you act on a control mapping, an obligation, or a deadline — especially in a filing, an audit response, or a board paper — verify it against the primary source. Where a lesson cites a date or a vendor, look for the "Verified" note next to it.

About the examples in this module

Real-World Example means a documented, publicly reported incident you can look up and verify independently. Illustrative Scenario means a composite drawn from patterns that recur across engagements — the dynamics and the lesson are real, but the organisation is not a specific named company and the figures are representative rather than audited. We label them differently so you always know which is which, and never cite a composite to your board as though it were a documented case.

01

FedRAMP & Cloud Authorization

The Federal Risk and Authorization Management Program (FedRAMP) is the mandatory gatekeeping framework for any cloud service provider (CSP) that wants to sell to the US federal government. It is not optional, it is not aspirational, and it is not fast. FedRAMP authorization typically takes 12-18 months for a Moderate baseline and costs between $500K and $2M+ depending on system complexity. Understanding FedRAMP is essential for any CISO whose organization either provides cloud services to the government or consumes them.

This programme has been rebuilt — check what era your guidance is from

FedRAMP has changed more between 2024 and 2026 than in its previous decade, and most FedRAMP material online — including consultancy guidance still being sold — describes structures that no longer exist. Three changes matter before you read anything else:

1. The JAB is gone. The Joint Authorization Board was dissolved in May 2024 and replaced by the seven-member FedRAMP Board (GSA, DoD, DHS by statute, plus VA, Department of the Air Force, CISA, and FDIC). The JAB P-ATO path and the FedRAMP Connect prioritisation process went with it. If a vendor or advisor is still selling you a "JAB strategy," that is a reliable signal their knowledge is at least two years stale.

2. The programme was legally re-founded. OMB Memorandum M-24-15 (July 2024) rescinded and replaced the 2011 memorandum that created FedRAMP in its entirety — same name, different authority and responsibilities. Because FedRAMP is now codified in statute (FedRAMP Authorization Act, 2022), OMB can no longer dissolve it by withdrawing a memo.

3. The vocabulary changed in 2026. As of 4 May 2026, FedRAMP issues certifications, not authorizations, and uses Classes A–D instead of FIPS 199 impact levels. Using the old terms in a proposal marks you as out of date.

Authorization Paths After M-24-15

M-24-15 replaced the old two-path model with three: agency authorizations (a sponsoring agency's authorizing official grants the ATO — still the dominant route in practice), program authorizations (granted through FedRAMP itself, the structural successor to the JAB path and aimed at CSPs that cannot secure an agency sponsor), and any additional path the FedRAMP PMO designs in consultation with OMB and NIST. That third category is not filler — it is the legal basis on which the 20x pilots below were run.

Why the programme was rebuilt: the numbers that forced it

FedRAMP's own retrospective describes a programme in crisis entering FY25: authorization times exceeding one year and sometimes approaching two, the JAB shut down unexpectedly for nearly a year during the transition, and just over 350 cloud services authorized in 13 years. For a CISO on the consuming side, that scarcity is the real story — it explains why your agency's approved-services catalogue is so much smaller than the commercial market, and why shadow IT pressure in government is structural rather than cultural.

FedRAMP 20x and the Class A–D Transition

FedRAMP 20x is the programme's rebuild of the assessment model itself: instead of narrating compliance against ~325 controls in documents, CSPs demonstrate Key Security Indicators (KSIs) through machine-readable submissions validated by a 3PAO. The pilots have run and the public rollout is underway.

MilestoneStatus
Phase One pilot (Low baseline)Ran Apr–Sep 2025. 12 authorizations from 26 submissions — a useful reality check on the "20x is fast" narrative.
Phase Two pilot (Moderate)Ran Nov 2025 – Mar 2026, limited cohort of ~14 CSPs.
Terminology change4 May 2026 — "authorization" → "certification"; impact levels → Classes A–D.
Consolidated Rules for 2026 + JSON schemasReleased 24 June 2026; optional early adoption from 4 July 2026.
FedRAMP ReadyBecame a legacy designation on 28 July 2026.
Class A pipelineOpened 3 August 2026 — a new entry-level route onto the Marketplace.
Phase 3 — public Low/Moderate certification under 20xExpected Q3–Q4 2026.
Phase 4 — High pilot (hyperscale IaaS/PaaS)Expected Q1–Q2 2027.
Rev 5 application cutoff11 June 2027 — FedRAMP stops accepting new Rev 5 certification applications, and existing Rev 5 providers must transition to machine-readable certification data. This is the date to put in your plan.
Class A–D: what maps to what

Class A — new entry-level path onto the Marketplace, no direct predecessor. Class B ≈ old Low. Class C ≈ old Moderate. Class D ≈ old High.

The relabelling was done because FIPS 199 impact levels were being confused with Department of War Impact Levels (IL2/IL4/IL5/IL6) — two different scales that share vocabulary and appear in the same procurement conversations. If you work across civilian and defence customers, this ambiguity has probably already cost you a meeting.

Impact Levels and Control Baselines

The historical baselines remain the best way to understand the scale of effort, and still govern every system certified before the transition. Low impact covers publicly available data (approximately 125 controls). Moderate covers data where loss of confidentiality, integrity, or availability could have serious adverse effects — historically the most common baseline, covering roughly 80% of federal systems at approximately 325 controls. High covers data where loss could be severe or catastrophic, including law enforcement, emergency services, financial systems, and health data — approximately 421 controls. Rev5 aligned FedRAMP baselines with NIST SP 800-53 Rev5, adding supply chain risk management (SR family), privacy (PT family), and PII processing controls.

What changes under 20x: the control counts stop being the unit of work. KSI-based assessment asks you to demonstrate security properties through machine-readable evidence rather than narrate control implementation in a System Security Plan. For CISOs, that shifts the cost centre from compliance writing toward security engineering and automated evidence generation — budget accordingly, because the skill sets are not interchangeable.

3PAO Assessment Reality

A Third Party Assessment Organization (3PAO) accredited by A2LA conducts the independent security assessment. The 3PAO produces the Security Assessment Report (SAR) that the agency AO or FedRAMP itself uses for the certification decision — and under 20x, the 3PAO's role shifts toward validating machine-readable KSI evidence rather than reviewing narrative documentation. Expect the 3PAO assessment alone to take 4-8 weeks for Moderate and cost $150K-$400K. The 3PAO will test every control — not a sample. Common failure points: incomplete System Security Plan (SSP) documentation, missing POA&M items, inadequate continuous monitoring tooling, and boundary definition disputes. Fix your SSP documentation before engaging a 3PAO — rework cycles are expensive.

Continuous Monitoring (ConMon)

Authorization is not the finish line — it is the starting gate. FedRAMP requires ongoing continuous monitoring that includes monthly vulnerability scanning with results submitted to the FedRAMP PMO, annual penetration testing, significant change requests (SCRs) for any architectural modifications, monthly POA&M updates, and annual security assessment of a subset of controls. The ConMon dashboard requirements are specific: you must provide near-real-time visibility into vulnerability status, inventory changes, and incident metrics. Tools like Devo, Splunk GovCloud, or the CISA-provided dashboards are common choices. Failure to maintain ConMon can result in revocation of your ATO — and GSA publishes revocations publicly.

Real-World: StateRAMP and Reciprocity

StateRAMP applies FedRAMP-like rigor to state and local government cloud procurements. While not federally mandated, over 30 states now reference StateRAMP in procurement language. The reciprocity challenge is real: a FedRAMP Moderate/Class C certification does not automatically satisfy StateRAMP, CJIS, or IRS Publication 1075 requirements. Each has unique controls. CISOs managing multi-tenant government platforms must maintain a control matrix mapping FedRAMP controls to StateRAMP, CJIS, and agency-specific overlays — typically 15-30% additional controls beyond the FedRAMP baseline.

Verified 30 August 2026

FedRAMP is mid-transition and dates in this lesson are moving targets — Phase 3 and 4 timelines in particular are projections, not commitments. Verify against fedramp.gov before building a plan on any date here. Treat pre-2026 FedRAMP guidance from any source as suspect: it will describe the JAB, FedRAMP Ready, and impact levels as though they still operate.

02

CMMC 2.0 & Defense Industrial Base

The Cybersecurity Maturity Model Certification (CMMC) 2.0 is the DoD's mechanism for verifying that defense contractors actually implement the cybersecurity requirements they have been self-attesting to for years under DFARS 252.204-7012. The catalyst was straightforward: self-attestation was not working. Audit after audit revealed that contractors claiming compliance with NIST SP 800-171 had implemented a fraction of the required controls. CMMC 2.0 replaces trust with verification.

The Three Maturity Levels

Level Name Requirements Assessment Who Needs It
Level 1Foundational17 practices from FAR 52.204-21 (basic safeguarding of FCI)Annual self-assessmentAll contractors handling Federal Contract Information (FCI)
Level 2Advanced110 practices aligned to NIST SP 800-171 Rev2Triennial third-party assessment by C3PAO (for prioritized acquisitions) or self-assessmentContractors handling Controlled Unclassified Information (CUI)
Level 3Expert110+ practices from NIST SP 800-172 (enhanced security)Government-led assessment by DIBCACContractors handling CUI on highest-priority programs

CUI vs FCI: The Classification That Drives Everything

Federal Contract Information (FCI) is information provided by or generated for the government under contract that is not intended for public release. Controlled Unclassified Information (CUI) is a broader category established by Executive Order 13556 that includes information requiring safeguarding — technical data, export-controlled information, critical infrastructure data, and more. The distinction matters because it determines your CMMC level. A contractor who only handles FCI needs Level 1. A contractor handling CUI needs Level 2 or 3. The challenge is that many contractors do not accurately know what CUI they hold because the DoD's CUI marking program has been inconsistently implemented. If you are unsure, assume CUI and plan for Level 2.

C3PAO vs DIBCAC Assessment

CMMC Third Party Assessment Organizations (C3PAOs) are accredited by the Cyber AB (formerly the CMMC Accreditation Body) to conduct Level 2 assessments. The Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) conducts Level 3 assessments directly. C3PAO assessments cost $50K-$200K depending on scope and typically take 2-4 weeks on-site. Expect a 6-12 month preparation period before you are assessment-ready. The assessor will verify every one of the 110 practices — documentation, implementation evidence, and interviews with staff who operate the controls daily.

POA&M and Enclave Strategies

CMMC 2.0 allows limited use of Plans of Action and Milestones (POA&Ms) for Level 2 assessments — you can have open POA&Ms for controls that are not fully implemented, but they must be closed within 180 days, and certain critical controls (like MFA, FIPS-validated encryption, and security awareness training) cannot be on a POA&M at all. The practical implication: if you fail a "non-POA&M-able" control during assessment, you fail the entire assessment.

For small and mid-size defense contractors, the most pragmatic approach is an enclave strategy: rather than securing your entire enterprise to CMMC Level 2, create a hardened enclave — a separate network segment, set of workstations, and storage — dedicated exclusively to CUI processing. This dramatically reduces your assessment scope. A 500-person company might have only 15 people who actually touch CUI; securing 15 workstations in a dedicated enclave is vastly more achievable than remediating an entire enterprise network. Cloud-based enclaves using Microsoft GCC High or AWS GovCloud are increasingly common and shift much of the infrastructure compliance burden to the CSP.

Illustrative Scenario: Impact on Small Contractors

A 50-person machine shop making precision parts for fighter jet landing gear generates $8M in annual revenue and holds CUI in the form of technical drawings. Achieving CMMC Level 2 compliance costs an estimated $150K-$300K in initial remediation plus $50K-$100K annually to maintain. For a small manufacturer operating on 8-12% margins, this is existential. Many small DIB contractors are choosing between investing in compliance, exiting the defense market, or being acquired by larger primes. The DoD has acknowledged this burden but has not provided funding relief. Subcontractor flow-down requirements mean primes are increasingly requiring CMMC readiness in subcontract terms, even before the rule is fully phased in.

03

Classified Environment Security

Classified information security operates in a fundamentally different paradigm from commercial cybersecurity. The controls are not risk-based trade-offs — they are absolute requirements backed by federal law (18 U.S.C. 793-798), executive orders, and intelligence community directives. Mishandling classified information is not a compliance finding; it is a federal crime. A CISO or Facility Security Officer (FSO) operating in classified environments must understand the legal framework, physical requirements, and operational constraints that define this space.

Classification Levels and Access

Level Damage from Disclosure Clearance Required Investigation Type Typical Timeline
ConfidentialDamage to national securityConfidential clearanceTier 3 (T3) / NACLC2-4 months
SecretSerious damage to national securitySecret clearanceTier 3 (T3) / NACLC3-6 months
Top SecretExceptionally grave damageTS clearanceTier 5 (T5) / SSBI6-18 months
TS/SCIExceptionally grave damage + intelligence sourcesTS + SCI access approvalT5 + CI polygraph (often)12-24 months

Access to classified information requires two conditions: an appropriate clearance level and a demonstrated need-to-know for the specific information. Having a TS clearance does not grant access to all TS information — it grants eligibility. The program manager or information owner must separately approve access to specific compartments or programs. This dual-gate model is foundational and frequently misunderstood by people coming from commercial IT backgrounds.

SCIF Requirements (ICD 705)

A Sensitive Compartmented Information Facility (SCIF) is a physically secured room or area accredited for processing, storing, and discussing SCI. Intelligence Community Directive (ICD) 705 defines the construction and accreditation standards. Requirements include: sound attenuation sufficient to prevent intelligible eavesdropping (STC rating of 45+ for walls, floors, ceilings), RF shielding or TEMPEST countermeasures to prevent electromagnetic emanations, intrusion detection systems (IDS) on all entry points, no windows or windows with opaque covering and RF shielding, access control via cipher locks or badge readers with two-person entry logs, and continuous visual inspection capability (CCTV). SCIF construction costs range from $150-$500 per square foot above standard construction costs. Accreditation involves inspection by the cognizant security authority (typically the agency's Special Security Officer).

Air-Gapped Networks in Practice

SIPRNet (Secret Internet Protocol Router Network) carries information up to Secret. JWICS (Joint Worldwide Intelligence Communications System) carries information up to TS/SCI. Neither network has any connection to the public internet — by design and by law. Cross-domain solutions (CDS) are hardware/software systems accredited to transfer specific data types between classification levels. Every CDS deployment requires approval from the Unified Cross Domain Services Management Office (UCDSMO) and is individually accredited. There is no general-purpose bridge between classification levels.

Spillage and Insider Threat Controls

A spillage (or "spill") occurs when classified information is placed onto a system not accredited to handle that classification level — for example, a Secret document emailed over an unclassified network. Spillage response is immediate and prescribed: isolate the affected system, notify the security officer, preserve all evidence, and do not attempt to delete the classified material (deletion on an unclassified system does not meet sanitization standards). The affected system typically must be sanitized to NSA/CSS EPL standards or destroyed, depending on the classification level and media type. SSDs are particularly problematic because standard overwrite methods do not reliably sanitize flash storage — physical destruction is often required.

The National Industrial Security Program Operating Manual (NISPOM, 32 CFR Part 117) governs how cleared contractor facilities protect classified information. It mandates insider threat programs, security education, visitor control procedures, and the role of the Facility Security Officer (FSO). The FSO is the CISO-equivalent for classified environments — responsible for personnel security, physical security, information security, and security education. Two-person integrity (TPI) rules apply to certain activities: opening a SCIF, accessing certain cryptographic materials, and handling specific weapons-related information all require two cleared individuals present. No exceptions.

The Cost of Spillage

Spillage is routine across the defense industrial base rather than exceptional, and remediation is what makes it painful: sanitising or physically destroying affected media, investigation labour, and reaccreditation of the affected system. A single incident can consume a small contractor’s entire annual security budget. We deliberately do not quote an incident count or per-incident dollar figure — the numbers in circulation are not traceable to a primary DoD source, and an unverifiable figure in a board paper is worse than an honest qualitative statement. The most common cause is not malicious intent — it is a cleared employee accidentally attaching a classified document to an unclassified email. Technical controls (DLP, classification banners, mandatory metadata tagging) reduce but do not eliminate this risk. The human element remains the primary vulnerability.

04

Insider Threat Programs

The National Insider Threat Task Force (NITTF), established by Executive Order 13587 following the WikiLeaks disclosures, mandates that all federal agencies and cleared contractor facilities operate formal insider threat programs. This is not a recommendation — it is a legal requirement codified in the NISPOM (32 CFR Part 117) and enforced by the Defense Counterintelligence and Security Agency (DCSA). An insider threat program that exists only on paper will fail its next DCSA assessment, and that failure can result in loss of your facility clearance — which means loss of every classified contract.

The Whole-Person Concept

Effective insider threat detection is built on the whole-person concept: no single indicator in isolation constitutes a threat. The program must aggregate and correlate information across multiple domains — cybersecurity indicators (unusual data access patterns, after-hours downloads, use of unauthorized storage devices), human resources data (performance issues, disciplinary actions, financial stress indicators), counterintelligence information (unreported foreign contacts, foreign travel anomalies), and security data (badge access patterns, SCIF access logs, security incident history). The correlation of these disparate data sources is what transforms noise into actionable intelligence.

Insider Threat Program Maturity Model

Level 1 — Reactive: Program exists on paper; referrals happen only after incidents. Level 2 — Defined: Hub established; automated UAM deployed; referral criteria documented. Level 3 — Proactive: Cross-domain data correlation active; regular threat briefings to leadership; tabletop exercises conducted quarterly. Level 4 — Optimized: Predictive analytics informing early intervention; continuous evaluation integrated; program metrics driving resource allocation. Most organizations operate at Level 1-2. DCSA expects Level 2 as a minimum for cleared facilities.

User Activity Monitoring (UAM)

UAM is the technical backbone of insider threat detection. On classified networks, UAM is mandatory per Committee on National Security Systems (CNSS) Directive 504. At minimum, UAM must capture: keystrokes on classified systems, full-screen capture at regular intervals, all file operations (copy, move, delete, rename, print), all removable media insertions, all network file transfers, and application usage. Commercial UAM tools include Dtex (now part of Proofpoint), Securonix, ObserveIT (now Proofpoint ITM), and Everfox (formerly Forcepoint). The data volume is enormous — a 500-user classified network generating full UAM telemetry produces 2-5 TB per month. Storage, retention (typically 12 months minimum), and review workflows must be planned before deployment.

Legal and Privacy Constraints

UAM on government systems is legally grounded in the "authorized use" banner that all users must acknowledge at login — it explicitly states that activity is subject to monitoring. However, insider threat programs must still navigate legal constraints: attorney-client privileged communications may not be monitored (DoD policy), union-protected activities have specific exclusions, whistleblower protections under PPD-19 prohibit retaliation against employees reporting through authorized channels, and medical/mental health information obtained through monitoring has strict handling requirements under the Privacy Act. Your insider threat program must have legal counsel review before deployment, and the program's operating procedures must be reviewed annually.

Real Cases: The Human Element

Chelsea Manning (2010): Downloaded 750,000 classified documents from SIPRNet to a Lady Gaga-labeled CD. Behavioral indicators included documented emotional distress, workplace conflicts, and access to information far beyond job requirements. Edward Snowden (2013): Used system administrator privileges to access and exfiltrate NSA programs. Exploited colleagues' credentials. Demonstrated that privileged access without adequate monitoring is a critical gap. Reality Winner (2017): Printed a single classified NSA document and mailed it to a media outlet. Caught within days through printer dot forensics and audit log analysis. Demonstrates that even small exfiltrations leave forensic traces when monitoring is properly implemented.

Continuous Evaluation vs Periodic Reinvestigation

The legacy model of periodic reinvestigation (every 5 years for TS, every 10 for Secret) is being replaced by Continuous Evaluation (CE) and its successor, Trusted Workforce 2.0. CE performs automated checks against government databases (criminal records, financial records, foreign travel, public records) on an ongoing basis rather than waiting for the reinvestigation cycle. Trusted Workforce 2.0 consolidates the vetting process across the federal government, replacing the five-tier investigation system with three tiers and implementing ongoing vetting as the standard. The practical impact: derogatory information that previously would not surface until the next reinvestigation now triggers an alert within days. CISOs must ensure their insider threat programs can ingest and act on CE alerts in near-real-time.

05

CJIS Security Policy

The FBI's Criminal Justice Information Services (CJIS) Security Policy governs the security of criminal justice information (CJI) — a category that includes biometric data, identity history records, case/incident data, and anything derived from the National Crime Information Center (NCIC), the Interstate Identification Index (III), or the National Instant Criminal Background Check System (NICS). Every law enforcement agency, every prosecutor's office, every state motor vehicle department, and every private contractor with access to CJI must comply. The policy is not optional, and non-compliance results in disconnection from CJIS systems — which operationally shuts down a law enforcement agency.

Core Security Requirements

The CJIS Security Policy (currently version 5.9.4) is organized into 13 policy areas. The most technically demanding requirements are in encryption, authentication, and personnel security. Encryption must be FIPS 140-3 validated (not just "FIPS-compliant" — the module must appear on the NIST Cryptographic Module Validation Program list). Data in transit must be encrypted with a minimum of 128-bit AES or equivalent. Data at rest containing CJI must be encrypted with FIPS 140-3 validated modules or be physically secured to compensate. This creates real operational challenges: many legacy law enforcement systems predate these requirements and require upgrades or compensating controls.

Policy Area Key Requirements Common Compliance Gaps
AuthenticationAdvanced authentication (MFA) for all access to CJI beyond the physical perimeterLegacy MDTs (mobile data terminals) in patrol vehicles lacking MFA capability
EncryptionFIPS 140-3 validated encryption for CJI in transit and at restBody camera uploads over non-encrypted channels; legacy database encryption gaps
Personnel SecurityFingerprint-based background check for all individuals with access to unencrypted CJIContractor/vendor personnel without completed screening accessing CJI systems
Auditing & LoggingAudit logs for all access, modifications, and deletions of CJI; minimum 1-year retentionInsufficient log storage; no automated review process
Media ProtectionPhysical and logical controls on all media containing CJI; sanitization per NIST 800-88Old hard drives and laptops disposed without proper sanitization

Advanced Authentication for Law Enforcement

CJIS defines "advanced authentication" as authentication that requires at least two of three factors: something you know, something you have, something you are. The policy specifically requires advanced authentication for any access to CJI that occurs outside the physically secure perimeter — meaning an officer querying NCIC from a patrol vehicle's MDT must use MFA. This has been one of the most operationally challenging requirements to implement. Officers wearing tactical gloves cannot easily use fingerprint readers. Smartcards require readers in every vehicle. The practical solutions that have gained traction include: certificate-based authentication using CAC/PIV cards with vehicle-mounted readers, proximity-based authentication using paired devices (officer's phone + MDT), and biometric authentication using iris or facial recognition where conditions permit.

Cloud Hosting of CJIS Data

Cloud service providers hosting CJI must sign the CJIS Security Addendum — a contractual agreement that obligates the CSP and all personnel with logical or physical access to CJI data to comply with the CJIS Security Policy. Both AWS GovCloud and Microsoft Azure Government offer CJIS-compliant environments. The challenge is that the CJIS policy requires state-level approval from the CJIS Systems Agency (CSA) in each state. A cloud-hosted records management system used by agencies in 12 states requires 12 separate CSA approvals. Each state CSA can impose additional requirements beyond the federal baseline.

Mobile and Field Access Challenges

Law enforcement is inherently mobile, and the CJIS Security Policy must be applied to officers accessing CJI from patrol vehicles, body-worn cameras uploading footage containing CJI, mobile phones used for field identification, and temporary command posts during major incidents. Each scenario presents unique encryption and authentication challenges. Body-worn camera footage that captures a suspect's identity history or a license plate run result contains CJI — the entire chain from camera to cloud storage must be encrypted and access-controlled. Vendors like Axon (formerly TASER) and Motorola Solutions have built CJIS-compliant evidence management platforms, but the agency is still responsible for ensuring proper configuration, access controls, and personnel screening for everyone in the data chain.

Real-World: CJIS Audit Consequences

The FBI CJIS Division conducts triennial audits of every CSA and a sampling of agencies within each state. Audit findings are not public, but consequences are real. In multiple documented cases, agencies that failed to implement advanced authentication or encryption requirements received 6-month remediation deadlines. Failure to remediate results in disconnection from NCIC/III — meaning officers cannot run criminal history checks, warrant queries, or stolen vehicle checks. For a law enforcement agency, this is operationally equivalent to being shut down. The audit is not theoretical — treat it as a survival requirement.

06

Election Infrastructure Security

In January 2017, the Department of Homeland Security designated election infrastructure as critical infrastructure under Presidential Policy Directive 21. This was a watershed moment: it formally recognized that election systems — voter registration databases, electronic poll books, vote casting and tabulation equipment, and election night reporting systems — are national security assets. For the CISOs and IT directors at the state and county level who actually operate these systems, this designation brought access to federal resources but also a spotlight on decades of underinvestment.

The Voting System Lifecycle

Voting systems in the United States are certified by the Election Assistance Commission (EAC) through Voting System Test Laboratories (VSTLs). The EAC's Voluntary Voting System Guidelines (VVSG) define security and reliability requirements. The 2.0 VVSG standards, adopted in 2021, added software independence requirements (the ability to detect errors without relying on the software being audited) and significantly enhanced cybersecurity testing. However, certification is voluntary at the federal level — states set their own certification requirements, and many still use systems certified under older VVSG 1.0 standards.

The practical reality: voting equipment has a 10-20 year lifecycle. Counties purchased systems after the Help America Vote Act (HAVA) of 2002 and many are still running them. These systems often run end-of-life operating systems (Windows 7, Windows XP Embedded), cannot be patched without decertification, and were designed before modern cyber threats were contemplated. Replacing them requires county or state appropriation — a political process that competes with roads, schools, and public safety for funding.

Election System Component Key Threats Primary Controls
Voter Registration DatabaseData manipulation, DDoS, data exfiltrationDatabase encryption, MFA, WAF, immutable audit logs, backup verification
Electronic Poll BooksTampering, denial of service, connectivity failureAir-gapped configuration, hash verification, paper backup rosters
Vote Casting Devices (BMDs, DREs)Software manipulation, supply chain tamperingPre-election logic & accuracy testing, voter-verified paper audit trail (VVPAT), hash verification
Tabulation SystemsResult manipulation, unauthorized accessAir-gapped tabulation, two-person integrity, pre/post-election audits
Election Night Reporting (ENR)Website defacement, DDoS, result manipulationCDN, DDoS mitigation, read-only publication, digital signatures on results

The County Resource Problem

There are over 3,000 counties in the United States, and elections are administered locally. Most county election offices have zero dedicated cybersecurity staff. The county IT department — often a team of 2-5 people supporting all county functions — is expected to secure election infrastructure alongside everything else. CISA has attempted to bridge this gap through programs including Albert sensors (IDS/IPS sensors deployed at no cost to election networks in all 50 states), free vulnerability scanning and penetration testing, election security tabletop exercises (conducted in every state since 2018), and the Elections Infrastructure Information Sharing and Analysis Center (EI-ISAC).

Real Threats: What Has Actually Happened

2016 Russian Interference: The Senate Intelligence Committee confirmed that Russian intelligence (GRU) targeted election infrastructure in all 50 states. Illinois voter registration database was breached — 200,000 voter records accessed. No evidence of vote tallies being altered, but the reconnaissance demonstrated capability and intent. 2020 Disinformation Campaigns: The threat shifted from technical intrusion to information operations. Foreign actors amplified false claims about election integrity to undermine public confidence. CISA's "Rumor Control" page became the authoritative source for debunking election disinformation. The lesson: election security is not just about technical controls — it is about maintaining public trust in democratic processes.

Post-Election Audits: Risk-Limiting Audits (RLAs)

Risk-limiting audits are the statistical gold standard for verifying election outcomes. An RLA examines a random sample of paper ballots and uses statistical methods to provide a predetermined level of confidence (typically 95%) that the reported outcome is correct. If the margin of victory is large, fewer ballots need to be examined. Colorado, Georgia, and several other states have implemented RLAs as standard practice. The key prerequisite: a voter-verified paper audit trail. Without paper, there is nothing to audit. This is why the election security community has converged on hand-marked paper ballots with optical scanners as the most auditable voting method.

07

Zero Trust Architecture in Government

Zero Trust is not new as a concept — the term was coined by Forrester's John Kindervag in 2010. What is new is the federal government mandating its adoption. OMB Memorandum M-22-09, issued in January 2022, requires all federal agencies to meet specific Zero Trust security goals by the end of FY2024. This is not aspirational guidance — it is a directive from the Office of Management and Budget with measurable milestones and reporting requirements. For CISOs at federal agencies, this transformed Zero Trust from a conference buzzword into a program of record with budget implications and accountability.

CISA Zero Trust Maturity Model

CISA's Zero Trust Maturity Model defines five pillars — Identity, Devices, Networks, Applications and Workloads, and Data — each with four maturity levels: Traditional, Initial, Advanced, and Optimal. OMB M-22-09 sets specific targets within each pillar that agencies must achieve. The most impactful requirements include: enterprise-wide phishing-resistant MFA (FIDO2/WebAuthn or PIV-based), enterprise-wide EDR deployment on all agency endpoints, DNS traffic encryption (DoH or DoT), HTTP traffic encryption for all internal applications (not just external-facing), and data categorization and tagging for all high-value assets.

Pillar OMB M-22-09 Requirements Key Implementation Challenges
IdentityPhishing-resistant MFA for all staff; centralized identity managementLegacy systems without SAML/OIDC support; contractor identity federation
DevicesEDR on all endpoints; continuous device health assessmentOT/IoT devices that cannot run agents; BYOD policies
NetworksMicrosegmentation; encrypted DNS; encrypted HTTP for internal appsLegacy flat networks; budget for microsegmentation infrastructure
ApplicationsInternet-accessible applications tested regularly; routine pentestingShadow IT; legacy applications without modern authentication support
DataData categorization and tagging; automated DLP; cloud DLP for SaaSMassive data volumes; inconsistent classification; cross-agency data sharing

DoD Zero Trust Strategy

The Department of Defense released its Zero Trust Strategy in November 2022 with a target of achieving "Target Level" Zero Trust by FY2027. The DoD strategy defines 152 specific activities across seven pillars (the CISA five plus Visibility/Analytics and Automation/Orchestration). The DoD approach is more prescriptive than the civilian OMB mandate and includes specific technology requirements: Software Defined Networking (SDN) for microsegmentation, Security Orchestration and Automated Response (SOAR) for incident handling, and User and Entity Behavior Analytics (UEBA) for anomaly detection. The Thunderdome project, managed by DISA, is the DoD's enterprise-level Zero Trust implementation using Secure Access Service Edge (SASE) architecture from Zscaler.

Phishing-Resistant MFA: The Non-Negotiable

OMB M-22-09 specifically requires phishing-resistant MFA — meaning SMS codes, email OTPs, and push notifications are not sufficient. The acceptable methods are: FIDO2/WebAuthn security keys (YubiKey, Google Titan), PIV/CAC smart cards (already standard for federal employees), and platform authenticators (Windows Hello for Business, Apple Touch ID/Face ID with passkeys). The government's insistence on phishing-resistant MFA is driven by real incidents: the 2020 SolarWinds compromise and the Microsoft Exchange ProxyLogon attacks both exploited stolen credentials that would have been useless against FIDO2 authentication.

Practical Implementation Roadmap

For agencies starting their Zero Trust journey, the recommended sequencing is: Phase 1 (0-6 months) — deploy phishing-resistant MFA for all privileged users, implement centralized identity governance, and deploy EDR enterprise-wide. These deliver the highest risk reduction per dollar. Phase 2 (6-18 months) — encrypt all DNS and internal HTTP traffic, begin data categorization for high-value assets, implement microsegmentation for the most sensitive enclaves. Phase 3 (18-36 months) — achieve continuous device health assessment, deploy automated DLP policies, implement SOAR for security operations, and expand microsegmentation enterprise-wide.

The budget reality is that most agencies are funding Zero Trust through existing cybersecurity budgets plus Technology Modernization Fund (TMF) grants and CISA-provided services. The TMF has allocated over $500M since 2021, with significant portions directed toward Zero Trust implementations. CISOs should align their Zero Trust roadmap with the agency's IT modernization strategy — many Zero Trust requirements (cloud migration, application modernization, identity consolidation) overlap with broader modernization objectives, enabling shared funding justifications through the Capital Planning and Investment Control (CPIC) process.

Real-World: Implementation at Scale

The Department of Education achieved enterprise-wide phishing-resistant MFA deployment in 14 months by issuing FIDO2 security keys to all 4,400 employees and implementing WebAuthn for contractor access. Their approach: rather than waiting for a single vendor solution, they deployed YubiKeys as a bridge while implementing Azure AD Conditional Access policies that enforce phishing-resistant authentication. The key lesson from their CISO: "Do not wait for perfect architecture. Deploy MFA that stops phishing now, then iterate on the broader Zero Trust architecture. Every month you delay MFA deployment is a month your agency is vulnerable to the most common initial access vector."

08

Critical Infrastructure Protection (Government Perspective)

The US government's role in critical infrastructure protection is uniquely dual: it is simultaneously the largest operator of critical infrastructure (defense installations, federal buildings, power grids on military bases, government data centers) and the principal regulator and coordinator of critical infrastructure security across 16 designated sectors. This dual role creates inherent tensions — the government must lead by example while also setting requirements for private sector operators who control approximately 85% of the nation's critical infrastructure.

The Regulatory Framework

Presidential Policy Directive 21 (PPD-21), issued in 2013, designates 16 critical infrastructure sectors and assigns a Sector Risk Management Agency (SRMA, formerly Sector-Specific Agency) to each. CISA serves as the national coordinator and is the SRMA for eight sectors. The framework is deliberately collaborative rather than purely regulatory — the government recognizes that it cannot secure critical infrastructure through mandates alone because it does not own or operate most of it. This collaborative model operates through Information Sharing and Analysis Centers (ISACs) and Information Sharing and Analysis Organizations (ISAOs).

Sector SRMA Key Regulatory Framework
EnergyDOENERC CIP standards (mandatory for bulk electric system)
Financial ServicesTreasuryFFIEC guidance, SOX, GLBA, OCC/FDIC requirements
HealthcareHHSHIPAA Security Rule, FDA cybersecurity guidance
Water & WastewaterEPAAWIA 2018 risk assessments (mandatory); no prescriptive cyber standards
TransportationDHS (TSA)TSA Security Directives (pipeline, rail); voluntary aviation guidelines
CommunicationsCISAFCC requirements; voluntary CSRIC best practices
Defense Industrial BaseDoDCMMC 2.0, DFARS 252.204-7012
Government FacilitiesCISA / GSAFISMA, OMB directives, NIST SP 800-53

NIST CSF 2.0 for Government

NIST released the Cybersecurity Framework (CSF) 2.0 in February 2024, adding a sixth function — Govern — to the existing Identify, Protect, Detect, Respond, Recover structure. The Govern function addresses cybersecurity risk management strategy, expectations, and policy at the organizational level. For government agencies, CSF 2.0 is not directly mandatory (FISMA and NIST SP 800-53 remain the compliance baseline), but it serves as the communication framework between government and private sector operators. When CISA issues guidance to critical infrastructure operators, it is mapped to CSF. When agencies assess sector-wide risk, they use CSF tiers. CISOs at government agencies that also serve as SRMAs must be fluent in both CSF 2.0 (for sector coordination) and SP 800-53 (for internal compliance).

CIRCIA: Mandatory Incident Reporting

The Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA), signed into law in March 2022, requires critical infrastructure entities to report significant cyber incidents to CISA within 72 hours and ransomware payments within 24 hours. CISA's final rulemaking (expected 2025-2026) will define covered entities and reporting thresholds. This is a fundamental shift: for most sectors outside financial services and healthcare, cyber incident reporting to the federal government has been voluntary. CIRCIA makes it mandatory with legal enforcement. CISOs must update their incident response plans to include CISA notification workflows, designate a reporting authority, and pre-build reporting templates aligned with the CIRCIA reporting schema.

Federal, State, Local Coordination

Critical infrastructure incidents rarely respect jurisdictional boundaries. A cyberattack on a water utility affects the county, the state environmental agency, the EPA, CISA, and potentially the FBI if it involves a nation-state actor. The coordination model works through several mechanisms: the National Cyber Incident Response Plan (NCIRP) defines roles for federal agencies during significant cyber incidents, Multi-State Information Sharing and Analysis Center (MS-ISAC) serves as the primary interface between CISA and state/local/tribal/territorial governments, Joint Cyber Defense Collaborative (JCDC) brings together government and private sector for operational coordination, and Cyber Unified Coordination Groups (UCGs) are activated for significant incidents (as was done for SolarWinds and Log4Shell).

The practical challenge is that state and local government cybersecurity capabilities vary enormously. Some states (Virginia, Texas, California) have mature cybersecurity operations with dedicated CISOs and SOCs. Others have minimal staffing and rely almost entirely on CISA-provided services. The SLCGP (State and Local Cybersecurity Grant Program), funded at $1 billion over four years through the Infrastructure Investment and Jobs Act, is the first dedicated federal funding for state and local cybersecurity. Eligible uses include governance planning, risk assessments, cybersecurity workforce development, and implementation of the NIST CSF. However, $1 billion divided across 56 states and territories over four years averages $4.5M per state per year — a start, but far below the level of investment needed to close the capability gap.

Real-World: Colonial Pipeline Response

The May 2021 Colonial Pipeline ransomware attack demonstrated both the strengths and weaknesses of the government's coordination model. DarkSide ransomware forced the shutdown of the largest refined fuel pipeline in the US, causing fuel shortages across the Southeast. The federal response involved CISA (technical assessment and coordination), FBI (investigation and attribution), DOE (energy sector coordination), and TSA (subsequent mandatory security directives for pipeline operators). The incident directly led to TSA issuing mandatory cybersecurity requirements for pipeline operators — the first binding cybersecurity regulation for the pipeline sector. It also demonstrated that voluntary frameworks alone are insufficient for critical infrastructure where the consequences of compromise affect national security and public safety.

Primary sources

This lesson summarises the documents below. Where it matters — a filing, an audit response, a board paper — read the source rather than the summary. Every link was checked on 31 August 2026.

  • FedRAMP
  • DoD CIO — CMMC programme documentation (publisher blocks automated link checks; cited by name)

Self-Check Quiz: Government & Defense

Test your knowledge of government cybersecurity frameworks, classified environments, and federal mandates. A score of 90% is passing.
Question 01 of 10
Approximately what percentage of FedRAMP authorizations go through the Agency path rather than the JAB path?
Question 02 of 10
Under CMMC 2.0, which controls CANNOT be placed on a Plan of Action and Milestones (POA&M) during a Level 2 assessment?
Question 03 of 10
What two conditions are required for access to classified information?
Question 04 of 10
Which directive established the National Insider Threat Task Force (NITTF) and mandated formal insider threat programs?
Question 05 of 10
Under the CJIS Security Policy, what type of encryption validation is required for protecting criminal justice information?
Question 06 of 10
What is the primary purpose of a risk-limiting audit (RLA) in election security?
Question 07 of 10
OMB M-22-09 requires phishing-resistant MFA. Which of the following does NOT qualify as phishing-resistant?
Question 08 of 10
Under CIRCIA, within what timeframe must critical infrastructure entities report ransomware payments to CISA?
Question 09 of 10
What is the correct response when classified information is spilled onto an unclassified system?
Question 10 of 10
What is the most pragmatic CMMC Level 2 compliance strategy for a small defense contractor where only a subset of employees handle CUI?
Next Module
10 — Org-Type Adaptation
Continue to Module 10 →