Security Industry Vies for Federal Network Monitoring Contracts

Security Industry Vies for Federal Network Monitoring Contracts
Written By
Robert Lemos
Robert Lemos
May 31, 2013
2 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

The U.S. government’s push to improve the security of its civilian, intelligence and military agencies has attracted enormous interest from the security industry, with almost two dozen teams of companies competing for a piece of a $6 billion budget over the next five years for deploying systems that will continuously monitor the security status of networks and systems.

In 2010, the U.S. Congress updated the Federal Information Security Management Act, or FISMA, requiring that federal agencies move away from annual compliance and toward monitoring their security status on a daily, or continuous, basis.

In December, the U.S. Department of Homeland Security issued a request for quote (RFQ) for companies to bid on building a subset of monitoring features, known as the continuous diagnostics and mitigation (CDM) project, that focus on discovering and managing hardware and software assets, patches and vulnerabilities. At stake is about $170 million set aside for the project in the federal budget.

“This is a must win for all these companies, because it is the first wave of what could be a $6 billion program,” said Niels Jensen, regional vice president for federal services at ForeScout Technologies, a maker of network access control (NAC) systems.

Following regular breaches of federal agency networks and less than impressive grades on the annual FISMA report card, Congress decided to put the Department of Homeland Security on notice for the move to continuous monitoring because civilian agencies were having trouble selecting and deploying appropriate solutions.

Only 22 percent of agencies had met the original FISMA deadline for deploying a continuous monitoring system within their organization by September 2011, according to a survey released by RedSeal Networks, a network monitoring and management firm. Even with the deadline extended to September 2012, only 45 percent of the federal agencies said they expected to be able to monitor key aspects of their organization’s IT security, the survey found.

The problem is that many civilian agencies do not have the budget, resources or skills to deploy the necessary technology to monitor their networks for misconfigurations, vulnerabilities and threats. Still, some agencies do not want to turn over control to another agency, such as the DHS. Yet, the administration appears to be taking a firm stance, according to ForeScout’s Jensen.

Advertisement

“Any time an organization asks for money for anything that seems related to continuous monitoring, they are pushed toward talking to the DHS,” he said.

The project comes as attacks on agencies have increased dramatically. In 2010, the Department of Homeland Security detected nearly 8,000 incidents, up from approximately 2,100 two years earlier. In addition, a far greater number of those threats were related to malware—84 percent in 2010 compared with 39 percent in 2008, according to a DHS presentation on the CDM project.

Federal agencies that deploy the technology should reduce their risk by nearly 90 percent, the DHS stated.

Robert Lemos

Robert Lemos is an award-winning journalist who has covered information security, cybercrime and technology's impact on society for almost two decades. A former research engineer, he's written for Ars Technica, CNET, eWEEK, MIT Technology Review, Threatpost and ZDNet. He won the prestigious Sigma Delta Chi award from the Society of Professional Journalists in 2003 for his coverage of the Blaster worm and its impact, and the SANS Institute's Top Cybersecurity Journalists in 2010 and 2014.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.