CMS CISO pulls third-party data in-house, layers continuous scans
The ATO isn't going anywhere, but continuous scanning, bug bounties, and the data pullback give the agency's security posture operational teeth.
TL;DR
CMS CISO Keith Busby told Federal News Network the agency is layering continuous attack surface management, external bug-bounty researchers, and automated monitoring atop its existing authorization framework. The shift affects roughly 6,000 federal employees and thousands of contractors who access CMS systems and data. Busby said the agency is pulling third-party data access back in-house ("come to us to do it") rather than letting sensitive data leave environments CMS controls.
CMS isn't dropping its authority to operate. But in a Federal News Network interview, CISO Keith Busby described a security posture that layers continuous attack surface scanning and CISA bug-bounty researchers onto the agency's existing authorization framework, with automated reactions triggered by visibility data rather than manual triage. Busby calls the goal "inherently compliant," where system teams skip checkbox activities because continuous monitoring keeps them inside the guardrails.
The most concrete shift is the data-minimization posture toward third parties. "Our data should not leave our environments," Busby said, describing a deliberate pullback of data and functions from contractor networks onto CMS-controlled infrastructure. That's a material change for the thousands of contractors that support the agency.
FISMA isn't going anywhere. Neither are ATOs. What Busby is describing is operational layering atop a compliance framework that remains statutory. The third-party data pullback gives the shift teeth regardless of whether "beyond compliance" sticks as a label.
Published ·Deep Fathom