Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

Stop acting. Start owning.

Дата публикации: 20-08-2026 20:32:21

Bill James, a former deputy assistant secretary for DevOps at the VA, calls on agency leadership to appoint a permanent CISO and address cyber risks.

Основное содержимое страницы с новостью.

Bill James, a former deputy assistant secretary for DevOps at the VA, calls on agency leadership to appoint a permanent CISO and address cyber risks.

William "Bill" James

August 20, 2026 4:32 pm

4 min read

I spent years inside the Department of Veterans Affairs’ Office of Information and Technology (OIT), and I’ve watched a specific failure compound there for two years running: Enterprise risk isn’t being managed.

An independent audit under the Federal Information Security Modernization Act (FISMA) this summer found VA’s information security program still deficient across seven separate areas. VA’s Office of Inspector General made 19 recommendations. VA didn’t concur with any of them and called the whole audit “a snapshot in time.”

I’d call that phrase a confession. An audit is supposed to be a snapshot: a clear look at one moment, so you can fix what it shows. Dismissing it as “just a snapshot” is what an organization says when it has no process for turning findings into fixes.

Look at OIT specifically, and the pattern underneath that finding is clear: Policy exists, execution doesn’t. Nobody has held the job long enough to make it happen. FISMA obligations are on the books. What’s missing is someone to make policy and practice meet, and the standing to force that meeting when they don’t.

You can see the gap in the organization chart, spelled out in a string of “actings.” VA still has no Senate-confirmed chief information officer (CIO). The administration’s third CIO nominee had his hearing in June and remains unconfirmed. The chief information security officer (CISO) seat has cycled through two acting holders in a row. VA can survive almost anything. What it can’t do is claim to be managing enterprise IT risk while the two seats most responsible for that risk have sat empty, in practice, for going on two years.

Here’s the clearest evidence that risk isn’t being managed: VA’s fiscal 2026 budget included a substantial increase in zero trust funding — real money appropriated specifically to close this gap. And yet, asked at a recent industry day how its zero trust maturity stacks up, the department’s own answer was that identity, network and application defenses are still at the lowest rung: “Initial.”

VA has the money. What is missing is a published plan mapping funding to the risks a real CISO would have prioritized, with no way for Congress or anyone else to check whether the spending is actually moving VA off that “Initial” rating. That gap, dollars with no strategic plan behind them, is a clear sign of missing leadership.

A recent VA memo clarifies that contracts can no longer require Federal Risk and Authorization Management Program (FedRAMP) certification. I concur with that, in principle. The secretary owns the risk of serving veterans; that risk gets delegated to the CIO, who leans on the CISO to identify it. Fine.

But accepting risk requires a thorough analysis, not just a decision about certification. If non-FedRAMP-ed just means a lower price with no thought about veterans, then the risk analysis is incomplete. My mantra as deputy assistant secretary for DevOps was simple: “DevOps equals empathy.” That means tracing every technical decision out to its human cost for a veteran. The Veterans Health Administration (VHA) already runs a formal enterprise risk management office for exactly this reason: treating risk as a mission-wide question, not a budget line. OIT just needs to catch up to the one sitting down the hall.

I know exactly what that gap looks like from the inside. Every fall, as OIT races to spend down its year-end funds, there’s a ritual called the unfunded requirements review, or UFR. OIT executives sign off on last-minute funding decisions for programs they may not have touched. One year I got asked to decide on wide-area network infrastructure funding. My answer was simple, until I sat down with VHA’s telehealth team and learned what actually rides on that network: real veterans, on real calls getting care. My understanding and my funding decision changed.

None of this is a new problem, and I’ve watched it fester. Two years without a confirmed CIO. Two acting CISOs in a row. A cybersecurity posture VA itself rates at the bottom rung. This pattern goes well beyond one bad audit. This is an organizational gap without ownership.

A CIO confirmation goes through the Senate, not VA. But appointing a CISO is VA’s call, and it’s the one move that fixes both problems at once: the cybersecurity gaps that FISMA identified, and the empathy gap that FedRAMP memo exposes. A resourced, permanent CISO is the person best positioned to make sure a procurement decision balances cyber risk with the risks to veterans’ services before it ever clears OIT’s door.

Appoint a CISO.

William “Bill” James is the former deputy assistant secretary for DevOps at the Department of Veterans Affairs. His debut techno-thriller, The Chariot Protocol, set in VA, publishes in September.

Copyright © 2026 Federal News Network. All rights reserved. This website is not intended for users located within the European Economic Area.

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1В Кузнецке прошел городской конкурс «А ну-ка, парни!»0021-02-2025
2☝Мамы, хотите действительно отдохнуть и не думать как накормить любимых, ...5629-06-2026
3Агидель: Ночь 20 дек, Чт0019-12-2018
4Vaccineproduktion på matematisk formel0021-09-2021
5VA’s top healthcare official is stepping down08.6201-07-2026
6Дорогие друзья! Премьера нашей песни! 0009-03-2023
7Евросоюзный суд не разрешил Латвии добычу снежного краба0007-02-2020
8Сытник связал попытку его уволить с делом Приватбанка0012-02-2020
9Собственники домов с электроотоплением станут платить меньше за электричество Правительство ...0021-02-2025
10Octopus Renewables : Notice of Results0001-01-1970

Классификация: Мнения. Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 9.32. Источник: federalnewsnetwork.com.