January 13, 2025
Everyone reading this knows that April 15 is the dreaded day that one must pay federal income taxes. Big business has hordes of tax accountants and lawyers who do tax planning to accommodate federal deadlines.
Sometimes, the deadline could be better known. Are you familiar with the OMB’s M-24-15? This will require companies to submit compliance information in a machine-readable format.
Today, we sat down with Valinder Mangat from DRTConfidence. Valinder describes technology, deadlines, and approaches your company can use to comply.
This interview will serve as a warning about an immense deadline that is crucial if you work with the federal government and cloud service providers.
"And so that is what the standard brings to the table, is the interoperability between a lot of different organizations to be able to conduct this process fast, automated, in an efficient manner. "
Valinder Mangat, DRTConfidence Tweet
Essentially, NIST recognized that compliance done manually was time-consuming and subject to error. Back in 2016, they suggested OSCAL to streamline compliance. In addition to speeding things up, OSCAL allows for reuse without repetitive assessments.
Whether you realize it or not, by the end of 2025, each federal contractor will be expected to provide compliance information in the OSCAL format, which stands for Open Security Controls Assessment Language.
The other side of the coin is important to discuss as well. If you are an agency dealing with cloud compliance, you will be expected to be able to ingest compliance data in the OSCAL format.
If you enjoyed this interview, you may want to listen to
Ep. 249 Securing Endpoints in Federal Systems Amid Constant Change
Related to federal cybersecurity and compliance, which ties well with cloud security and OSCAL frameworks.
Ep. 251 Breaking Through Bureaucracy: Modernizing Federal Systems in an era of Digital Urgency
Discusses modernization in federal systems, a good complement to innovation in federal cloud and compliance.
