FCW Workshop: CMMC

As DOD continues the roll-out of its Cybersecurity Maturity Model Certification program, both government acquisition professionals and the contracting community are scrambling to understand and implement the certification requirements. A change to Defense acquisition rules that took effect at the end of November kicked off new requirements for self-certification on security, strategy plans and reporting milestones. The General Services Administration also began including CMMC certification as a requirement in some upcoming contracts, and DOD indicated it would offer CMMC reciprocity to FedRAMP authorized cloud providers to help mitigate the costs of new assessments. Meanwhile, there is a question about whether there will be enough assessors available to handle the large base of defense contractors.

Attendees learned the latest on what is required and what may be ahead for acquisition and contracting executives concerning cyber certifications and audits as government and industry experts share their insights and lessons learned.

Those who joined us walked away with an improved ability to:

  • Understand NIST SP 800-171 and its 110 controls
  • Register on the Supplier Performance Risk Systems and its importance
  • Produce and maintain a System Security Plan and Plan of Actions and Milestones
  • Prepare for future audits by third party auditors
  • Mitigate gaps in contracting processes

Speakers

/media/images/GIG/People/C/Calkins_BobBW.jpg

Bob Calkins

Senior Director of Sales Engineering, Public Sector

Gigamon

Read More
/media/images/GIG/People/C/Calkins_BobBW.jpg

Bob Calkins

Senior Director of Sales Engineering, Public Sector

Gigamon

With over 30 years in the IT industry and almost 9 years with Gigamon, Bob leads a large team of highly successful Systems Engineers in Gigamon’s Public Sector division. With extensive experience in technologies ranging from SMB to complex multi-national organizations, he has spent decades solving problems for both public as well as private sector businesses.

When not recruiting the best technical team in the industry and helping customers’ networks stay secure and optimized, he enjoys golf, bicycling and international travel.

/media/images/GIG/GIGEvents/2021Custom/Speakers/Clark_KennethBW.jpg

Kenneth Clark

Chief Data Officer and Assistant Director, Office of Information Governance and Privacy

U.S. Immigration and Customs Enforcement

Read More
/media/images/GIG/GIGEvents/2021Custom/Speakers/Clark_KennethBW.jpg

Kenneth Clark

Chief Data Officer and Assistant Director, Office of Information Governance and Privacy

U.S. Immigration and Customs Enforcement

Dr. Kenneth (“Ken”) Clark is the ICE Chief Data Officer and Assistant Director, Office of Information Governance and Privacy responsible for advancing ICE's data and information management program efforts in privacy, records and data management, information governance, and Freedom of Information Act compliance. Prior to this position, he was the Senior Advisor to the Assistant Director, Office of Information Governance and Privacy, and the Deputy Assistant Executive Director, Law Enforcement Information Sharing Initiative in the Homeland Security Investigations directorate responsible for planning and coordinating operational, administrative resources, and functions related to law enforcement information sharing and statistical program reporting. This included providing expert law enforcement information sharing policy, strategic planning, and program planning support to ICE and the U.S. Department of Homeland Security (DHS), and ensuring proper safeguarding and adherence to policy, procedures, and laws regarding law enforcement information sharing activities with federal, state, local, and foreign partners.

Joining the ranks of the Senior Executive Service in 2012, Dr. Clark served as the Director, Information Sharing and Intelligence Enterprise Management in the DHS Office of Intelligence and Analysis. In this position he led strategic program planning and priorities development efforts to guide interagency intelligence sharing and analysis, program management for multi-mission threat information sharing, and Homeland Security Enterprise resource planning. This included partnering with the DHS Cybersecurity and Infrastructure Security Agency to establish a joint program that increased critical infrastructure threat information sharing to the private sector, leading cross-DHS efforts that implemented White House information safeguarding mandates affecting classified information technology networks, and initiating a new mission requirements approach to develop a DHS-wide command and control and common operating picture capability, and improve intra- and interdepartmental law enforcement information sharing.

Dr. Clark has over 30 years of professional experience in the Federal Government and in the private sector working with diverse organizations from the homeland security, defense, intelligence, law enforcement, and diplomatic communities. He designed and led nationwide information sharing policy, standards, and enterprise architecture programs, and full-scope continuity of operations, cybersecurity, and critical infrastructure protection programs. He is a retired lieutenant colonel in the U.S. Air Force and served in positions that included Presidential Communications Officer under Presidents Clinton and Bush, White House Military Office Director of Information Technology Management, and Commander of the National Reconnaissance Office headquarters' telecommunications and information technology operations and maintenance organization supporting over 5,000 customers.

Dr. Clark received his Doctor of Philosophy degree in public policy from the George Washington University, and his Master of Engineering degree in electronic engineering from the California Polytechnic State University. He is Chief Information Officer certified through the Department of Defense, and holds Senior Level Federal Acquisition Certification for Program and Project Managers. Ken and his wife Sheila live in Virginia.

/media/images/GIG/People/W/Whitworth_AlexBW.jpg

Alex Whitworth*

Director of Supply Chain Management

Carahsoft

*Providing Session Opening Remarks

Read More
/media/images/GIG/People/W/Whitworth_AlexBW.jpg

Alex Whitworth*

Director of Supply Chain Management

Carahsoft

*Providing Session Opening Remarks

Alex Whitworth is an IT executive with more than 11 years of experience in all aspects of public sector sales, marketing and channel development. As Director at Carahsoft Technology Corp., he manages several sales teams, providing leadership and insight into the Public Sector IT marketplace. His teams play a major role in supporting the government’s evolving cybersecurity demands, with a deep focus towards supporting agencies with successful zero trust adoption. In addition, he leads Carahsoft Technology Corp.’s corporate strategic efforts in helping agencies with Supply Chain Risk Management objectives and helping organizations meet compliance with the DoD’s CMMC initiative.

As the trusted government IT solutions provider, Carahsoft serves as the largest government distributor for Microsoft, RSA, Forescout, IronNet, and Eclypsium among others. The company also drives value for an extensive ecosystem of resellers, system integrators, and consulting partners serving the government, education and healthcare markets.

/media/images/GIG/People/P/Perry_PatrickBW.jpg

Patrick Perry

Director of Emerging Technology DOD | IC

Zscaler

Read More
/media/images/GIG/People/P/Perry_PatrickBW.jpg

Patrick Perry

Director of Emerging Technology DOD | IC

Zscaler

As Director of Emerging Technology, Patrick is responsible for the alignment of usable and secure Zscaler capabilities providing dynamic, mission-focused capability with tailored operations to the Department of Defense (DoD) and Intelligence Communities (IC).

Patrick recently retired from the Army as a Signal Corps Chief Warrant Officer Four after 21+ years of service. Patrick’s experience over the last 15 years has been with the U.S. Special Operations community. Throughout his career, he has served as the Chief Technical Advisor to senior military leaders as well as performed both network and security engineer positions. He specialized in developing innovative and emerging technology solutions to both strategic and tactical missions globally.

Patrick holds degrees from the University of Oklahoma and University of Maryland University College, as well as industry certifications including 2 x CISCO Certified Internet Expert (CCIE) and a CISSP. He is married to a career Army Signal Officer currently serving on active duty and they have five children.

/media/images/GIG/People/W/Wakeman_RichardBW.jpg

Richard Wakeman

Senior Director, Aerospace & Defense for Azure Global Engineering and Commercial Industry Lead for Azure Government

Microsoft

Read More
/media/images/GIG/People/W/Wakeman_RichardBW.jpg

Richard Wakeman

Senior Director, Aerospace & Defense for Azure Global Engineering and Commercial Industry Lead for Azure Government

Microsoft

Richard Wakeman is the Senior Director of Aerospace & Defense for Azure Global Engineering, and is the commercial industry lead for Azure Government, Microsoft’s cloud solution specifically engineered to meet US government compliance and security requirements. He specializes in the Defense Industrial Base adopting cloud services from Microsoft and is the Program Manager for the Microsoft Cybersecurity Maturity Model Certification (CMMC) Acceleration Program. Richard engages with Microsoft partners and customers end-to-end from engineering to drive adoption of Azure Government, Microsoft 365 GCC High and Dynamics 365 GCC High as solutions within the Microsoft US Sovereign Cloud.

Richard joined Microsoft in 2007 as a developer, identity and messaging expert at the dawn of Microsoft Online Services. Shortly after joining, he was engaged by the Exchange Product Group to lead cloud deployments worldwide for Live@edu as part of the Exchange Labs program, the predecessor of Office 365. He led the charge for integration of MCS and Premier services with cloud offerings, becoming a Senior Architect for the Microsoft Enterprise Services Business Productivity Global Domain Solution Architecture Office. During the decade tenure in professional services, Richard had impact in deploying over 100 million seats into the Microsoft cloud. He deployed the first Microsoft cloud customers, to include the first million seat organization in the public multi-tenant cloud to the first Government Community Cloud customer.

Following his role in Microsoft Enterprise Services, Richard joined the sales organization as the lead Modern Workplace Global Black Belt for Aerospace & Defense. In the GBB role, Richard engaged with the Defense Industrial Base adopting Microsoft 365 GCC High.

In his role guiding customer journeys to the cloud, Richard has worked with hundreds of the most prominent world-wide accounts, adopting the evolving Microsoft Online Services from Live@edu to BPOS to Office 365 and Azure, and now Microsoft’s new sovereign clouds such as Azure Government.

/media/images/GIG/GIGEvents/2019Custom/Speakers/KeithNakasone2019.jpg

Keith Nakasone

Deputy Assistant Commissioner, Acquisition
Office of Information Technology Category
Federal Acquisition Service

General Services Administration

Read More
/media/images/GIG/GIGEvents/2019Custom/Speakers/KeithNakasone2019.jpg

Keith Nakasone

Deputy Assistant Commissioner, Acquisition
Office of Information Technology Category
Federal Acquisition Service

General Services Administration

Mr. Keith Nakasone is the Deputy Assistant Commissioner, Acquisition Management, within the Office of Information Technology Category (ITC) in GSA’s Federal Acquisition Service (FAS). The Federal Acquisition Service provides buying platforms and acquisition services to Federal, State and Local governments for a broad range of items from office supplies to motor vehicles to information technology and telecommunications products and services. As an organization within FAS, ITC provides access to a wide range of commercial and custom IT products, services and solutions.

Acquisition Management provides oversight of strategy development, internal training for the acquisition workforce, and system support for executing ITC’s acquisition, some of the largest in government, such as Schedule 70, IT Governmentwide Acquisition Contracts (GWACs) and Telecommunications contracts such as Networx and Enterprise Infrastructure Solutions (EIS). Additionally, the office establishes training and development programs to ensure a trained, engaged, innovative, and forward-thinking acquisition workforce.

Mr. Nakasone started his civil service career in 1989 specializing in the field of Procurement with an emphasis in Telecommunications and IT Services, Hardware and Software. Prior to joining ITC, Mr. Nakasone served as Senior Procurement Executive at the FCC overseeing the Acquisitions and Procurements, Contracting Officer’s and Contracting Officer’s Representatives Certification Programs, as well as responsible for the Small Business goals for the agency. Mr. Nakasone’s almost 30 years of work experience included:

  • Technical Director/JELA Program Manager, Procurement Directorate, DISA HQ
  • Deputy, Strategic Planning, Analysis, and Governance Division, DISA HQ
  • Agile Implementation Manager, DoD/VA Interagency Program Office (IPO)
  • Chief, Hawaii Procurement Division and the Deputy for the Defense Information Technology Contracting Organization-Pacific (DITCO-PAC)
  • Chief, Hawaii Product and Services Branch, DITCO-PAC

His education includes a Master of Science, National Resource Strategy, National Defense University, Industrial College of the Armed Forces, Ft. McNair, Washington D.C.; Bachelor of Science, Business Administration w/Distinction Cum Laude, Hawaii Pacific University, Honolulu, HI. And he currently holds certifications in Change Agent, Implementation Management Associate; Scrum Master, CSM, Winnow Management; Level III Certified – Acquisition Career Field of Contracting; Certification of Completion – Defense Senior Leadership Development Program (DSLDP); Senior Acquisition Certificate – National Defense University, Industrial College of the Armed Forces; and Executive Leadership Training Certificate – George Washington University.

/media/images/GIG/People/B/Buehler_KimberlyBW.jpg

Kimberly Diane Buehler

Director, Army Office of Small Business Programs

U.S. Army

Read More
/media/images/GIG/People/B/Buehler_KimberlyBW.jpg

Kimberly Diane Buehler

Director, Army Office of Small Business Programs

U.S. Army

Ms. Kimberly D. Buehler serves as the Director for the Army Office of Small Business Programs, where she provides executive leadership for all aspects of the Army's small business mission. Ms. Buehler represents the Secretary of the Army at congressional committee and subcommittee hearings on small business matters, and leads strategic inter-agency communication with the Small Business Administration, the Office of Federal Procurement Policy, the Minority Business Development Agency (Department of Commerce), and other agencies and presidential commissions. Ms. Buehler previously held various assignments with the Department of Army, including serving as the Director of Procurement Policy for the Deputy Assistant Secretary of the Army (Procurement). Her educational accomplishments include earning a Master of Arts in Art History from Temple University, Philadelphia, Pennsylvania (1996) and a Bachelor of Arts in History from Trenton State College, Ewing, New Jersey (1993). Ms. Buehler is Level III Certified in Contracting, Level I Certified in Program Management, and a member of the Army Acquisition Corps Member.

/media/images/GIG/GIGEvents/2021Custom/Speakers/KelleyDempseyBW.jpg

Kelley Dempsey

Senior Information Security Specialist, Information Technology Laboratory/Computer Security Division

National Institute of Standards and Technology

Read More
/media/images/GIG/GIGEvents/2021Custom/Speakers/KelleyDempseyBW.jpg

Kelley Dempsey

Senior Information Security Specialist, Information Technology Laboratory/Computer Security Division

National Institute of Standards and Technology

Kelley Dempsey began her career in IT in 1986 as an electronics technician repairing computer hardware before moving on to system administration, network management, and information security. In 2001, Kelley joined the NIST operational Information Security team, managing the NIST information system assessment and authorization program, and then joined the NIST Computer Security Division FISMA team in October 2008. Kelley has co-authored a variety of NIST publications related to information security risk management including Special Publications 800-37, 800-53, 800-128, 800-137, and 800-171 and Interagency Reports 8011 and 8023. Kelley holds a B.S. in Management of Technical Operations and an M.S. in Information Security and Assurance as well as CISSP, CAP, and Certified Ethical Hacker certifications.

/media/images/GIG/People/H/Hansen_BrentBW.jpg

Brent Hansen

Chief Technology Officer

Thales Trusted Cyber Technologies

Read More
/media/images/GIG/People/H/Hansen_BrentBW.jpg

Brent Hansen

Chief Technology Officer

Thales Trusted Cyber Technologies

Brent Hansen is Thales Trusted Cyber Technologies Chief Technology Officer. Brent leads Thales Trusted Cyber Technologies’ sales engineering organization and spends the majority of his time evangelizing and strategizing on data-centric approaches for federal agencies looking to avert being the next victim of a data breach.

Brent brings over 19 years of IT experience in data and enterprise architecture, data warehousing, big data, and business intelligence. He is an industry expert in data encryption and tokenization. He leads teams that architect security strategies to secure and protect sensitive data for both federal government and large commercial enterprises across the globe.

Agenda

8:30 AM

Wednesday, May 19, 2021

Welcome

8:35 AM

Wednesday, May 19, 2021

Opening Keynote: CMMC: The Interagency Perspective

Kenneth Clark, Chief Data Officer and Assistant Director, Office of Information Governance and Privacy, U.S. Immigration and Customs Enforcement

Alex Whitworth*, Director of Supply Chain Management, Carahsoft

*Providing Session Opening Remarks

Description

This session will provide insights from an interagency mission partner on the Department of Defense’s implementation of the CMMC. The discussion will explore interoperability questions, iinter-agency data and information sharing, the benefits of improved data protection within the Federal government’s supply chain, as well as the burden on suppliers as CMMC is implemented.



9:05 AM

Wednesday, May 19, 2021

Applying Data Protection Best Practices to CMMC

Brent Hansen, Chief Technology Officer, Thales Trusted Cyber Technologies

Description

Whether an organization is addressing CMMC requirements for maturity level 1 or level 5, data protection should be at the core of every cybersecurity strategy. Organizations need to take a data-centric approach to security which means applying protection to the data itself and not solely relying on perimeter protection.  Data-centric security focuses on what needs to be protected—the files containing sensitive information—and applying the appropriate form of protection no matter where the data happens to be.

Attend this session to learn how to apply data protection best practices to CMMC. Attendees will learn how to: 

  • Develop a data-centric security strategy to defend data where it lives and where it begins
  • Detect threats and issue alerts
  • Address CMMC security controls through encryption, key management and identity and access management


Sponsored By:

9:25 AM

Wednesday, May 19, 2021

Fitting the Pieces Together: How GSA Will Make CMMC Part of its Contracts

Keith Nakasone, Deputy Assistant Commissioner, Acquisition
Office of Information Technology Category
Federal Acquisition Service, General Services Administration

Description

Keith Nakasone from GSA’s IT Category Office will discuss how they are shifting the focus from compliance to cybersecurity maturity model certification and how by integrating cyber and supply chain security directly into IT contracts, they can dramatically reduce supply chain risk.



9:50 AM

Wednesday, May 19, 2021

CMMC - Accelerate the Process | Reduce Complexity and Cost

Bob Calkins, Senior Director of Sales Engineering, Public Sector , Gigamon

Description
Sponsored By:

10:10 AM

Wednesday, May 19, 2021

Coffee Break

Description

10:15 AM

Wednesday, May 19, 2021

Protecting Sensitive, but Unclassified, Data

Kelley Dempsey, Senior Information Security Specialist, Information Technology Laboratory/Computer Security Division, National Institute of Standards and Technology

Description

Controlled Unclassified Information (CUI) has the same value and potential adverse impact if compromised, whether such information is located in a federal or a nonfederal organization. NIST Special Publications (SPs) 800-171 and 800-172 provide recommended security requirements for protecting the confidentiality of CUI when the CUI is resident in nonfederal systems. The session will provide a brief synopsis on the history and development of SPs 800-171 and 800-172, the relationship between SP 800-171 and SP 800-172, and an overview of the guidance from the NIST perspective including a discussion of basic, derived, and enhanced security requirements.

10:40 AM

Wednesday, May 19, 2021

Crossroads: CMMC and Transformation

Patrick Perry, Director of Emerging Technology DOD | IC, Zscaler

Description
Sponsored By:


11:00 AM

Wednesday, May 19, 2021

Tips for Working with CMMC Smoothly

Kimberly Diane Buehler, Director, Army Office of Small Business Programs, U.S. Army

Description

The session will provide insight to the challenges faced by both small businesses and government contracting officials in implementing CMMC, and an overview of the available resources to help industry embrace and execute cybersecurity processes and practices.


11:25 AM

Wednesday, May 19, 2021

Modernize your organization while maintaining CMMC compliance

Richard Wakeman, Senior Director, Aerospace & Defense for Azure Global Engineering and Commercial Industry Lead for Azure Government, Microsoft

Description
Sponsored By:

11:45 AM

Wednesday, May 19, 2021

Closing

Underwriters

Thales
Gigamon
Zscaler
Microsoft