Lisa Hoover 0 Junior Poster

NASA is looking for organizations to become members of its CIO Executive Board, which serves under the Corporate Executive Board. Now that's a job I can get behind.

According to the , "The membership includes unlimited accesses to proprietary council research for staff designated by the member CIO; a series of Annual Executive Retreats offering a unique opportunity for CIO's to interact with other Council principals; on site presentation of research of the most progressive IT departments; customized to the Council member's organizational requirements. "

The whole idea of IT at NASA just boggles my mind. I mean, how hard must it be to coordinate and maintain the infrastructure behind space travel, one of the most massive technological undertakings in the history of the planet?

NASA CIO Jonathan Q. Pettus told FedTech Magazine recently that security is a chief concern for his department. He says it's "particularly challenging because our mission is about creating knowledge and information, and sharing that with our partners -- with academia and with scientists, not only in this country but other countries. It’s a challenge to make the data available to those who need it, and yet ensure that we’re also protecting information that in many cases is a critical national asset -- important to the nation’s security and knowledge advancement."

Additionally, NASA is beginning to allow employees to telecommute or work remotely which adds yet another layer of technology -- BlackBerrys, notebook computers, and so on -- to support.

The job can't be an easy one, and Linda Cureton, CIO, NASA/Goddard Space Flight Center, says "a CIO needs to love her mission [and] use her knowledge of IT to its success." In fact, Cureton offers a number of useful suggestions that apply to IT departments everywhere, not just those involved in the space race.

"IT Governance establishes a process and a forum for informed decision making," says Cureton. "IT investments are made because of (a) mission alignment; (b) return on investment; and (c) ability to reduce risks. CIOs may know more about IT than someone in the mission area or the CFO, but it takes more than knowledge of IT to make the right decisions about IT on behalf of the organization."

It's easy to see how large-scale IT management principals would apply to smaller organizations, but what about the reverse? Assuming your company is a wee bit smaller than the whole space administration, what advice would you give to NASA about IT governance?

Dani AI

Generated

raised the right questions: at NASA scale governance decisions become architecture, procurement, and culture choices. Large, mission-driven organizations must make data usable for partners while limiting access to sensitive assets — a balance that GAO reviews have repeatedly said requires stronger agencywide IT oversight and risk alignment. (gao.gov)

Practical, small‑org lessons that scale:

  • Keep decision loops short. Use small governance panels with named owners, measurable SLAs, and clear RACI so centers can move without waiting for endless sign‑off.
  • Treat data and services as federated platforms with explicit data contracts, short‑lived credentials, and least‑privilege access. Move toward a Zero Trust posture and stronger identity federation so partners get what they need without broad implicit trust. (csrc.nist.gov)
  • Automate operations and security: CI/CD, infrastructure‑as‑code, automated testing, and observability let you patch, rollback, and learn fast without risky manual changes.

Procurement and engineering changes:

  • Require supplier security evidence (attestations, SBOMs, timely notifications) and contract language that enforces remediation and transparency. Bake secure development practices into acquisition requirements — the NIST SSDF and SCRM guidance are practical frameworks for this. (csrc.nist.gov)
  • Design runbooks, telemetry, and rehearsal into every mission system so operations, engineering, and security share the same playbook. Use system security engineering to build resilience rather than bolting it on later.

Quick checklist for a pilot program:

  1. map critical data flows; 2) pick one partner and pilot Zero Trust; 3) require SBOM/SSDF evidence for contractors; 4) automate security gates; 5) name data stewards and a trusted integrator; 6) measure mission outcomes, not just compliance. These steps keep governance light, practical, and mission‑enabling — exactly the kind of approach that complements the points @LisaHoover raised.
Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.