ServiceNow Federal Forum 2023: The Zero Trust Journey: A Roadmap for Success
[Music] foreign just a quick poll we did a zero trust discussion in our federal Forum last year who attended that panel raise of hands so quite a few okay fantastic so we're looking for another quality conversation today um just just given the the quick introduction that Steve gave I think it'd be worthwhile if each of you just give a little bit more information about your role and your mission and Jamie if you wouldn't mind kicking that off I don't mind at all I'm from the United States PTO and that doesn't stand for paid time off it's actually the patented Trademark Office I've been there for four years now I can't believe it it feels like 28 dog years as they go it is a highly competent Workforce we have 8 300 patent examiners and we have about a thousand trademark examiners and they're spread throughout the world 83 percent of us are in a formal teleworking agreement remote so we have our challenges ahead in zero trust and we can pass it off to Dr Kelly hey thank you so I'm the CIO of the Department of State I've been in the job for five months so ask me anything um that's a joke um we are about over a hundred thousand users and the the main thing about us is that we are located globally so we have 270 locations more than 270 uh overseas uh we are everywhere from Beijing to Vienna to Mexico City uh You Name It We Are there and we're there to help American citizens we're there to issue visas and where there is diplomats so it's a really really exciting mission so I'm at Duncan I'm CIO for Department of energy and I guess my first thing is I want to know after this whether we said anything different than was said last year and secondly that's a shout out I was telling Kelly the other day how amazing her folks are I was just in uh in in Zagreb and um uh had a control officer from her team so amazing work from the I.T Folks at state so doe um we have a few fewer sites we have 97 sites in 27 States our mission ranges from uh securing the nuclear stockpile renewing the nuclear stockpile not nuclear not proliferation to keeping up the power grid in 35 States and selling bulk power so you know when you get that nice energy from our Western Dam Network that's because do we sold it and we're in the grid to our open science Mission uh with well our science mission was 17 National Labs which ranges from open science to again nuclear materials and and research in that space and then finally our cleanup Mission we continue clean up the Manhattan Project waste and the waste we've generated since then um and you know for better for worse we own the largest cleanup sites in the country so back to you Jamie Dr Kelly and thank you very much and what we did say last year about zero trust was that you could ask five people what zero trust means and have six people with six different answers and so that brings us to our first question so the Biden Administration recently released the national cyber security strategy which commits the government to improving Federal cyber security through long-term efforts to implement a zero trust architecture so with that plan as the backdrop the big question is how would you define zero trust and what does that mean for the future and this would be for any of your panelists to answer we were chomping at the bit I was so please do the Army's always out front because we were the first service and you could take the boy out of the army but you can't take the Army out of the boy just just set the stage here right love it I love what we've done with zero trust because it can fit on your hand the Five Pillars are really a great way to describe it you have the first pillar being that thumb that opposable thumb that separates us from everybody else and that's the users then you have your applications then you have your data then you have your network and then you have your devices realize these five pillars have different maturity levels that you can be on too many people get hung up on multi-factor authentication and users of course you have to have your users strong but don't forget about the four other pillars most people realize a better benefit on your middle pillar the data if you're really concentrating on data you can have a great effect financially and for effectively with your users on data but don't forget about your devices if so much is based on MFA of the device of the users how about your MFA for devices how do you double check that your network is really have those devices that should be there that are authenticated so often hackers just uh fool other people fool other devices into thinking that there's something that they're not they shouldn't be trusted so I look at the five areas and I look at the maturity along those areas I love your answer Jamie it really speaks to the need for defensive depth and there's issues that you describe to those that we also face certainly in the private sector so moving on to our next question Kelly as the newly appointed CIO of the Department of State you've already made many critical moves to advance cyber security through zero trust programs so tell us about your journey so far and the goals that you have looking ahead um great question thanks so I first want to say um you know I showed up at the Department of State and I didn't know what to expect I had never been in a United States Embassy I didn't know anyone at the Department of State and I showed up and I was so relieved because we were talking about exactly the same Technologies I had been talking about at DOD the Department of State has done really amazing things in the past couple of years I think as a lot of us did they leveraged covid to really Embrace modernization we have a lot of cloud-based Technologies and that's incredibly important for Foreign Service officers they're moving every one to three years and it's really powerful for them to be able to continue to access email to continue to access other applications as they move globally so I also want to say you know I was really lucky that I showed up and I had an incredible team of a mix of Foreign Service and civil service and contractors in our industry partners and they were doing really really good stuff that frankly now I just get to talk about so I feel really lucky in that way and just to highlight some of the big successes they've had recently and you talked about multi-factor authentication it is absolutely not the only thing you need to do but it is a thing you need to do and so I'm incredibly impressed the team has a driven multi-factor authentication from two years ago uh we weren't doing that we just weren't doing it uh and now we're at over 70 percent uh that's a big deal uh the same sort of metrics with data with encryption so we've made meaningful changes I think one area where we've made really good changes under the leadership of our ciso Donna Bennett is Enterprise governance so something she did is she stood up like scorecards so now every assistant secretary they get a score um and it's you know it's from an A to an f and then we rank them uh and you know what Donna ranks me um we are going to improve my score uh but she ranks everybody and it's created sort of a little bit of a gamification but also it's allowed us to highlight hey here are the key things that you need to do right now 20 other bureaus are doing better than you um so that's been a big difference the things that we're moving forward to um you know in the future when I got there one big difference between the state department and DOD that I saw is that state department because of their mission which is to communicate it's to communicate with our partners abroad it's to communicate with the public it's a huge part of our mission we've stood up a lot of non-enterprise Networks um and they were stood up for good reason uh that said these are places where we're very vulnerable right they're missing a lot of the standard cyber security controls that we have in our Enterprise Network and so we're really getting after these non-enterprise networks making sure that our cyber Defenders and Diplomatic Security have visibility we're making sure that all the good things we're doing with zero trust on our big Enterprise Network that we do it for our non-enterprise networks as well so that's our next Focus area thank you Kelly So Jamie two questions for you how successful in your opinion have agencies been in implementing the president's 2021 cyber security executive order and which approach should they now take to address the new cyber security strategy that was just announced earlier this month so I love executive orders because they're all about guidance and advice and very little teeth and that's because you should have the ability to operate within any guidance with any guard rails because whenever we put down all these standards and thou must so often you're not taking into account the line level because nobody knows everything and so from high above you can't say you know eat with a fork and a spoon what happens if you need Chopsticks so the fact is that these are guidance and their guidelines I'm not going to speak for other agencies I can only speak for ourselves we take our nation's intellectual property so sacred of a duty to protect at the same time we can't protect everything because I sort of have a Jekyll and Hyde mentality about patents and trademarks on the one hand I have to keep those like I said very tightly surrounded and secured but on the other hand I need to make sure all the public knows about these intellectual property assets because they have to take them to court they have to know what they can't do in trademarks and branding and so I'm sort of Jekyll and Hyde in that regard because I do have a public duty to disclose all of the information that we have and we have nine petabytes online that's right I have nine petabytes of data information online so that's security not everything needs to be classified and one thing I would encourage other agencies to do is don't over classify things because it just makes things harder so you have to really figure out what your classification strategy is and then how to attack each one as and said we need to make sure multi-factor authentication is done it's not just a good idea it's a mandate do it you will get hacked if you don't at the same time I'm looking at devices and how we can create certificates for devices to be authenticated in the network and in the environment so this are just two things like I said data is really where you have to encrypt everything data data in motion of course happens all the time we do it all across the internet SSL et cetera et cetera nobody everybody knows that but the thing is do you think about data at rest encrypting as well as data in use encrypting and those are Technologies we're looking at to actually be beneficial in the future thank you Jamie and given these Federal mandates it's now widely accepted because of the mandates the federal agencies are moving towards Azure trust architecture so it's not a matter of when or if but when so looking at the big picture what are the most important steps that agencies should be taking now and forward to accelerate their zero trust Journey so uh so thank you so first of all Jamie those teeth that are in the EO I think they're not Neo for you because they're they're biting us but okay so I think what I'll do is tell you a little bit about what we're doing at doe because obviously the approach we're taking is what we think uh should be happening so um first of all we believe that that um successful impotations is going to you know focus on comprehensive Automation and orchestration but also we know that Doe as I describe is a very diverse environment and and we're not going to have a one-size-fits all so our goal is not to define a strategy at headquarters and say thou shalt implement it but to work together to get to a solution so we started with a zero trust working group that encompasses all of the department elements all the National Labs all the plants and sites dozens of people every week getting together to talk about this implementation process to discuss examples of success and examples where maybe things didn't go so well um and and that group works across all five pillars of the maturity model and so we've we're working together to number one measure the current maturity of zero trust within doe and then develop implementation plans and at headquarters we feel like our one of our roles is to be the Exemplar in there so we went first we developed our implantation plan first and we're using that as sort of the the the the the design that others can use to leverage as they develop their own model and their own implementation plans and um those maturity models and and the and the um levels and provided us a basis for evaluating how others are doing so as we go through this we look at the implementation plans we look at their implementation progress and we evaluate how we're doing and and where we're going um and so having that that maturity score that we create from that really helps us to know how what kind of progress we're making across the Enterprise in addition uh to getting those plans from everybody we also took some funding that we received and provided some of that out to the organization to do pilots so we said we're going to fund this particular activity that you need to accomplish so it's not simply let's try something and throw it away but we're going to try this we're going to accomplish this for you and solve your problem but in return for that funding you're going to come back to the community as a whole and share what you learned and your models and your tools and your capabilities so that either we discovered it didn't work so well we're not going to do that again or we learned that it is something that's worked and we're able to to give a leg up to everybody else in the organization to implement that capability going forward so really it's an effort to move a really diverse group of people and organizations forward all together and I think probably the most telling thing is you know we're almost two years into this and every time the group meets there are still 100 people on the phone so that tells me or on the call it tells me that that this matters to people because people vote with their feet and one of the vote with their fetus they stop showing up for meetings that aren't helpful to them so I think it's a path that is going to serve us well uh going forward thank you and and given that approach the question I have is for for all of you what are not just the successes you've seen in your progress to adopting a zero trust strategy and approach but also what are some of the challenges that you've faced as well so I'll take that I'll take a swing here um I think we've had really good success with the model of uh sort of a building tools to help with cyber security or platforms and then engaging across the department and saying hey I have this platform you can inherit some security controls or I have you know for example identity what I really want to do is my organization can build the tool and then it's consumed by other bureaus so a little bit like what Ann said is we're also very diverse right a lot of different bureaus a lot of different activity but there are some things that we all need and so there's a lot of power and one organization building these Enterprise tools and then the other you know system owners consuming those tools I think that's really powerful um but I will say what makes this hard is I think like everyone here we are operating with a lot of Legacy technology a lot of really outdated technology so then we say hey we built this thing you can just consume it hey we have this platform you can just write on it and they say like yeah but the problem is I'm like under Bill's desk and like as soon as we are operating with really outdated Technologies this model is incredibly hard so I say like we could hit zero trust out of the park uh if I was in a green field but I'm not so we have incredibly important system supporting incredibly important missions but honestly just because they're so outdated it's incredibly hard to sort of get them up to snap so what we're trying to do is really couple modernization with zero trust and something that we did I think is very cool is uh we're rolling out Wi-Fi which I think to a lot of people is like maybe not that exciting but I can assure you at the state department Wi-Fi is incredibly exciting It's tricky because of security class specification all of that but we're finally rolling it out which is great and that is our new network and it's it's going to be a zero trust instance of the network and it's going to you know improve user experience and also users just love that there's Wi-Fi um so I'm excited about all the things that we're doing to couple improved user experience with zero trust I'll add um what are the challenges so we're having to make a cultural shift um so Jamie's got some thoughts of that space too um two you know a couple ideas right we always had this you know we thought our network was hard on the outside and soft and gooey on the inside so we have to move away from that um but it's also about security by Design the idea that that we're going to make sure that the products we build and buy and operate are designed with security in mind rather than security bolted on and whether that's the product themselves or the architecture we design whatever that solution space is that we want to make sure it's security by Design and secondly we have to take a risk-based approach not all our assets are equal um and you know you probably care a lot more that I keep the grid up and running than that I keep Berkeley National Labs science land running so so if you had a choice you I probably know which one you all in this room would make is that you want me to keep the grid up and running so so we prioritize different things differently we protect things differently and because we have limited resources like everybody here uh to apply to that problem um and then the third thing I think that's a huge big mindset change for us is the idea that we're all in this together right Chris English you may have heard talk about Collective defense um and and that's a huge mindset shift from the days when we said oh I just have to be better I've been to the state department they'll go bug the state department if if if if if I'm better than them well that's that's just not the case we have to work together to secure all of our all of our assets uh the federal government into industry our allies it's a hugely important thing that's actually a big part of what the national cyber strategy is about and it's about one of the things that's really clear in that strategy is we're going to shift that burden to those who are most able to carry it so that Collective defense means that the federal government and private sector large corporations are going to carry that burden instead of what we do now which is we tend to shift it to individuals small businesses state and local government who do not have the expertise and the capability to do that so I think that's that all those cultural mind shifts are part of we have to take on that zero trust Journey I got I can't agree with you more Anne you remind me of the story about two African hikers on The Plains of the in Africa and they come upon the lion and all of a sudden the one hiker takes running shoes out of his backpack he said what are you doing you can't outrun lion but I can outrun you yep and so we have to be more cohesive in our Enterprise approach to these items and the biggest hurdle in that way the biggest challenge is the Cyber culture I love visuals right this is the Cyber culture right now everything is so intense and strict and guidance oh my gosh I'm gonna the fear of cyber is terrible we need to open up and we need to have an open cultural incrementalism not black and white yes or no you need to always keep getting better not you have to have this high idealness standard that can't be met incrementalize and improve along the five areas the five pillars of zero trust and I tell you what remember it's easy users applications need data need Network need devices right but if you don't encrypt your data it's going to really be bad just now it seems like it should have been the last word but we still have more time okay so we uh we just spent 25 minutes there looking at zero trust we we talked about taking a holistic approach ensuring to follow those five pillars we talked about some successes some challenges such as dealing with Legacy systems and the need to work closely together in this quest to reach that zero trust defense and depth approach I think that of all the countries in the world being uh working for a company in the private sector as a global services provider I think the United States is by far the most aggressive in its cyber mandates to protect our critical infrastructure and our citizens and so with that I'd like all of you to put your hands together together to give a huge thank you to our panelists Jamie Dr Kelly and Anne
https://www.youtube.com/watch?v=UniYbV0ofOQ