This site uses cookies to improve your experience. To help us insure we adhere to various privacy regulations, please select your country/region of residence. If you do not select a country, we will assume you are from the United States. Select your Cookie Settings or view our Privacy Policy and Terms of Use.
Cookie Settings
Cookies and similar technologies are used on this website for proper function of the website, for tracking performance analytics and for marketing purposes. We and some of our third-party providers may use cookie data for various purposes. Please review the cookie settings below and choose your preference.
Used for the proper function of the website
Used for monitoring website traffic and interactions
Cookie Settings
Cookies and similar technologies are used on this website for proper function of the website, for tracking performance analytics and for marketing purposes. We and some of our third-party providers may use cookie data for various purposes. Please review the cookie settings below and choose your preference.
Strictly Necessary: Used for the proper function of the website
Performance/Analytics: Used for monitoring website traffic and interactions
Modern software development is incredibly complex for federal technology managers, with products typically built from many different components from a variety of global software supply chain sources.
Govern” focuses on how an organization’s “cybersecurity riskmanagement strategy, expectations and policy are established, communicated and monitored,” the framework stated, and is intended to address the implementation and oversight of a cybersecurity strategy.
A survey by Guidehouse and the Association for Federal Enterprise RiskManagement has found that cybersecurity and privacy continue to top the list of risks that federal agencies anticipate to have the greatest impact on the strategic objectives of their organizations in the next three to five years.
Suzette Kent, former federal chief information officer and a two-time Wash100 awardee, has joined the newly established Artificial Intelligence RiskManagement Center of Excellence at StackArmor.
Close Contributing Editor , FedInsider REGISTER The post Bringing Automation to Cloud RiskManagement first appeared on FedInsider. Jane’s private sector career also includes on-air work with multiple radio and television stations, most recently as a daily drive-time host on Federal News Radio/WTOP in Washington DC.
Characterizing disaster risk and developing strategies for resilience and response to natural event hazards is core to the mission of the Pacific Northwest National Laboratory (PNNL). The science of event simulation and emergency response is based broadly on physics and earth science for climate simulations.
Federal agencies have long followed the National Institute of Standards and Technology’s RiskManagement Framework for Information Systems and Organizations to help agencies select the appropriate safeguards related to cybersecurity, privacy and supply chain riskmanagement.
The government’s new Trustworthy and Responsible AI Resource Center is expanding IT leaders’ understanding of artificial intelligence and its risks, says Reva Schwartz, research scientist at the National Institute of Standards and Technology.
Federal contracts present lucrative opportunities, but they are tied to inherent risks like missed renewals and cybersecurity. First, you must stay up-to-date with the latest contract risk mitigation However, don’t be discouraged as there are many practices and solutions to navigate these challenges.
Supplier riskmanagement is the effort associated with identifying, assessing, mitigating, and monitoring risks associated with an organization’s third party. The post What is Supplier RiskManagement? appeared first on Art of Procurement.
The post Relationship Building: The Key to Effective RiskManagement in Procurement appeared first on Art of Procurement. “You need to know your suppliers, what they can and what they can’t do, and what they’re ready to do.
Keep reading for a checklist to help you optimize procurement compliance and internal riskmanagement. Compliance and riskmanagement is a team effort Procurement compliance and riskmanagement doesn’t just fall to the procurement department—it’s everyone’s responsibility.
Non-financial riskmanagement firm Constellis announced that it has received Cybersecurity Maturity Model Certification, or CMMC, Level 2 from Cyber AB, the Department of Defenses nongovernmental partner in the CMMC program.
In a March report following that incident , the CSRB found that Microsofts operational and strategic decisions pointed to a corporate culture that deprioritized both enterprise security investments and rigorous riskmanagement.
Draper succeeds by helping customers and collaborators succeed. As a nonprofit engineering company, Draper can center its customers’ missions in designing and developing systems solutions. With an objectivity that enables unbiased assessments of technology and designs, Draper takes a multidisciplinary approach to drive innovative engineering.
diplomats abroad, according to the department’s Cybersecurity-Supply Chain RiskManagement and Emerging Technologies Working Group lead. The State Department is developing countermeasures to prevent foreign adversaries from exploiting 5G or future 6G networks and the Internet of Things to target U.S.
Several federal agencies are playing catch-up on meeting recommendations from NIST detailed in a 2018 framework for how government should incorporate privacy into their riskmanagement strategies.
Drabkin and Yukins discussed the congressionally mandated reports they did on bid protests and mandatory debarment for labor violations , through Stevens Institute of Technology’s Acquisition Innovation Research Center ; those studies, they explained, are examples of how, as the OECD has noted , public procurement can be seen more broadly as (..)
Centerra, the infrastructure services subsidiary of non-financial riskmanagement company Constellis, has secured a spot on a $249 million multiple award construction contract for general construction projects at the U.S. Naval Station Guantanamo Bay in Cuba, also known as NAVSTA.
The Federal Emergency Management Agency has announced plans to conduct a competition for a contract to provide financial, internal controls, IT audit and assessment services for FEMA’s Office of the Chief Financial Officer, or OCFO, RiskManagement and Compliance Division.
Issued by the director of national intelligence in 2008, the directive serves as the Intelligence Communitys guidance for riskmanagement and certification of information systems. Azure OpenAI and Azure Machine Learning, plus 24 other Microsoft products, have been cleared for use under the Intelligence Community Directive, or ICD, 503.
She joined the space security and sustainability company after a two-year stint at Ball Aerospace, where she was responsible for overseeing cybersecurity operations, supply chain riskmanagement,
Interos has secured a five-year contract from the General Services Administration to enable the Department of Defense and civilian agencies to access its supply chain riskmanagement platform.
The cost-plus-fixed-fee, firm-fixed-price contract also tasks the company to provide riskmanagement and cyber test frameworks for depot-level repair of the Navy’s […] Navy for operational test programs and models to support the service branch’s AN/APY-9 radar avionics line replaceable modules.
Jon Paul Kiwus, a CIA veteran with three decades of agency service, was named program manager of the national security division at Constellis , a riskmanagement and mission support services provider. Kiwus brings to the role experience with the CIA in security and operations and he retired from the agency in 2020.
Federal agencies across the government have posted their plans to comply with an Office of Management and Budget memo on artificial intelligence governance, providing a window into what riskmanagement and reporting practices will look like in the executive branch. 1 deadline.
Bindi Patel, a more than two-decade consulting industry veteran, has been appointed vice president of contracts and procurement and corporate risk officer at Springfield, Virginia-based defense and space manufacturing company Ensco.
EmeSec, a cyber riskmanagement company, will perform cyber-related services at Joint Base San Antonio-Lackland, Texas; and Scott Air Force Base, Illinois.
The company said Monday the CMMI Level 3 appraisal validates that its project, program and riskmanagement operations comply with industry best practices. Tim Spadafore,
According to the SEC, the new rules “enhance and standardize” disclosures of cybersecurity riskmanagement, strategy, and governance by public companies under the reporting guidelines of the 1934 Securities Exchange Act of 1934. The SEC determined that inconsistent disclosure practices necessitated new rules. billion to whistleblowers.
For 40 years and counting, LMI has been at the forefront of innovating solutions for the healthcare, artificial intelligence, supply chain management, disaster and pandemic riskmanagement, space innovation, and science and technology sectors. A seasoned industry player
A riskmanagement approach: IT leaders need to know what the threats are and where they come from. This applies to identity management, too: understanding how personal attributes are assigned and validated. “It It all comes down to riskmanagement,” Nielsen said.
“What’s interesting in financial services is that third-party riskmanagement is very different than supplier riskmanagement. The post Establishing a Single Source of Truth for Third-Party Risk in Financial Services appeared first on Art of Procurement. When a financial.
Navy Veteran with over 30 years of experience across sectors including finance, technology, aerospace, defense and logistics, Troy Edgar leads IBM Consultings Federal Supply Chain Transformation organization, which includes asset and facility optimization and supply chain riskmanagement. Supply chains are the backbone [.]
The military branch said Wednesday it will implement the Commercial Space Strategy through four lines of effort: collaborative transparency, operational and technical integration, riskmanagement
For WashingtonExec’s Top Supply Chain Execs to Watch in 2023, we identified the leaders in GovCon helping federal customers with supply chain riskmanagement, managing procurement processes, centralizing supply chain systems, ensuring technology is getting to where it needs to go, and helping the nation work through unprecedented supply chain challenges. (..)
The space agency said that it had systems in place for dealing with the risks of space. While we do not dispute this, we note that NASA’s space security guide recognizes that NASA does not currently have a cybersecurity riskmanagement framework for end-to-end integrated space mission systems,” the auditing agency said in response.
Compliance and RiskManagement: In addition to staffing and technology, procurement professionals need to ensure that all solutions meet regulatory requirements. It’s important to have clear lines of communication between all stakeholders, as well as access to medical personnel who can respond to emergencies on the ground.
Most recently, Furness served as deputy CISO and director of cyber riskmanagement at Children’s National Hospital. He joined the pediatric hospital in December 2020 as director of cybersecurity governance and riskmanagement.
Strengthening Digital Accessibility and the Management of Section 508 of the Rehabilitation Act Class Deviation—Implementation of the United States Trade Representative Trade Agreements Thresholds Civilian Agency Acquisition Council (CAAC) Consultation to Issue a Class Deviation from the Federal Acquisition Regulation (FAR) Regarding New Trade Agreements (..)
Supply Chain RiskManagement on the World Stage – Lessons Learned. Organizations should continue to monitor and analyze events around the world and develop a riskmanagement process to gather risk signals and information to alert stakeholders to potential disruptions.
A different agency spokesperson confirmed in an interview with FedScoop that the NRC has conducted “some limited risk assessments” of generative AI tools that are publicly available to “help us develop our policy statement.”
We organize all of the trending information in your field so you don't have to. Join 5,000+ users and stay up to date on the latest articles your peers are reading.
You know about us, now we want to get to know you!
Let's personalize your content
Let's get even more personalized
We recognize your account from another site in our network, please click 'Send Email' below to continue with verifying your account and setting a password.
Let's personalize your content