FedRAMP Summit

The Federal Risk and Authorization Management Program (FedRAMP), the government-wide plan to secure cloud products and services, is almost a decade old. It is still evolving, however. Early in 2021, the House of Representative passed a bill that would have codified a number of its provisions into law, standardizing its processes for agencies to on-ramp cloud computing technologies. To date, the Senate has not acted on the bill. At the same time, alongside FedRAMP, the Defense Department is pushing out its own security standards for suppliers, which is, in turn, seeing expanding use in civilian IT contracts.

FedRAMP remains an important part of the federal government’s “Cloud Smart” policy for agencies, as hundreds of cloud projects have been authorized by the program. As it moves into its second decade, federal policy makers and technologists look to keep FedRAMP up with ever-advancing IT and security concerns.

This summit will examine the new policy developments, challenges agencies still face in reusing authorizations, and efforts to pass legislation to put FedRAMP requirements into law. It will also look at constantly evolving security landscape, the variety of cloud deployment models and the challenges agencies face to secure the data in them.

Attendees will come away with a better understanding of:

  • How the Defense Department’s Cybersecurity Maturity Model Certification program will work with FedRAMP
  • What the transition for FedRAMP to National Institute for Standards and Technology’s SP 800-53 Rev5 -- which catalogs security and privacy controls--means for federal agencies and suppliers.
  • How state and local governments are assessing using FedRAMP
  • The current status of moves to automate the authorization process through the General Services Administration using standardized machine-readable language (Open Security Controls Assessment Language --OSCAL) and a Web Services API.
  • Lessons COVID 19 and the SolarWinds hack have taught as agencies accelerated their move to cloud and amplified the need for increased security
  • How agencies are using FedRAMP to speed digital transformation

 

 

 

Speakers

/media/images/GIG/GIGEvents/2021Custom/Speakers/Leask_JayBW.jpg

Jay Leask

Director, Strategic Accounts and Solutions

AvePoint

Read More
/media/images/GIG/GIGEvents/2021Custom/Speakers/Leask_JayBW.jpg

Jay Leask

Director, Strategic Accounts and Solutions

AvePoint

I sell software, but my passion is to help translate the needs of the business into the capabilities of available technology. Over two decades in tech I have helped customers analyze collaboration solutions against actual mission needs in helping them select the best path based on their personal critical success factors. Per my training I’m a project manager, an engineer, an architect, and a designer; but ultimately, I’m a problem solver.

/media/images/GIG/GIGEvents/2021Custom/Speakers/Gillis_RyanBW.jpg

Ryan Gillis

Vice President, Cybersecurity Strategy and Global Policy

Palo Alto Networks

Read More
/media/images/GIG/GIGEvents/2021Custom/Speakers/Gillis_RyanBW.jpg

Ryan Gillis

Vice President, Cybersecurity Strategy and Global Policy

Palo Alto Networks

Ryan and his team work with governments, companies and organizations around the world to prevent and mitigate cyber attacks. Ryan’s team leverages the capabilities of Palo Alto Networks to help senior government officials, C-suites, and boards manage cyber risk. They also develop and implement operational partnerships across industry and government by sharing actionable cyber information to counter malicious actors, conducting cybersecurity exercises, and responding to real-world cyber campaigns (e.g., WannaCry and NotPetya). Additionally, Ryan leads the company’s global public policy efforts by advising governments on strategy and legislation.

Ryan represents Palo Alto Networks at international forums and industry associations, including the World Economic Forum’s annual meeting and as a Founding Member of the Centre for Cybersecurity. As a leader in Palo Alto Networks’ Federal Ignite conference, the Joint Service Academy Cyber Summit, and the RSA Conference’s International Cybersecurity Forum, Ryan helps convene cybersecurity leaders from across the globe. He is a member of the Council on Foreign Relations and participant in the Diplomatic Track 1.5 U.S.-Australia Cyber Security Dialogue. Ryan has advised the U.S. government through the Center for Strategic and International Studies’ (CSIS) Cyber Policy Task Force, and represented the tech community on the IT Sector Coordinating Council’s Executive Committee.

Prior to joining Palo Alto Networks, Ryan spent a decade in various senior roles in the United States government with the National Security Council staff at the White House and the Department of Homeland Security. He previously worked for a startup, several systems integrators, and has served as an election monitor for the Organization for Security and Co- Operation in Europe (OSCE) in Ukraine, Montenegro, and Moldova.

has received the National Security Council’s “Outstanding Service Award,” and the Federal Computer Week “Fed 100” award. He is a graduate of Georgetown University.

/media/images/GIG/GIGEvents/2020Custom/Speakers/JudyBaltensperger2020.jpg

Judy Baltensperger

Project Manager, CDM Dashboard

Cybersecurity and Infrastructure Security Agency (CISA)

Read More
/media/images/GIG/GIGEvents/2020Custom/Speakers/JudyBaltensperger2020.jpg

Judy Baltensperger

Project Manager, CDM Dashboard

Cybersecurity and Infrastructure Security Agency (CISA)

Judy Baltensperger is a Project Manager for the Continuous Diagnostics and Mitigation (CDM) Dashboard at the Cybersecurity and Infrastructure Security Agency (CISA). In this role, she oversees the development, implementation, and acquisition capabilities of the CDM Dashboard.

Prior to joining the CISA CDM Program, Judy has experience implementing mission critical/business essential information systems with the Technical Management Directorate (TMD) of U.S. Army, PEO-EIS, PdM P2E deploying IT capabilities for the European, Southwest Asia and Pacific Theaters. As well as serving as Systems Manager deploying IT capabilities with the NATO Consultation, Command and Control in Afghanistan, Drug Enforcement Administration and several IT capabilities facilitating Intelligence Community information sharing with the Department of State, Bureau of Diplomatic Security on a global scale in hostile international environments.

Judy holds a Master of Business Administration (MBA) degree from Jones International University, a Master of Science degree in Information Security Analysis (MSISM) from University of Fairfax, and a Bachelor of Science (BS) degree in Marine Engineering Systems from the U.S. Merchant Marine Academy.

Judy is a Certified Information Systems Security Professional (CISSP) with 20+ years of experience, a certified NSA 4012 Senior Systems Manager (CNSS), and a certified NSA 4011 Information Systems Security (INFOSEC) Professional (CNSS).

Judy was recently honored as one of the of the 2018 Federal 100 Award Winners.

/media/images/GIG/People/V/Vida_JulianaBW/Vida_JulianaBW.jpg

Juliana Vida

GVP, Chief Strategic Advisor - Public Sector

Splunk

Read More
/media/images/GIG/People/V/Vida_JulianaBW/Vida_JulianaBW.jpg

Juliana Vida

GVP, Chief Strategic Advisor - Public Sector

Splunk

Juliana Vida is the GVP, Chief Strategy Advisor - Public Sector at Splunk. She and her team of business and cybersecurity advisors provide guidance, direction and thought leadership around Splunk’s Data to Everything platform. She leverages her 30 years of experience as an accomplished military and technology leader to partner with and inspire public sector leaders, customers and internal teams to harness the power of data to drive valuable outcomes.

Prior to joining Splunk, Juliana was a Vice President in Gartner Executive Programs, advising and coaching federal government Chief Information Officers (CIO) and IT senior leaders. Before entering commercial industry as an executive leader, she served honorably for 24 years as a US Naval Officer at sea and on shore as both a combatant ship driver and helicopter pilot. Her final role in government was as the Navy’s Deputy CIO in the Pentagon where she lead policy and governance over technology investments and implementation.

A 1994 graduate of the US Naval Academy, Juliana is a Special Advisor to the Washington Cyber Roundtable, Board Director for AFCEA International, AFCEA Cyber Committee member, Board Advisory for CalPoly’s Master of Business Analytics program, and an elected member of the US Naval Academy Alumni Association’s Board of Trustees. She is an active member and mentor in Women in Technology and Women in Defense.

/media/images/GIG/GIGEvents/2021Custom/Speakers/Rohde_MikeBW.jpg

Mike Rohde

Deputy Chief Information Security Officer – Federal, Office of the CISO

ServiceNow

Read More
/media/images/GIG/GIGEvents/2021Custom/Speakers/Rohde_MikeBW.jpg

Mike Rohde

Deputy Chief Information Security Officer – Federal, Office of the CISO

ServiceNow

Mike Rohde is the Deputy Chief Information Security Officer - Federal at ServiceNow focusing on securing the organization’s Government Community Cloud. He has a long history of securing cloud services and working with the Federal Risk Authorization Management Program (FedRAMP). Prior to joining ServiceNow, Mr. Rohde was the Senior Director responsible for the 3rd Party Assessment Organization (3PAO) efforts at Kratos SecureInfo. In this capacity, he led the efforts for many of the leading global cloud service providers to obtain a FedRAMP authorization from the US Government.

Mr. Rohde has also served in consulting and management positions with Booz Allen Hamilton and PricewaterhouseCoopers, and his background includes cloud security and compliance, Federal Information Security Management Act (FISMA) compliance and reporting, Security Assessment & Authorization, IT security assessments, risk mitigation strategies, privacy, IT security training, and management consulting.

Mr. Rohde achieved a Bachelor’s degree in Accounting and a Master’s degree in Accounting Information Systems from James Madison University in Harrisonburg, Va.

/media/images/GIG/People/C/Conrad_BrianBW.jpg

Brian Conrad

Acting FedRAMP Director and Program Manager for Cybersecurity

GSA

Read More
/media/images/GIG/People/C/Conrad_BrianBW.jpg

Brian Conrad

Acting FedRAMP Director and Program Manager for Cybersecurity

GSA

Brian Conrad joined the Federal Risk and Authorization Management Program (FedRAMP) team in December 2018, bringing with him a wealth of technical knowledge and leadership experience. Prior to joining the General Services Administration (GSA), Brian served for over 20 years in the United States Marine Corps, gaining experience in leadership, telecommunications/IT, government acquisition, and project management.

Upon his transition from active duty, Brian joined Booz Allen Hamilton where he spent over seven years building his IT, cybersecurity, and project management skills supporting various clients across the Department of Defense (DOD), including the U.S. Marine Corps, United States Navy, and the Chief Information Officer for the DOD. During this time, Brian became recognized as a cloud computing/cybersecurity Subject Matter Expert within the federal government.

At GSA, Brian leads multiple efforts associated with Joint Authorization Board assessment and authorization activities that facilitate the authorization and adoption of commercial cloud services across the federal government.

Brian holds an M.S. in Information Technology Management from the U.S. Naval Postgraduate School, and a B.A. in History with a minor in Economics from the University of Memphis.

/media/images/GIG/GIGEvents/2021Custom/Speakers/Cochrane_KevinBW.jpg

Kevin Cochrane*

SVP, Product Marketing

Acquia
*Providing Session Opening Remarks

Read More
/media/images/GIG/GIGEvents/2021Custom/Speakers/Cochrane_KevinBW.jpg

Kevin Cochrane*

SVP, Product Marketing

Acquia
*Providing Session Opening Remarks

Kevin Cochrane is SVP, Product Marketing at Acquia. Kevin has been a leader in the CMS industry since its inception, leading marketing teams at Interwoven, Alfresco, Adobe, Bloomreach and most recently, SAP. He is excited to continue driving innovation in the digital experience space. Kevin studied international relations at Stanford University.

/media/images/GIG/GIGEvents/2021Custom/Speakers/Pillitteri_VickyBW.jpg

Victoria Yan Pillitteri

Acting Manager, Security Engineering and Risk Management
Computer Security Division

NIST

Read More
/media/images/GIG/GIGEvents/2021Custom/Speakers/Pillitteri_VickyBW.jpg

Victoria Yan Pillitteri

Acting Manager, Security Engineering and Risk Management
Computer Security Division

NIST

Victoria Yan Pillitteri is a supervisory computer scientist in the Computer Security Division at the National Institute of Standards and Technology (NIST). Ms. Pillitteri is the Acting Manager of the Security Engineering and Risk Management Group, and also leads the Risk Management Framework team (Federal Information Security Modernization Act (FISMA) Implementation Project). The team conducts the research and development of the suite of risk management guidance used for managing cybersecurity risk in the federal government, and the associated stakeholder outreach and public-private coordination/collaboration efforts. She serves as the lead of the Joint Task Force working group, a partnership with Department of Defense, the Intelligence Community and Civilian Agencies to develop a unified security framework to protect USG from cyberattacks, and is co-chair of the Federal Cybersecurity and Privacy Professionals Forum hosted by NIST.

Victoria holds a B.S. in Electrical Engineering from the University of Maryland, a M.S in Computer Science, with a concentration in Information Assurance, from the George Washington University, completed the Key Executive Leadership Program at American University, and is a Certified Information Systems Security Professional (CISSP). She has completed a Senior Executive Service Candidate Development Program and is SES certified by the Office of Personnel Management Qualifications Review Board.

/media/images/GIG/People/R/Rao_NageshBW.jpg

G. Nagesh Rao

Chief Information Officer, Bureau of Industry and Security

US Department of Commerce

Read More
/media/images/GIG/People/R/Rao_NageshBW.jpg

G. Nagesh Rao

Chief Information Officer, Bureau of Industry and Security

US Department of Commerce

G. Nagesh Rao currently serves as Chief Information Officer for the Bureau of Industry and Security within the US Department of Commerce. Most recently he was Director of Business Technology Solutions (BiTS) at the US Small Business Administration’s (SBA) Office of the Chief Information Officer, and prior to Chief Technologist & Entrepreneur in Residence within SBA’s Office of Investment & Innovation.

Over the last 20 years, Nagesh has worked for numerous organizations in the public, private, and not for profit sectors. During his time in the public-sector, he co-developed programmatic endeavors such as i6 Green, Patents for Humanity, USAID’s-SBAR Program, and SBA’s Growth Accelerator Fund Competition. Furthermore he oversaw the creation and issuance of 5 major interagency policy committee reports, regarding the SBIR/STTR programs, for US Congress on behalf of SBA and White House-OSTP; as well he led the revamp and modernization of SBA’s digital platforms including SBIR.gov and SBA.gov. Additionally Nagesh oversaw technology direction, as part of SBA’s COVID-19 leadership response team, with respect to the agency’s Virtual Command Center, PPP and EIDL endeavors as part of the historic CARES Act efforts.

Nagesh’s musings (written and oratorical) have been featured and/or quoted via Wired, TechCrunch, WAMC-NPR, The Scientist, The National Academies, The Hill, FedTech Magazine, DC Inno, Technical.ly DC, NextGov, Daily Mirror (Sri Lankan version), Financial Times (Sri Lankan version), and The Courier-Journal.

Nagesh is a 2004 Mirzayan Fellow of The National Academies and a 2016 USA Eisenhower Fellow. Among many accolades that Nagesh has received over the years, prominent ones include the Mahatma Gandhi Pravasi Samman & Hind Rattan awards from the NRI Welfare Society, Fed 100, ACT-IAC Collaboration Award, BT 150, DC Inno 50 on Fire, 2019 Gears of Government, and the RPI Alumni Key Award.

/media/images/GIG/GIGEvents/2021Custom/Speakers/Schultz_CynthiaBW.jpg

Cynthia Schultz

Cybersecurity Federal Auditor

Uptake

Read More
/media/images/GIG/GIGEvents/2021Custom/Speakers/Schultz_CynthiaBW.jpg

Cynthia Schultz

Cybersecurity Federal Auditor

Uptake

Cynthia Schultz is the Cybersecurity Federal Auditor for Uptake Technologies. In her role, she performs internal audits on the Uptake Federal environment according to FedRAMP High and DOD IL 5 requirements, upholding the SSP and Federal Documentation suite to all Federal mandates and requirements. Additionally, she conducts regular risk assessments for Uptake Federal compliance, as well as vulnerability discovery, remediation, and all technical security initiatives within the Uptake Federal program and is preparing for FedRamp High & DOD IL 5 systems maintenance.





Prior to joining Uptake in 2020, Cynthia was the Senior Technical Manager for Caliburn International where, among other corporate responsibilities, she supported and monitored continuous compliance activities to uphold regulations and standards including; AICPA SOC II, HIPAA, NIST Cybersecurity Frameworks (800-53, 800-171), CMMC, FedRamp, ISO/IEC 27001, ITIL, and COBIT.

Cynthia holds a Bachelor’s degree in Technology from the New York Institute of Technology, a Master’s degree in Business from Ellis University and holds several professional certifications including Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), Certified Risk and Information Systems Control (CRISC), Certified Microsoft Azure Security Engineer and Project Management Professional (PMP).

/media/images/GIG/People/B/Barney_ShaneBW.jpg

Shane M. Barney

Chief Information Security Officer, Office of Information Technology

USCIS, DHS

Read More
/media/images/GIG/People/B/Barney_ShaneBW.jpg

Shane M. Barney

Chief Information Security Officer, Office of Information Technology

USCIS, DHS

Shane Barney is the U.S. Citizenship & Immigration Services (USCIS) Chief, Information Security Division (ISD) and the Chief Information Security Officer (CISO).  In this role, he manages USCIS’s next generation Information Technology Security program responsible for ensuring the confidentiality, integrity, and availability of USCIS networks, systems, and information, protection from both internal and external threats, as well as the implementation of the information security program and policies for the agency. 

Before accepting the CISO position, Shane served as the Deputy ISD Chief and Deputy CISO and has been Acting CISO since April 2018.

Prior to Shane’s roll as ISD Deputy, he was the Chief of the Cyber Intelligence Branch within ISD overseeing the classified operations, communication security, insider threat, and forensic programs for USCIS.  Before joining the federal workforce, he worked as a contractor for USCIS first in the Contracting Office in Vermont and then with the Office of Security and Integrity in Washington, D.C. As a contractor, Shane helping to charter the technical direction for the intelligence and fraud/risk detection missions on the classified networks. He developed analytical tools, data requirements, and system access needs in support of these missions.

Shane holds two Master’s Degrees and a Bachelor Degree all from the University of Vermont.

/media/images/GIG/GIGEvents/2020Custom/Speakers/RajParamesaran2020.jpg

Raj Parameswaran

President, Information Technology

Maximus Federal

Read More
/media/images/GIG/GIGEvents/2020Custom/Speakers/RajParamesaran2020.jpg

Raj Parameswaran

President, Information Technology

Maximus Federal

Raj Parameswaran has been leading Maximus Federal’s technology strategies and solutions since joining the team in May of 2015. In this role, he oversees the strategic alignment and application of leading technology platforms to deliver business outcomes. As the President of Maximus Federal Information Technology, Mr. Parameswaran also assumes responsibility for the management and delivery of the entire federal information technology solutions and services portfolio, as well as serving as Maximus Federal’s technology innovation leader for the federal market.

Prior to joining Maximus, Raj was the CEO of Optimos, where he was responsible for the overall growth strategy and operations management that included business development, program execution, financial management, and customer relationships. In this capacity, he also helped establish and drive processes that the company incorporated into its successful customer engagements. During his 18-year tenure, Mr. Parameswaran played a pivotal role in the company’s evolution to a premier enterprise solutions provider for the federal government, while achieving growth of over 200% in a 5-year period.

Mr. Parameswaran has extensive experience with architecture and delivery of enterprise solutions and has successfully led agency-wide transformation and modernization initiatives. His collaborative engagement style with customer programs has succeeded in ensuring high-quality delivery to the largest contracts in the Company’s portfolio, including clients like the Department of Treasury, National Archives and Records Administration, National Labor Relations Board, National Science Foundation, Library of Congress, Dept. of Housing and Urban Development.

Mr. Parameswaran has a bachelor's degree in electronics and a M.S. degree in information systems.

/media/images/GIG/GIGEvents/2019Custom/Speakers/GregorySisson2019.jpg

Gregory Sisson

Chief Information Security Officer

Department of Energy

Read More
/media/images/GIG/GIGEvents/2019Custom/Speakers/GregorySisson2019.jpg

Gregory Sisson

Chief Information Security Officer

Department of Energy

Mr. Sisson is currently serving as the United States Department of Energy’s Chief Information Security Officer (CISO).

Prior to joining DOE in 2018, he served as the Chief of Staff and the Deputy Director of Operations at Joint Force Headquarters Department of Defense Information Network (JFHQ-DODIN). JFHQ-DODIN is a component of United States Cyber Command, and oversees DOD information network operations and defensive cyberspace operations globally.

Before JFHQ-DODIN, he served in a number of roles at United States Joint Forces Command and the Joint Staff, training military organizations as they prepared for combat operations and was awarded the Civilian Global War on Terrorism Medal for his work. His last job was as a Cyberspace and Information Technology Training Capabilities Advisor for the Joint Staff J7 where he was instrumental in engaging stakeholders across the DOD and the interagency community to coordinate actions integral to the development, delivery and implementation of the DOD’s Cyber Strategy.

Prior to serving as a DoD Civilian, Mr. Sisson served over 20 years as a non-commissioned and commissioned officer in the United States Army where he led diverse organizations at multiple echelons. He retired as a Signal Officer in 2004.

Mr. Sisson completed his undergraduate work at the University of South Carolina Aiken where he earned a Bachelor of Arts in History and, in 2014 he earned a Master of Arts in National Security and Strategic Studies from the College of Naval Warfare in Newport, RI.

/media/images/GIG/GIGEvents/2021Custom/Speakers/Vance_TresBW.jpg

Tres Vance

Hyperscale GTM Leader

Red Hat

Read More
/media/images/GIG/GIGEvents/2021Custom/Speakers/Vance_TresBW.jpg

Tres Vance

Hyperscale GTM Leader

Red Hat

Tres Vance is currently leading Hyperscale Sales efforts within the Red Hat North America Public Sector. As an advocate for innovation, he has embraced the tenets of Open Source and community building to accelerate the move to the Open Hybrid Cloud. Prior to joining Red Hat, he co-founded the AWS effort known as ATO on AWS, an Amazon Partner program to reduce the friction to cloud adoption. He has successfully led digital transformation for multiple organizations and is experienced in entrepreneurship at the micro, midsize, and enterprise levels.

/media/images/GIG/GIGEvents/2020Custom/Speakers/JoeFlynnBW.jpg

Joseph Flynn

CTO, Public Sector

Boomi

Read More
/media/images/GIG/GIGEvents/2020Custom/Speakers/JoeFlynnBW.jpg

Joseph Flynn

CTO, Public Sector

Boomi

Joseph Flynn is the Public Sector CTO for Dell Boomi. A former CIO and Vice President, Joe brings years of Public Sector experience helping organizations and their leaders define unique, business focused solutions to complex technology programs.

/media/images/GIG/People/I/Michaela_IorgaBW.jpg

Dr. Michaela Iorga

Senior Security Technical Lead for Cloud Computing

NIST

Read More
/media/images/GIG/People/I/Michaela_IorgaBW.jpg

Dr. Michaela Iorga

Senior Security Technical Lead for Cloud Computing

NIST

Dr. Michaela Iorga, a recognized expert in information security, risk assessment and information assurance for cloud, fog and IoT systems, has a deep understanding of cybersecurity, identity and credential management, and cyberspace privacy issues. In her capacity at NIST, Michaela works with industry, academia, and other government stakeholders on developing vendor-neutral security and forensics guidance and standards. Dr. Iorga is also managing several NIST efforts that include the development of the Open Security Controls Assessment Language (OSCAL), cognitive-based fingerprinting of IoT devices, IoT security, fog computing, and risk management for cloud-based systems.

/media/images/GIG/GIGEvents/2021Custom/Speakers/Wand_PaulBW.jpg

Paul Wand

Cybersecurity Visualization Engineer

National Renewal Energy Laboratory

/media/images/GIG/GIGEvents/2021Custom/Speakers/Sanders_EricBW.jpg

Eric Sanders

Deputy Director, Cybersecurity Office
Deputy Chief Information Security Officer for Strategy & Management

National Geospatial-Intelligence Agency

Read More
/media/images/GIG/GIGEvents/2021Custom/Speakers/Sanders_EricBW.jpg

Eric Sanders

Deputy Director, Cybersecurity Office
Deputy Chief Information Security Officer for Strategy & Management

National Geospatial-Intelligence Agency

Mr. Sanders is currently serving the National Geospatial-Intelligence Agency (NGA) as the Deputy Director of the Cybersecurity Office and Deputy Chief Information Security Officer (CISO) for Management & Strategy. Previously, he served a 2-year Joint Duty Rotation at the National Reconnaissance Office (NRO) as the CISO and Director of the Cybersecurity Office where he delivered enterprise security services, streamlined the assessment and authorization (A&A) process, and delivered NRO’s first-ever agency-wide cybersecurity strategy. Prior to NRO, Mr. Sanders served the NGA as the Chief of the Risk Management where he architected and delivered NGA’s innovative approach to A&A known as REvAMP. Previously, his civil service included serving the NRO for 6 years, securing the operation of the NRO’s largest IT portfolio and multi-int groundstations. Prior to his civil service, Mr. Sanders supported multiple government and industry customers as a contractor for over 10 years.

Mr. Sanders holds a MBA from Mary Washington University, a graduate certificate in Cyber Warfare from the Naval Postgraduate School, a graduate certificate in Technology Management from the Virginia Polytechnic Institute and State University, and a BS in Computer Networking. His professional certifications include the GSTRT, CISSP, CCSP, CISM, CRISC, GCPM, and MCSE.

/media/images/GIG/People/F/Frazier_SeanBW.jpg

Sean Frazier

Federal CSO

Okta

Read More
/media/images/GIG/People/F/Frazier_SeanBW.jpg

Sean Frazier

Federal CSO

Okta

Sean Frazier is Federal CSO at Okta. In his role, Sean acts as the voice of the CSO for Okta's federal business. Prior to joining Okta, Sean spent more than 25 years working in technology and public sector security for companies such as Duo Security, Netscape, LoudCloud/Opsware, Proofpoint, Cisco & MobileIron. Sean has helped lead numerous projects used by the Department of Defense and Intelligence Community, including the Fortezza Crypto Card, Defense Messaging System (DMS) and many others. He also has extensive experience in identity and public key infrastructure (PKI), network, applications, mobile and IoT. Sean has testified in front of the U.S. Senate Homeland Security and Government Affairs Committee on the importance of public/private partnership in protecting the nation’s digital infrastructure. Sean also advises public/private partnership working groups including ACT-IAC, ATARC and many others.

/media/images/GIG/GIGEvents/2021Custom/Speakers/Bible_KennethBW.jpg

Kenneth Bible

CISO

Department of Homeland Security

Read More
/media/images/GIG/GIGEvents/2021Custom/Speakers/Bible_KennethBW.jpg

Kenneth Bible

CISO

Department of Homeland Security

Since January 2021, Kenneth Bible has served as the Chief information Security Officer at the Department of Homeland Security. Mr. Bible previously worked as Deputy Director, C4/ Deputy CIO with the U.S. Marine Corps, and occasionally served as the acting CIO. Previously, he had served as a technical adviser to the Marines commandant for all matters pertaining to identification and validation of IT requirements. Mr. Bible was also the lead for continuing assessment and identification of promising emerging C4 and information technologies for exploitation and application in the war fighting and business domains.

Agenda

9:00 AM

Wednesday, August 18, 2021

Welcome and Opening Remarks

9:05 AM

Wednesday, August 18, 2021

Building on Success: A Look at FedRAMP’s New Initiatives

Brian Conrad, Acting FedRAMP Director and Program Manager for Cybersecurity, GSA

Kevin Cochrane*, SVP, Product Marketing, Acquia
*Providing Session Opening Remarks

Description

FedRAMP has seen an incredible increase in the adoption of the program, both in agency participation and reuse of authorizations. FedRAMP's Acting Director, will discuss the program’s growth and its FY21 focus on strategic initiatives—such as automation and a threat based authorization approach—and continued partnerships with stakeholders.

Sponsored By:

 

9:35 AM

Wednesday, August 18, 2021

In nothing we trust: a journey to change the way we think about security

Sean Frazier, Federal CSO, Okta

Description

Sponsored By:

9:55 AM

Wednesday, August 18, 2021

Panel: Enabling Digital Transformation with FedRAMP

Victoria Yan Pillitteri, Acting Manager, Security Engineering and Risk Management
Computer Security Division, NIST

G. Nagesh Rao, Chief Information Officer, Bureau of Industry and Security, US Department of Commerce

Cynthia Schultz, Cybersecurity Federal Auditor, Uptake

Description

Sponsored By:

10:35 AM

Wednesday, August 18, 2021

Break

10:45 AM

Wednesday, August 18, 2021

Executive Insights: Leveraging Data & Security Analytics

Judy Baltensperger, Project Manager, CDM Dashboard, Cybersecurity and Infrastructure Security Agency (CISA)

Juliana Vida, GVP, Chief Strategic Advisor - Public Sector, Splunk

Description

With cloud migration accelerating, agencies are looking for ways to keep networks secure as they make the move. The Cyber and Infrastructure Security Agency’s CDM Dashboard-as-a-service provides a secure environment to leverage FedRAMP authorizations and control data, including data and security analytics from FedRAMP-approved Azure Service Microsoft Defender Advanced Threat Protection platform.

Sponsored By:

 

11:15 AM

Wednesday, August 18, 2021

NGA’s Journey to Multi-Cloud

Eric Sanders, Deputy Director, Cybersecurity Office
Deputy Chief Information Security Officer for Strategy & Management, National Geospatial-Intelligence Agency

Description

A look at lessons learned along the way. As one the IC’s early adopters of cloud, NGA embraced the power of cloud to derive cutting edge GEOINT capabilities. Lessons learned are being used to evolve our consumption and inform our approach to multi-cloud.

11:45 AM

Wednesday, August 18, 2021

Microsoft 365 and Teams: Real World Security + Adoption

Jay Leask, Director, Strategic Accounts and Solutions, AvePoint

Description

Sponsored By:

12:05 PM

Wednesday, August 18, 2021

Break

12:15 PM

Wednesday, August 18, 2021

Panel: How NIST’s OSCAL Can Help Automate and Reduce Risk for FedRAMP users

Joseph Flynn, CTO, Public Sector, Boomi

Dr. Michaela Iorga, Senior Security Technical Lead for Cloud Computing, NIST

Paul Wand, Cybersecurity Visualization Engineer, National Renewal Energy Laboratory

Description

A look at how the Open Security Controls Assessment Language (OSCAL) standardizes the security authorizations the cloud platforms have put in place so that they can be automated and shared, as well as continuously monitored.

Sponsored By:

12:55 PM

Wednesday, August 18, 2021

Executive Insights: FedRAMP and IT Modernization

Gregory Sisson, Chief Information Security Officer, Department of Energy

Tres Vance, Hyperscale GTM Leader, Red Hat

Description

Sponsored By:

1:25 PM

Wednesday, August 18, 2021

A CSP’s view on the Presidential Executive Order on Cybersecurity and how it relates to FedRAMP

Mike Rohde, Deputy Chief Information Security Officer – Federal, Office of the CISO, ServiceNow

Description

Sponsored By:

1:45 PM

Wednesday, August 18, 2021

Break

1:55 PM

Wednesday, August 18, 2021

Executive Insights: The Value of Automation

Shane M. Barney, Chief Information Security Officer, Office of Information Technology, USCIS, DHS

Raj Parameswaran, President, Information Technology, Maximus Federal

Description

Sponsored By:

2:25 PM

Wednesday, August 18, 2021

Investing in FedRAMP: An Industry Perspective on Securing the U.S. Government

Ryan Gillis, Vice President, Cybersecurity Strategy and Global Policy, Palo Alto Networks

Description

Sponsored By:

2:45 PM

Wednesday, August 18, 2021

How FedRAMP Plans to Keep Up with Agile Development

Kenneth Bible, CISO, Department of Homeland Security

Description

Agile software development’s goal is to accelerate applications, becoming automatic processes that allow continuous integration and development (CI/CD). However those same speedy processes can complicate FedRAMP’s goal of tighter cybersecurity. As CI/CD pipelines and DevSecOps become more ubiquitous and move to the cloud, it becomes harder to define applications’ composition and provenance. FedRAMP has to support opportunities to grow and keep up with these valuable, but fast-moving practices.

3:15 PM

Wednesday, August 18, 2021

Closing Remarks

Underwriters

Uptake
Acquia
Red Hat
Okta
Splunk
ServiceNow
Boomi
MAXIMUS
Palo Alto Networks
AvePoint