Federal Cybersecurity Must Move Beyond Managing Security by PDF

Presented by Carahsoft

The federal government has spent years building processes intended to demonstrate that its systems are secure. Branko Boken believes some of those processes have become so complex and expensive that they now stand in the way of the outcome they were designed to achieve.

Boken, Chief of the Architecture and Engineering Center of Excellence at the Cybersecurity and Infrastructure Security Agency, wants agencies to move away from cybersecurity managed through static documents and toward operational visibility delivered through machines.

The issue, he said, is ultimately about trust.

Screenshot 2026-07-30 at 3.26.40 PMAt the Carahsoft Summit on FedRAMP, trust referred not to the architectural principles of zero trust, but to the confidence agencies need before adopting a cloud service. A federal customer must understand what a provider is doing to protect its systems and whether the company is willing to continue sharing that information after the purchase.

Over time, government efforts to create that confidence sometimes produced the opposite result.

“We made security extremely difficult and extremely expensive,” Boken said.

The burden created a barrier for small providers trying to enter the federal market and for smaller agencies attempting to purchase modern cloud capabilities. Compliance became complicated and costly, but the additional expense did not always translate into better security.

“We need to remove these barriers with no cost to cybersecurity,” Boken said.

That requires distinguishing between the activity of compliance and the capability of defense.

Traditional federal security processes often depend on large PDF files and other documents describing the controls an organization has implemented. Those packages take time to create. They must be transmitted to another organization, opened and reviewed by people.

In a modern technology environment, that process is too slow.

“Managing cybersecurity by PDFs” is no longer feasible, Boken said.

Computer networks produce more information than human analysts can reasonably examine. Every device, application, identity service and cloud platform generates events. Asking people to review each interaction and decide what it means has long been unrealistic, and the growth of cloud and AI has made the gap even wider.

“Humans simply don’t have capacity to process the amount of information that comes out of modern computer systems,” Boken said.

Agencies therefore need machine-to-machine communications that allow security tools to exchange information without requiring a person to touch every step. The data must be structured in a machine-readable format so automated systems can process it, identify patterns and support decisions.

That information must also arrive in what CISA calls “cyber-relevant time.”

Boken deliberately avoids saying that every security event must be delivered in real time. The correct timing depends on the use.

Screenshot 2026-07-30 at 3.26.55 PMAn active incident may require an immediate response. An investigation conducted weeks later may rely on logs that were collected and preserved when the event occurred. The essential requirement is that the information be available when defenders need it.

Operational visibility gives agencies a clearer picture of what is happening inside the infrastructure supporting their systems. That picture is more valuable than a document showing what was in place during a previous assessment.

Transparency from vendors can also help address the acquisition challenge.

Agencies need some way to understand the assurance associated with a product before they buy it. A company cannot simply declare that its technology is secure and expect government customers to accept the claim.

It can demonstrate what it is doing, explain its practices and provide customers with access to meaningful security data.

“Letting your customer have visibility and showing them that you are willing to provide that data” can become a powerful tool for adoption, Boken said.

Trust is strengthened when the agency knows what information it will receive and how the provider will continue demonstrating security after implementation.

The next challenge is determining which information agencies actually need.

Modern systems generate enormous volumes of telemetry. Collecting everything without prioritization can become costly and create so much noise that defenders struggle to find the signals that matter.

CISA and the Office of Management and Budget have required agencies to log and retain certain types of security activity. Boken said those efforts are now moving through another stage of refinement as the government learns what data is most useful and how it should be stored, processed and analyzed.

Some baseline telemetry will remain valuable over time. Other requirements will change as agency architectures and adversary behavior evolve.

Finding the balance between signal and noise will be one of the government’s central cybersecurity tasks over the next several years.

Boken identified several areas that can improve both security and confidence.

The first is stronger operational visibility into the infrastructure supporting federal information systems. Agencies need to detect anomalous events, analyze incidents and understand activity across the environments on which their missions depend.

The second is secure configuration guidance.

Through its Secure Cloud Business Applications program, known as SCuBA, CISA has developed secure configuration baselines for major Microsoft and Google cloud products. Those baselines help agencies understand how to deploy commonly used services more securely.

But developing detailed guidance for every cloud platform is too large a task for CISA alone.

Boken wants individual cloud providers to create secure configuration baselines for their own products and offer them to federal customers. That would give agencies a stronger starting point and reduce the risk that a secure product is implemented through an insecure configuration.

CISA’s binding operational directives provide another mechanism for improving the security of cloud environments. When the agency identifies a vulnerability or threat requiring federal action, providers supporting government systems should be prepared to incorporate those instructions into their own infrastructure and services.

FedRAMP can help connect CISA’s direction with the cloud service providers responsible for supporting agency workloads.

The final priority is Secure by Design.

Government and industry spend significant time remediating vulnerabilities after software reaches production. Many of those vulnerabilities originate as preventable defects that could have been addressed before the product was released.

CISA is working with software developers to reduce the number of weaknesses shipped to customers.

Agencies should not have to purchase software and then devote extensive resources to correcting defects that could have been eliminated during development.

The movement away from compliance documentation does not mean government will stop requiring evidence or accountability. It means the evidence should describe the system as it operates—not simply as it appeared during an audit.

Machine-readable information, automated analysis, secure configurations and continuing transparency can provide a more accurate understanding of risk.

That is how security can become an enabler of federal innovation. The government does not need to lower its expectations. It needs processes that show whether those expectations are being met in a way that is faster, clearer and more closely connected to the actual behavior of the technology.