The GIST of Govt IT
The weekly show that breaks down ideas, innovations and decisions that cut through complexity and offer real insights from the intersection of technology and the mission.
The GIST of Govt IT
Fed Christmas in July? The OMB M-26-14 Holiday Rush Begins!
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Level One by Christmas. Level Two by Valentine's Day. Level Three by Independence Day. That's the OMB M-26-14 logging mandate clock federal agencies are now racing against — and if you don't want to spend your holidays at the office, it's time to start planning now! In Episode 13 of The GIST of Govt IT, Brian and Sean dig into OMB M-26-14 on the eve of Sean's fireside chat with CISA Director Nick Andersen. Sean breaks down what actually changed: the shift from long-term log hoarding (30 months of cold retention) to an outcomes-driven model focused on defending the cyberspace effectively, and the dramatic expansion of scope to include IoT and operational technology — the unmanaged, line-of-business-owned, often third-party-managed devices that CISOs have never had eyes on. The conversation walks through the mechanics: the Logging Reference Architecture (LRA) dropping mid-August, the 90-day plan requirement, and the three maturity levels with their rising inventory-and-logging thresholds (70/50, 80/80, 90/90). Brian and Sean unpack why asset inventory is the real "creeper" that will blindside teams, why OT discovery requires drop-in kits and passive network detection rather than active scanning that can break physical systems, why centralized logging matters for coordinated FSEB-wide defense, and how to think about "three-for-one" investments that solve this mandate and other capability gaps at once.
----------
RESOURCES MENTIONED IN THIS EPISODE
The Core Policy
- OMB M-26-14 (new logging mandate, issued May 22)
- OMB M-21-31 (the rescinded SolarWinds-era predecessor)
- OMB M-26-14 Signals a New Era for Cyber Visibility (BLOG)
Background: The SolarWinds / Sunburst Hack
- CISA on the SolarWinds supply chain compromise
- GAO review of federal M-21-31 log management adoption
The Maturity Milestones (per the memo)
- Level 1 (Basic) — ~120 days after LRA: 70% of assets inventoried, 50% logged centrally
- Level 2 (Intermediate) — ~Valentine's Day 2027: 80% inventoried, 80% logged
- Level 3 (Advanced) — ~320 days / Independence Day 2027: 90% inventoried, 90% logged
OT/IoT Discovery & Network Detection Solutions Referenced
- Zeek
- Corelight (commercial Zeek / "Sericana" reference
- Armis
- Dragos
- Nozomi Networks
SIEM, SOAR & SOC Modernization
- Continuous Threat Exposure Management (CTEM)
- CISA SIEM-as-a-service with Elastic
Related Episodes
- Episode 12: The Founding Father's Guide to Federal IT
- Episode 7: Iran Came for the US Dams and We Got Lucky: Frontline Insight from the OT Fight
- Episode 6: Cupcakes and OODA Loops: Inside(r)'s Insights Into the New Federal Cyber Playbook
Upcoming Events
- July 14 Breakfast Briefing at the National Press Club — "When the Perimeter Disappears: Securing the Converged Federal Enterprise Across IT, IoT, and OT":
- July 14 Mid-Year Federal IT Priority Setting Session with a fireside chat featuring CISA Director Nick Andersen
The Hosts & Show
- Swish Data
- GIST 360
----------
CONNECT WITH US
Got an idea for a future episode? Want to be a guest? Let us know.
Brian Lake - blake@swishdata.com
Sean Applegate - sapplegate@swishdata.com
Subscribe wherever you get your podcasts: Apple Podcasts, Spotify, or gist360.com.
Countdown To New Logging Deadlines
Brian LakeLevel one by Christmas, level two by Valentine's Day, and level three, well, that's next year's Independence Day. That's the holiday countdown that federal agencies are now staring down thanks to OMB's new M2614 logging mandate. And here's the catch. Most agencies have no idea how far behind they already are. Because this time, it's not just IT logs, it's every smart device, every sensor, and every piece of operational technology that you've probably never even had eyes on. So to break down what's changed, what's coming, and what you should be adding to your holiday asset inventory wish list, you know what we gotta do. Let's get down to the gist of it.
Welcome And The Hacker Name Bet
Brian LakeWelcome to the gist of government IT, your weekly insights from the intersection of technology and the mission. I am your host, Brian Lake, and as always, I'm joined with my co-host, Mike Ampadre, the CTO Extraordinaire and the old Marine himself, Mr. Sean Applegate. Hey Sean, how are we doing today, man?
Sean ApplegateBrian, pretty exciting. It's a great Monday, and we're gonna go talk to some interesting people tomorrow.
Brian LakeAbsolutely, here at our virtual office, not in the studio. So uh big week. Big week, Sean. Uh, I'm excited. Uh, we talked about it last week, how tomorrow you're sitting down uh with the SISA director, uh, Mr. Nick Anderson, and you're gonna be talking about uh a whole host of things, priorities for CISA over the coming year. But obviously, top of mind for a lot of folks in the government IT space right now is something that they're waiting for from SISA, and that's around OMB M2614. So before we dig, that's what today's show is gonna be about. We're gonna talk a little bit about OMB 2614, the implications for government IT, for the uh government agencies and the community at large. But before we dig into that, I gotta ask you. You know, we do it every week on our show. We're talking about hacker names. So please, can you tell me that you're gonna ask the CISA director what his hacker name would be if he wasn't actually in charge of cybersecurity for all of the federal government? So are you gonna do it? Are you gonna ask him?
Sean ApplegateI'm gonna I'm gonna ask Nick permission to do it before I do it, but we will absolutely try to get it in there. Okay. And he's Nick's Nick's a lot of fun. He's an old engineer at heart. I I'm pretty sure he has some uh hacker name ideas in the background.
Brian LakeOh man. Well, I will take that as a committed non-commit uh to try to get this out of him, but really looking forward to tomorrow's conversation. And we're gonna dig in a little bit more today about a probably a pretty big important top of mind topic that will be both part of your conversation tomorrow, but that a lot of people are facing with. So let's dive right in. Um, so M2614, uh, let's frame how we got here, right? So M2131 was a
Why The Mandate Changes Now
Brian Lakeresult of the big solar winds hack back in 2020. Um, uh sunburst, I believe, is what they called it. So and it really required federal agencies to collect logs, keep them in case they actually got attacked or their systems were penetrated. Uh so M2614 rescinds this as I understand it. So talk to me a little bit about what's changed and why now that they're producing this new uh this new mandate from OMB.
Sean ApplegateYeah, certainly. So so, like a lot of other things in the administration, we're shifting to things that are effective and efficient. Um, M2131 really focused on long-term, long-term log retention. So it was really about keep your logs around, but it wasn't about the outcomes of what you do with that data. And not all logs are equal. And so there's a lot more flexibility in M264 and focused on outcomes. So, how do we defend the cyberspace more effectively? We'll get into what that cyberspace looks like in a minute. But more importantly, you don't have to retain things for 30 months in cold retention, which is a long period of time. Really drives a lot of costs. So I think this will help CISOs spend their money in more effective manners on using the logs effectively, but not maybe paying a ton of money to keep that around for undue amounts of time. Now, they certainly could if they want to and they have budget for it, but they don't have to. It's not a not a mandate for the federal civilian executive branches. They also focus on making the logs usable and doing continuous event monitoring and then using um threat hunting, incident uh incident investigations, and other activities that are really critical for the SOC to do. So a lot of us focus on using the logs and learning, and then I probably long-term applying more machine learning, non anomaly detection, and eventually agentic SOCS to defend the cyberspace more effectively. But like most things in AI and data in business these days, as we transform, we need the data. We need quality data, the right data. Um that's really where the big change here. When you think of scope of the landscape, the biggest change is that this thing requires us as uh cybersecurity professionals to collect the IT logs that are appropriate, which we do pretty well today, generally most agencies. We need to collect the IoT logs, which are often unmanaged and line of business-owned devices that the CIO and the CISO often don't have direct line of sight to in many cases. And also the operational technology, those are things that affect things in the physical world. Water pumping stations, electric grids, building management systems, uh manufacturing systems. Um, you could extend that eventually to weapon systems or command and control systems, although the depart this doesn't directly apply to the Department of War, but the OT zero trust reference architecture definitely calls those things out as in scope as well.
Brian LakeI think they actually said it in the in the in the memo, right? It's being driven by AI accelerated attack surfaces. There's no other way about around it, right? I mean, this is the the the landscape has completely changed in just the five short years since 2131 came out.
Sean ApplegateYeah, we certainly are seeing an accelerated attacks. Um they move quicker, they're scaling quicker. Obviously, agentic frameworks make that easier and allow one person to do that, not necessarily the giant amount of funding in teams and highly skilled employees that we might have at nation states, but they certainly get additional leverage and and benefits. Outside of that, the OT environment seeing typically 2x the number of attacks that IT sees. And there's more devices in IoT and OT typically than there is in traditional IT. So think of those things being supporting the mission directly. They're they're they're why we have IT. IT is the foundation to connect things together to enable the business to do what they need to do or the mission itself. And those IoT and OT devices are directly contributing to the mission, or they're the foundational pieces of the physical world in many world cases. So if those are getting attacked twice as often, that's much more important to be aware of and defend than just the IT assets. The risk is much higher. Right.
Brian LakeNow, but but I mean, overall though, I mean, as you mentioned, I I remember when M2131 came out, it was an unfunded mandate. And then you're saying you got to keep all of these logs for such a long period of time. And the agencies are like, well, with what money, right? So but they weren't just, I mean, so they figured it out, and but they weren't just passively sitting on these logs. What were they doing with these logs previously before now this this rescind of that actual memo mandate?
Sean ApplegateSure. Every agency has a sim. So they would start with, hey, let's go take the logs, dump them in the SIM. SIMs are typically ingest-based licensing or um processor-based. And so those are the two licensing models. I think a lot of agencies are reevaluating their SIM architecture and how they layer in um scalable long-term growth for that, which would definitely come into play. And then the other thing is they're they were doing incident response, often with humans. So when you think of pivot chair operations or swivel chair operations, you had a bunch of SOC analysts, they might churn fairly often, like a help desk, and they're doing a bunch of deep investigation work, and it's complex connecting of the dots. Being able to connect those dots really depends on having the right data, good threat intel, um, good analytical tools that can connect the dots. We talked about data in the past, having a sim that can do knowledge graphs and dependency mapping, and ideally have generative AI and now agents integrated with it that do a lot of that heavy lifting for the analysts allows their job to be a lot easier. But again, if you've got that covered for IT, that's great. You know, how do you do that for these new IoT devices? Because everything's now a smart device, and then the items in the physical world that that often might not be easy to find or discover, or maybe off in their own separate networks that you don't need to get data out of upstream and into the appropriate stock. The other interesting point that most commercial organizations don't think about, or even many vendors that are in the security spaces, they have to do centralized logging and centralized authentication. So if you're running multiple disconnected networks or different classifications of networks in an F-Sub, you have to have all of those logs for every one of those networks at the highest classified or highest sensitivity SOC or logging location. So you have everything in one place to see it in one way. There's some flexibility around that relative to not mixing things in that we don't want mixed in for either either legal reasons. Uh, so think of policies and laws that we can't mix things together on. Or if we mix things together, maybe it creates something at a classification level that's maybe higher than we want it to be for that target environment. So there's there is flexibility for the CISOs and CIOs to work together on that and their stakeholders in the line of business. But those are maybe some things that were called out that make a lot of sense. They're logical, um, they'll make life easier. Um, but where do you design some of those new enhancements? How do you connect those things together or things we may not have in place today?
Brian LakeSo let's talk a little bit about what the actual mandate says. Uh, you know, the way that I read this, it feels almost like a pre-mandate, for lack of better words. Like get your house in order. More is coming. So a shot across the bow that we need to actually start paying attention to this. We're waiting on this thing called the LRA. Uh and it's going to be coming from CISA, which is why I'm excited about tomorrow's conversation with Nick Anderson. Walk us through the mechanics. Uh what is the LR, what are the LRAs or the LRA? Uh, what what what does the clock look like? And when does it actually start ticking for federal agencies?
LRA Timing And Holiday Milestones
Sean ApplegateAll right, so at a high level, let's let's cover the clock first. That's simplest. Okay, so this the memo came out, OMB M2614 came out on the 22nd of May. The CISA and OMB and the federal CISO Council will publish the logging reference architecture details, the guidance within 90 days. So that means it will be out sometime around August 18th to 20th, probably. Depends on how you want to run the math. And um, they they say count I think it's calendar days, not business days, probably, but let's assume that happens. There are effectively three main timelines. We have a requirement to get to level one uh well, the first requirement is go write your plan, assess where you're at, and submit it within 90 days. So that's that's kind of the first thing is get the plan in. At 120 days, so just 30 days after that, you have to be at level one, what's called basic level. And what's interesting is the scope is you have to be at basic um for IT, IoT, and OT devices. So there's a very heavy lift to understand the inventory first, how you're logging against those, and then what you can do with those logs. And we'll maybe talk about them more in depth. But that's that's around Christmas.
Brian LakeSo you'll see a theme here around holidays. Before Christmas, you have to identify every asset in your environment, IoT, OT, and IT asset. Is that what you're saying?
Sean ApplegateWell, so you don't have to I you need to understand your inventory first and what you're doing relative to logging for that identified inventory. You also need to probably understand what percentage of the inventory you believe you don't haven't identified yet. And so when you think of doing um hardware asset management, software assets management, and device management of all types that are connected, that's broad scope. And there's a lot of stakeholders that have their little things probably in their program or their project or their department scattered around that you need to go, you know, look under rocks and look in corners and you know, get stakeholders together to be, hey, do you have stuff? So that's probably gonna be a pretty heavy data call action and solicit that data back. And there's a lot of other ways we'll talk about how to go find those things. And so there'll be sprints on going and finding those things that maybe you weren't aware of. All right, all right.
Brian LakeSo we know what we're gonna be asking Santa for Christmas this year, basically. Right.
Sean ApplegateYeah, the Santa Christmas is hey, you gotta go get lots of things found and then do basic logging, which needs to improve. And then level three is the advanced level. And and this is 320 days after the LRA drops. That if they drop it near the end of the period, uh, which normally is what happens, that's gonna be Independence Day of 2027. So those are the dates. Level one, Christmas, level two, Valentine's Day, level three Independence Day. Pretty big milestones to hit. It's pretty hard to miss those, but those will those are memorable dates. Stick around those. Obviously, if they get it out quicker, those dates are a little bit earlier, but that's roughly what they align with.
Brian LakeSo if you don't want to spend your holidays stuck at work trying to get this done to make these deadlines, get it done early, is the message I'm hearing here.
Sean ApplegateYeah, get it done early. Okay. And again, it's not just the logging, it's the activities around those things that need to mature as well, which again we'll talk about in a minute. Okay.
Brian LakeWell, let's
Finding The Devices You Do Not See
Brian Lakelet's dig into that. Like, you know, what are those different activities? Um, do we want to start with like finding what you can't see? Uh, you keep coming back to inventory and all these assets. Why is that the hardest part? Is it political? Is it technical? Is it uh just the lacking the resource to actually go find this?
Sean ApplegateYeah, so normally most IT assets are connected and in under good management in a single domain. IoT and OT often are third-party managed. So if you have partners managing things that you pay for and are accountable for as an agency, those have to be inventory and you're accountable for logging for those things, not just knowing you have them. And so OT similar. OT might be air gapped out, they might be you know fleet vehicles with smart management GPS systems and smart video systems in them. Again, those things count. So if you're somebody like Customs of Border Protection, you have maritime platforms that have smart things on them, you have centers at borders, you have vehicles and helicopters and planes that do things. Those can be considered OT. Sure. And they might not may not be connected today. So the question is like, well, how's how's that look? How do I do those things? They probably have management systems that you can plug plumb into and get logs out of too. So there's different ways to look at logging for OT that are typically more passive or maybe integrating with their their OT management systems to pull the logs out of that that can work very well, but you have to find all of that stuff and integrate it. And sometimes those OT organizations don't operate like IT culturally, right? Those things, if you break them, they have physical real world impacts. They put people at risk. They they potentially influence chemicals or temperatures or other things in the real world that aren't as simple as rolling back an IT change to like a database or a website. So get become friends with all of your OT OT buddies in the organization, get the stakeholders together and get executive level support from the top down. Absolutely critical as we go work on this together.
Brian LakeRight. I mean, we talked about that a couple weeks ago with Matthew Schallbetter, I believe, right? We have to break down this is my kingdom and the OT world, and that now I need to be working with the IT teams and the CISOs. Um, so again, it sounds like you gotta start talking now if you haven't already, right?
Percent Targets And Centralized Visibility
Sean ApplegateYeah, and here's the the interesting percentages, right? So when you think of measuring, when you run your maturity assessment, OMB's been and CIS has been clear, your level of maturity is at the lowest level achieved across all five of the capability areas. So if you're really mature in a few, but immature in one, and you're level one and one or level zero, that's the one you have to fix. So being able to prioritize where you're at rapidly and then put very focused efforts around key levels of maturity, like one of those five areas, will be important to up level pretty rapidly because you can't report on uh intermediate level if if you're, for example, are missing half of your OT devices that are in your inventory when you get to logging. And so percentage-wise, when you think of the the initial level, that's a 70% of all devices must be inventoried, meaning you must know about all of them, have them captured, and be aware of them. And that's 70% for just the initial level. For those 70% for the initial level, you have to have logs coming in for at least 50% of those. So normally an IoT and OT, that's where we might know about a lot of stuff, but we may not be logging it centrally. The keyword is centrally, not in eight different places and no single plane of glass for people to look and process it. At the intermediate level, Brian, you have to increase that to 80% of things being identified and covered in your inventory, and then 80% have to be logged. And then for the advanced level, those numbers work to 90% being inventoried and known and documented and 90% being logged. So that's within a year, we have to get 90% of all IT, IoT, OT inventoried on paper, managed, identified, and logged centrally, again, not different places centrally. So then we can streamline our continuous event management and our threat hunting capabilities and response capabilities around that. Because ideally, you want to build that with more mature practices that leverage technology to do that quickly and centrally. The other reason that needs to be centralized is if there is a major incident, something like solar winds again, that might affect multiple agencies or a few other events like that, that where we get compromised, CISA, OMB, FBI, and others want to be able to get all of those logs aggregated and work on it proactively very quickly. So if one big agency gets impacted, they want to be able to pivot and work with all the other FSEBs quickly to go, hey, are those indicators of compromise occurring in your environment as well? So how do we defend the FSEBs as a team from a well-coordinated uh cyberspace, not try to defend those in a bunch of localized groups that aren't working together? So it's a great return on investment, a great effort to row together and fight cyberspace together across all these organizations. And honestly, Nick Anderson and I have talked about this in in previous years, huge fan of doing this effectively at scale. And I think this is where the real value is going to come from, Sissa and some of the other folks.
Brian LakeHow difficult is it to centralize all these different logs, uh collection devices into a centralized dashboard? Like what kind of a kind of a lift does that actually look like for agencies? And what type of solutions do you need to have to actually make that a reality?
OT Logging With Network-Based Signals
Sean ApplegateYeah, I think I think what you'll find is the most organizations need to make sure they have a consolidated, you know, log observability pipeline where they can point all the logs to, they can grab it and get it to where it needs to go intelligently. That's a bit like a data mesh challenge. It's pretty solved. Most agencies have something to feed those things to today. The trick with IoT and OT is a lot of those devices cannot send logs as a at a device level. And so if they're doing things locally, uh let's say inside of a vehicle or uh more importantly, a building, you might need to do passive detection. So passive discovery using network detection response. And there's a lot of use of the word network in the memo. So that when those things talk between themselves and other IoT or OT devices, a human machine interface, uh project uh process logic controller, talking to a physical asset, those things communicate locally. And our adversaries, if they penetrate those, can then move through the system of systems and affect those things. And we have to be able to see that lateral movement on the wire on the network. So network detection response with OT sensors and good network detection response with high fidelity uh logs that provide forensic value and investigations are important. So things like open source Zeek, commercialized versions of that, and Tercana from Corelate are great examples. Solutions like Armist, Dregos, Nuzomi do an exceptionally good job of understanding the OT environment, their protocols in the wire, and also in many cases can do passive dis uh listening combined with active scanning using the OT APIs themselves. So they don't put undue load on OT devices or potentially break those older devices. A lot of OT vendors will tell you hey, if you scan our devices, you could potentially impact their physical operation. So don't do that. So this is a little nuanced for organizations that haven't done it before. There's proven ways to do this at scale. And those things also, if they're they're tuned for OT, provide a lot of edge processing that gets us very efficient discovery and inventory. Very efficient alerts and alarms that are contextually aware and allow us to do investigations very efficiently to meet the mandates without just bloating the logs upstream to a general sim that maybe isn't OT capable. So that's the the probably level set from that approach is a good place to start. What most people don't realize though is again, where you put those things matters, and you can't just put them in the data center and scan the whole network because the OT environments are typically the point and layers of security, or they're not connected to the traditional network. So you have to kind of go discover those things and then drop those things in. So think of having a little OT cyber protection kit or an OT discovery kit or set of kits you can drop in really quickly to do that discovery confidently. So you feel like your plan and initial study of that to CISA is well informed and has a good strong foundation to build from. The last thing you want to do is get six months in, finally get your OT CPT kits in, go do a bunch of discovery and find out you have 50% more devices you didn't have a clue that you had, and now you got to go scramble to get logging done with 90 days before you have to be at the advanced level.
Brian LakeI remember when, I mean, you just said uh a lot of different types of technologies that are can meet the need to try to centralize all of this, this log management and this log visibility. Uh when M2131 came out, I think the biggest gripe was for many agencies what with the sheer cost of the mandate or the unfunded mandates.
Buying Smart And Avoiding Capacity Surprises
Brian LakeUm is this something that's similar? And really with the LRA not being out there yet, and we're creeping towards the the almost the end of the fiscal year here. What should agencies be doing or prioritizing on spend or really looking at you know fallout money or end-of-year fiscal spends to try to actually meet this mandate? What does that look like in your mind?
Sean ApplegateYeah, I think in our mind, the first thing is let's assess where you're at. Grab your security teams, your engineers, your industry partners, you know, build the team, do a rapid whiteboard assessment of where, you know, what's this thing made of? Where do we think we're at? Let's go start pulling that together, get ahead of that before the LRA plan drops so that you're ahead of the game. You know, that's you know, maybe it's a couple of standing meetings regularly, build a little project team around it, build momentum, and probably assign a project manager to own it. So somebody's accountable to go do the work and can build momentum over time. Again, many times your SOC directors or their lead engineers are doing a lot of this work today. You get to figure out who you're going to assign to it. But find somebody that you as a CISO can hold accountable that is good at navigating the agency. And this is probably the thing when you think of it's not really a technical problem, it's a relationships problem. So whoever you have own this, they need executive support. Um, they've got to have top-down data call support, but they know need to be in in the agency, know how to get things done across teams, and they have to have a good reputation of collaborating because they're going to bring a lot of people to the to the table and go get things accomplished with maybe new teams they've never worked with, and they need to have a little bit of you know trusted reputation when they go do the work.
Brian LakeUh and then I noticed you maybe it definitely didn't answer the procurement funding part of that question. Really, like how do you think about acquisition strategies to meet these mandates?
Sean ApplegateThat's a good question. I mean, I uh if you have you if if you have known gaps that are prioritized, and this is where where often you know a partner like Swish or others that are experts in these areas can come in, help you build the prioritized approaches, and then help navigate the most effective ways or options to address those priorities. You have to figure out what those are, but but generally speaking, a lot of our clients are still digging in on OT security to do discovery, to build those environments up, to see what's out there and then and build the processes around that or IoT. So, you know, the general gut check from people we've spoken with is hey, we're gonna need more OT sensors. We're gonna need to do this OT thing and IoT thing effectively. If there are solutions to aggregate that across IT, IO uh IT, IoT, and OT together with a single investment that's rationalized, that feels like a good financial decision to get us a lot of value. Not every solution can do that. So a lot of that's gonna depend on what do you have today, how do we integrate with it and provide a one plus one equals three result. And that's not necessarily a lot of spend, but it but it needs to be very targeted in your gaps to go get you there pretty quick. And then when you think of the cyber, the sim function itself of doing continuous event monitoring and the threat hunting and its response activities and the forensics, the fidelity matters and the ability to do that with smart technical investments, again, that can give you value in lots of broad use cases is important. And so those are probably the two big areas people need to evaluate. Do I have the passive and active scanning for those new areas I own at scale? Um, and then do I have the right things on my SIM SOAR approach to use technology to do that effectively once I get the right data in there or the bet or better, you know, higher fidelity data in there.
Brian LakeRight. So just to recap, three three for one spends, be very strategic in what you purchase now that could maybe solve both this issue and uh other issues at hand and other gases.
Sean ApplegateAbsolutely, Brian. Yeah. And probably the sleeper thing we haven't talked about is if if you add uh 40 or 50% more devices to your logging, the the sleeper thing is there may be a lot more log data coming in. And so you have to go make sure that you're wherever you're gonna put that stuff, you've got enough capacity to support it, eventually search it, and eventually do analytics on top of it. And so think about that, because that may be the surprise that we haven't necessarily thought through.
Brian LakeRight, right. Yeah, it goes back. I mean, same thing, same problem in 2131, right? You have to store all this stuff. Where do we store it? We don't have that storage, right?
Sean ApplegateYeah. Well, you think of it as a balloon, you squeeze the balloon on you know, you the old the old long uh you know uh balloon animal balloon, right? You could squeeze it on one end, the air goes the other end. In this case, this has thought thought about that a bit, right? They said, hey, you don't need to keep things around for 30 months, you really just need it for 12 at the advanced level, but but to get to like level one or two, you really just need it for six months uh hot and ideally 12 months for cold, meaning eventually retrievable. Um, so so to get to that intermediate level, you could basically get rid of may you know, you could get rid of a couple years of data potentially, save a lot of storage costs because you're now told you don't have to retain it, and then reinvest that cost on things that are much more top of mind and more valuable. Again, they're more effective and efficient ways to do the work. So don't waste it on a bunch of storage, waste it on things that help you fight and defend the cyberspace right now, today, or in the last six months, if something really hits us that we haven't found. Again, normally finding alerts and alarms still takes time. So you need uh three to six months of data around to really do most of that work.
Brian LakeThat that's an interesting point. And I think this is the whole point of the is the mandate, right, is to is to be proactive instead of reactive, which is where 2131 I always felt was the issue in that collected so that if you discover later on that you've been attacked, and we can go back and figure it out. This is really about proactivity and getting in front of it and being able to be able to manage the actual threat environment of today, right?
Sean ApplegateRight. And then and then again, spend your money or the taxpayer's money wisely. So don't keep, again, don't keep around 30 months of data if you don't ever use it. Like that's a waste of money. Let's spend it in ways that are much more effective for the real mission. And so I I think that's a great thing to do with our taxpayer funds is spend on things that matter.
Brian LakeYeah. Yeah, absolutely.
Monday Morning Plan And Executive Air Cover
Brian LakeSo we always talk a little bit about kind of getting to the point of the closing the shows, what should federal IT leaders be doing on Monday mornings to be successful for the week and beyond? So in this case, it sounds like again, they should have already been doing these kind of things. So, what should the federal cyberleaders have been doing a few Mondays ago to be ready for this mandate and then ultimately be ready for the upcoming LRA announcement in in, I mean, shoot, we're looking at less than four weeks, about four weeks here. Um what are you thinking? They should be top of mind right now.
Sean ApplegateYeah, I think I think get your team pulled together. So start networking the people, build your team two, scramble to do that IoT OT inventory. I think that's the creeper for most people. We need to get out in front. There's a lot of that, and you're gonna need to do that regularly. And I think you need to make sure that from an organizational perspective, you've mapped out the lines of business, those programs of record, those weird things you weren't maybe aware of before that are running around in the corners of different departments that you need to go engage, have a conversation, get them on board, and just build a good team effort. Um, separate of that, I think a lot of it really is, and that's going to require getting air cover. So, so again, near term, getting secretary-level air cover, communicate that to his the XDs or those number two folks, get out to the program managers and get some basic data call stuff pulled together and then pull them together and do your tabletop exercise, your your rapid assessment. Again, some of the vendors like Swish will provide the opportunity to help you run the assessment, prioritize some gaps, get some rapid ideas on what options are, size those up, and then assess what your next steps are. That assessment phase is important because you know 90 days after this thing's drop, we have to have a written plan in to for every agency into CISA OMB to analyze that. So having your working on the plan now is important because it's going to change quite a bit in the next three months. Right, right.
Brian LakeI mean, listen, mid-August, the LRA drops. If you've done your due diligence, you've built the team, you've identified your gaps and where you need to buy, you have 45 days. So we all know the government spends hundreds of billions of dollars in the last 48 hours of the fiscal year. So you really try to get in front of your leaders to prioritize these investments at if there's going to be money that's going to come and be available to be spent on things in the last week or two of the fiscal year, right? So you know, do it now. And I love the leadership air cover. Gets get your leaders to be pushing forward that this is something we have to invest in because none of us want to be spending Christmas uh at at the office trying to meet a mandate instead of at home with our loved ones or Valentine's Day. Your your wife or your husband is not going to be pleased if you say sorry, you're gonna have to do dinner on your own, right? So um, well, listen, this is moving
Resources, Blogs, And Next Week
Brian Lakefast. Uh, I think that's the biggest thing. I I've seen uh both industry and government have been talking about this pretty actively over the last several weeks. I know that we've been talking about it. I know that we're talking about it tomorrow, uh, both with um with folks at the Department of War and Department of Transportation, our breakfast briefing, but more importantly, obviously with Nick Anderson. So excited about that conversation. We're gonna have some blogs that we're gonna write from both both of these events where this is gonna be top of mind conversation, top of mind discussions. So make sure you go to gist360.com to read those blogs. Hopefully you're gonna find out, and maybe we can talk about it next week, what Nick Anderson's cyber uh hacker name is. We're really excited about that, that little piece of the puzzle there. Uh, but obviously, everything about this, it's in the show notes, places to go, resources to read, um, different um suggestions uh about how to approach assessing where you're at, working with partners to try to understand where you're where you're at in the maturity level, check it on the show notes as well. Then obviously, Sean, I mean, listen, this this is not gonna be the last time we're gonna talk about this mandate, right? I mean, it it's gonna be top of mind for the next uh the next couple weeks, the next couple months, the this the rest of this year, right?
Sean ApplegateWe have a one-year sprint ahead of us, Brian, and we all need to work together on it. Uh maybe, maybe it's a one-year marathon. Okay, one year marathon. But uh but there's some goal, there's some targets to hit. They are pretty clearly defined, and we need to go work on those targets. GAO did an interesting GAO-studied adoption of M2131 several years after it. And uh, we'll probably pull those details out in one of the blog posts. But the the bottom line is a lot of agencies didn't meet the guidance, and it was often due to funding or maybe resource, lacks of resource. So I think we'll have to work together on this and figure it out. And you know, maybe there's some ways they can use those investments for other capabilities in in both this IoT and OT space. A good example might be be able to operate and manage the environment more effectively, not just secure it.
Brian LakeYeah. Yeah. So three for one investments, right? We gotta, we gotta maximize those resources, save the tax taxpayers dollars. Uh, can't wait to the idea of a year-long sprint just just made it made my stomach churn right there. So drink your water, folks. It's gonna be a busy one. Go to gist360.com for any other information. Sean, looking forward to digging into this with you for the next couple of weeks and next couple months. But always good to talk with you, my friend. I'll see you later. Talk to you soon, brother. Hey, take care, Brunt. See you next week.