December 4, 2024
Revolutionizing DoD Software: Jason Weiss on Streamlining DevSecOps and Securing the Future
Jason Weiss, the former Chief Software Officer at the Department of Defense (DoD) and now the Chief Technology Officer for Public Sector at Second Front Systems, provides an in-depth analysis of the recently updated DevSecOps fundamentals guidance. He praises the streamlined document for reducing complexity while introducing more detailed emphasis on securing the software supply chain and implementing continuous Authority to Operate (ATO). Jason explains the importance of understanding the origins of software and the conditions under which it was created, noting how details such as compiler settings are critical in the current threat environment. He delves into the shift in mindset around continuous ATO, which has evolved from being viewed as a shortcut to becoming an essential tool for agile, secure software deployment. Jason highlights the significance of integrating DevSecOps with other DoD processes, such as the software acquisition pathway, to reduce timelines and improve outcomes. Additionally, he emphasizes the value of leveraging existing managed platforms within the DoD to avoid redundancy and enhance efficiency, enabling faster innovation without sacrificing security. His observations underscore how these updates represent a significant step forward in modernizing the DoD’s approach to software development and risk management.
Key Takeaways:
- The updated DevSecOps guidance emphasizes the importance of understanding the origins and conditions of software creation, including granular details like compiler settings. This focus addresses vulnerabilities in the supply chain, which are increasingly targeted in today’s cybersecurity threat environment.
- Continuous Authority to Operate (ATO) has shifted from being perceived as a shortcut to becoming an essential framework for secure and agile software deployment. By integrating continuous monitoring, active cyber defense, and robust supply chain management, it enables faster, risk-aware operational readiness.
- Weiss advocates for leveraging existing managed platforms across the DoD, rather than creating redundant software factories. This approach reduces development timelines, improves efficiency, and enables resources to be allocated more effectively, accelerating innovation while maintaining security and compliance.
Uncovering Injustice: TenaVel Thomas and CBP's Mission to Rescue 130 from Forced Labor
TenaVel Thomas, Senior Executive Port Director for Customs and Border Protection (CBP) at the Port of New York/Newark, shares the extraordinary story of her team’s efforts to rescue 130 individuals from forced labor and indentured servitude. She recounts how a single tip—a random email she received while off duty—unfolded into a major operation that uncovered a complex scheme exploiting vulnerable individuals. Using minimal initial information, Thomas directed her team to locate and speak with the victims, whose gratitude and courage revealed a deeply exploitative situation. She elaborates on how her team’s proactive approach and strong intelligence capabilities played a pivotal role in identifying and addressing the issue. She also highlights CBP’s collaborative efforts with federal and state law enforcement partners to ensure the perpetrators were brought to justice and the victims received appropriate care and resources. Thomas reflects on the broader mission of CBP as a law enforcement agency, emphasizing the agency’s intelligence-sharing capabilities and its critical role in combating illicit migration and human trafficking. Her work, which earned her a 2023 Fleming Award, showcases the dedication, leadership, and collaboration necessary to protect vulnerable individuals and uphold the law in complex and often hidden situations.
Key Takeaways:
- Thomas emphasizes the critical role of intelligence and swift action in uncovering and addressing forced labor cases. A single tip led to the rescue of 130 individuals, demonstrating the importance of CBP’s proactive approach and its ability to act decisively with limited initial information.
- The success of this operation highlights CBP’s strong partnerships with other federal and state law enforcement agencies. By pooling resources and expertise, the collaborative effort ensured both the rescue of victims and the prosecution of perpetrators, showcasing the power of interagency cooperation.
- Thomas underscores CBP’s dual mission of enforcing laws and protecting vulnerable individuals. Her team’s compassionate engagement with victims—many of whom didn’t recognize their exploitation—illustrates how CBP’s training and leadership can effectively combat human trafficking and forced labor while prioritizing the welfare of those impacted.
Please fill out the requested information below