FedRAMP & AI: A Re-envisioning
- Industry technology experts suggest that the Federal Risk and Authorization management Program (FedRAMP) requires a fresh perspective in the era of artificial intelligence.
- During a Leadership Connect webinar on Thursday, tushar Rathod, CEO of Vedic Professional Services, emphasized that security authorizations are evolving.
- This discussion follows the Trump management's decision in January not to renew expiring contracts for approximately 80 private-sector professionals involved in FedRAMP.
Table of Contents
Industry technology experts suggest that the Federal Risk and Authorization management Program (FedRAMP) requires a fresh perspective in the era of artificial intelligence.
The Need for Continuous Assessment
During a Leadership Connect webinar on Thursday, tushar Rathod, CEO of Vedic Professional Services, emphasized that security authorizations are evolving. They are no longer “one-time things” but instead involve step-by-step assessments at multiple levels, demanding continuous remediation.
FedRAMP’s Diminished Workforce
This discussion follows the Trump management’s decision in January not to renew expiring contracts for approximately 80 private-sector professionals involved in FedRAMP. MeriTalk initially reported this decision. The program, wich evaluates the security of cloud services, has authorized 379 offerings for agencies’ use.however, its effectiveness may decrease without efforts to replace the reduced workforce.
“FedRAMP itself should be a highly intelligent technology platform and not a bunch of forms and people evaluating those things,”
Tushar Rathod, CEO of Vedic Professional Services
Government’s Evolving Concept of AI
Sam Navarro, strategic account executive for health IT at Microsoft, noted that agencies’ primary challenge with AI has been applying industry use cases to their specific missions and incorporating them into readily adopted contracts.
Fortunately, the government’s understanding of AI has matured. It’s shifting from simply using large language models to viewing AI as a comprehensive capability where an LLM is just one component. According to Navarro, formerly director of client experiences at Technology Transformation Services, this shift enables agencies to better understand their cybersecurity, compliance, and pricing needs and compare them with vendor proposals.
Agencies might find that automation or analytics tools lacking AI are sufficient, depending on the specific use case. Though, when AI is preferred, agencies with legacy technologies should introduce it gradually to avoid suboptimization, according to Daniel Chenok, executive director of the IBM Center for The Business of Government.
The 2024 Federal Agency AI Use Case Inventory, released in December, lists 2,133 use cases across civilian agencies. Rathod suggested that the reasons for this relatively low number include data readiness, AI skills and tools, and the maturity of both the public and private sectors.
Despite these challenges, agencies’ progress in adopting AI is expected to improve in the coming months due to the rapid evolution of AI technology.
Starting Small with AI: Cloud Solutions
Rathod advises that agencies should not purchase AI based on fear of missing out. Thoughtful implementation and organizational readiness are crucial.
Agencies should start with a small AI use case to assess its effectiveness. Cloud solutions are frequently enough a good starting point as many now include AI tools like Microsoft’s Data Assistant. Navarro suggests that this tool, which curates system data within an enclave, can be more cost-effective than deploying a chatbot.
“The beauty of a simple use case like that is the simplicity offers the ability to scale, and onc you create that scalability, that becomes somewhat of a template — becomes a great story to tell,”
Tushar Rathod, CEO of Vedic Professional Services
He added, “It’s something that people can rally behind.”
chenok, who previously served as branch chief of the Office of Management and Budget, emphasizes that agencies must verify that AI vendors have robust cyber platforms, comprehensive data management policies, and ethics programs to ensure privacy protection, transparency, and explainability.
Canada’s approach of creating a blanket purchase agreement that assesses AI companies’ security strategies, data protection, and ethics profiles could serve as a model for the U.S.
Building a “Second Team” of AI Experts
AI technical expertise is scarce within the government. However, private sector and academic experts can provide valuable advice to agencies grappling with AI challenges. Navarro recommends consulting multiple AI vendors to obtain an objective perspective.
“In times of austerity like we’re seeing today, it’s very important for agencies to build what I call your second team,”
Sam Navarro, strategic account executive for health IT at Microsoft
Navarro added, “It’s your ability to reach into a group of experts and get an unbiased opinion on how to move forward with a capability or solution you’re thinking of.”
the integration of Artificial Intelligence (AI) into government operations is prompting a re-evaluation of existing security authorization frameworks, particularly FedRAMP. This Q&A guide addresses key considerations for agencies navigating this intersection.
What is FedRAMP and why is it vital?
FedRAMP stands for the Federal Risk and Authorization Management Program. It’s a government-wide program that provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services. this ensures that federal data is protected when agencies utilize cloud-based solutions.
Why is FedRAMP being re-evaluated in the age of AI?
Industry experts believe that FedRAMP needs a fresh viewpoint due to the unique challenges and evolving nature of AI.
Continuous Assessment: Security authorizations are no longer one-time events but require ongoing, step-by-step assessments with continuous remediation.
Evolving AI Landscape: The government’s understanding of AI is maturing, shifting from simple LLM (Large Language Model) usage to viewing AI as a complete capability.
What is meant by continuous assessment in the context of FedRAMP and AI?
Continuous assessment means that security authorizations should not be viewed as a one-time event.Instead, they should involve:
Step-by-step evaluations
Multiple levels of scrutiny
Ongoing remediation efforts to address vulnerabilities.
How is the government’s understanding of AI evolving?
The government’s perspective on AI is shifting from viewing it as solely large language models (LLMs) to recognizing it as a comprehensive capability.Key aspects of this evolution include:
Understanding AI as more than just LLMs, but and comprehensive capability.
A better understanding of cybersecurity, compliance, and pricing needs.
Improved ability to compare these needs with vendor proposals.
Sam Navarro, strategic account executive for health IT at Microsoft, highlights the primary
