『The GIST of Govt IT』のカバーアート

The GIST of Govt IT

The GIST of Govt IT

著者: Swish
無料で聴く

【Amazonプライム会員限定】今ならプレミアムプランが4か月 月額99円。

10月19日まで。※適用条件あり

The weekly show that breaks down ideas, innovations and decisions that cut through complexity and offer real insights from the intersection of technology and the mission.

© 2026 The GIST of Govt IT
マネジメント マネジメント・リーダーシップ 政治・政府 政治学 経済学
エピソード
  • Security Compliance Checklists vs. Commander's Intent
    2026/09/14

    The government is great at security governance — but that isn't the same as being secure. In Episode 18 of The GIST of Govt IT, Brian and Sean sit down with Ian Kelly of Cloudflare, a self-described liberal arts major turned 15-year Google veteran turned public-sector technologist, to talk about closing the gap between the checkbox and the outcome. The conversation digs into why the exploit window has collapsed from weeks to roughly five minutes, the pivot from point-in-time compliance to continuous, risk-based security, and AI governance before the horse leaves the barn. Sean and Ian also get into edge compute, the CBP conversational video bot built for the FIFA games, infrastructure as code for repeatable accreditation, and the emerging discipline of AEO — optimizing content so agents, not just humans, can use it. Plus, Cloudflare's FedRAMP High authorization and IL4 intentions, a wall of lava lamps as a cryptographic entropy source, and three Monday-morning takeaways, not to mention KatEye makes an appearance.


    Resources Mentioned in This Episode

    Featured Guest

    • Ian Kelly, Senior Director of Solutions Engineering, Cloudflare Public Sector

    • Cloudflare Public Sector

    • Cloudflare FedRAMP High authorization announcement

    Cloudflare Capabilities Discussed

    • Cloudflare Edge Compute

    • Cloudflare AI Gateway (visibility, governance, cost control)

    • Cloudflare SASE / Zero Trust

    • Cloudflare's LavaRand entropy wall (true randomness)

    Compliance, Standards & Frameworks

    • FIPS 140-3 validated cryptography

    • FIPS 203 and NIST post-quantum cryptography

    Also Mentioned

    • KATSEYE

    • Military Grade Metal Podcast

    Related Content

    • GIST360 Webinar: Rethinking Command and Control Resiliency at the Edge

    The Hosts & Show

    • Swish

    • GIST 360

    CONNECT WITH US

    Got an idea for a future episode? Want to be a guest? Let us know.

    Brian Lake - blake@swishdata.com

    Sean Applegate - sapplegate@swishdata.com

    Subscribe wherever you get your podcasts: Apple Podcasts, Spotify, or gist360.com.


    続きを読む 一部表示
    46 分
  • The LRA is Here and the Clock is Ticking!
    2026/08/31

    It's here. On August 20, CISA dropped the Logging Reference Architecture (LRA) a practitioner's guide that operationalizes OMB M-26-14 and the countdown just got real. In this episode of The GIST of Govt IT, Brian and Sean break down the aggressive timeline it sets: agencies have 90 days to inventory their environment and submit a plan in Cyberscope (the week before Thanksgiving), then about 30 more to hit Baseline 1 maturity (the week before Christmas). Surprisingly, or not, Sean's read is refreshingly positive, this guide was written by practitioners for practitioners, with concrete advice, outcome-focused questions to ask your teams, and clear thresholds: 70% of assets inventoried, 50% logging coverage, 50% actionable alerts, six-month retention.

    The conversation digs into why IoT and OT are the hard part (segmented networks, third-party-managed devices, systems you can't actively scan), why the LRA deliberately doesn't mandate AI, and a practical path forward: assign a single LRA owner, reconcile your CMDB against your property book, deploy passive OT listening kits rather than scanning fragile systems, and use end-of-fiscal-year funds now to close gaps you can't fill over the holidays. The clock is ticking and agencies are going to have to build the airplane while they fly.


    Resources Mentioned in This Episode

    The Core Documents

    • CISA Logging Reference Architecture (LRA), released August 20

    • OMB M-26-14 (the logging mandate the LRA operationalizes)

    • CyberScope (where agencies submit their plans)

    The Baseline 1 Thresholds

    • Inventory visibility: 70% of assets captured in a centralized inventory

    • Collection coverage: 50% of inventoried assets logging

    • Collection operations: 50% of logs producing actionable alerts

    • Data retention: minimum six months (per M-26-14; the LRA guide notes a slightly different figure)

    • Timeline: plan ~Nov 18, Baseline 1 ~mid-December

    Frameworks & Technical References

    • MITRE ATT&CK (adversary behavior models)

    • CISA Zero Trust Maturity Model

    • NIST SP 800-92 (log management guidance)

    The Threat Backdrop

    • DOJ/FBI seizure of Chinese state-sponsored hacking infrastructure (August 26)

    • CISA advisory on edge-device compromise and lateral movement

    • Anthropic and OpenAI on the narrowing window to defend against AI cyber threats

    From Swish / GIST 360

    • Swish LRA planning assessmen

    • “When the Perimeter Disappears” breakfast briefing recap

    Related Episodes

    • Episode 13: Fed Christmas in July? The OMB M-26-14 Holiday Rush Begins!

    • Episode 15: Billion Dollar Pilots and Boil Water Notices: Securing OT Environments

    • Episode 7: Iran Came for the Dams and We Got Lucky: Frontline Insights into the OT Fight

    The Hosts & Show

    • Swish

    • GIST 360

    CONNECT WITH US

    Got an idea for a future episode? Want to be a guest? Let us know.

    Brian Lake - blake@swishdata.com

    Sean Applegate - sapplegate@swishdata.com

    Subscribe wherever you get your podcasts: Apple Podcasts, Spotify, or gist360.com.


    続きを読む 一部表示
    33 分
  • Federal AI Wants to Fly but Data Weighs it Down
    2026/08/24

    Somewhere between 60% and 80% of federal AI projects have stalled out and the common denominator almost always traces back to the data. In Episode 16 of The GIST of Govt IT, Brian and Sean sit down with Matt Lawson, Director of Solution Engineering for NetApp Federal, to unpack what it actually takes to build a data foundation that lets AI succeed. Matt's thesis is that projects keep stalling because teams can't get the right data, in the right place, at the right cost.

    The conversation digs into data gravity (you can't move petabytes overnight, and you can't beat the speed of light), the take-the-data-to-the-model vs. bring-the-model-to-the-data debate (answer: you need both), and the copy-of-a-copy sprawl that quietly wrecks both budgets and data authority. Matt walks through ideas that change the math, and the guys close out on post-quantum cryptography and why “harvest now, decrypt later” makes it a today problem, not a tomorrow problem. Plus Matt on why he always chooses the blue pill.

    Featured Guest

    • Matt Lawson, Director of Solution Engineering, NetApp Federal

    • NetApp Public Sector

    The “Why AI Projects Fail” Data

    • The concept of data gravity

    AI, RAG & Partners

    • Retrieval-Augmented Generation (RAG) explained

    • Apache Kafka (real-time event streaming)

    Post-Quantum Cryptography

    • NIST Post-Quantum Cryptography Standards (FIPS 203/204/205)

    • OMB M-23-02 (migrating to post-quantum cryptography)

    The Monday-Morning Playbook (Matt Lawson)

    • 1. Catalog your data — know what data sets you actually have

    • 2. Plan for a federated environment — data will live in many places, some not even yours

    • 3. Design for security from day one — immutability, ransomware recovery, and PQC can't be bolted on later

    Related Episodes

    • Episode 9: Quad Charts Be Damned: Data Meets the Mission

    Upcoming Event

    • GIST 360 Breakfast Briefing with NetApp — Washington, DC, November 10

    The Hosts & Show

    • Swish

    • GIST 360 Program

    CONNECT WITH US

    Got an idea for a future episode? Want to be a guest? Let us know.

    Brian Lake - blake@swishdata.com

    Sean Applegate - sapplegate@swishdata.com

    Subscribe wherever you get your podcasts: Apple Podcasts, Spotify, or gist360.com.


    続きを読む 一部表示
    43 分
adbl_web_anon_alc_button_suppression_t1
まだレビューはありません