Why Government is distinct
OMB M-22-09 (Jan 2022) mandated phishing-resistant MFA across the federal workforce. FedRAMP authorization is the price of admission for any cloud vendor serving federal customers. CMMC Level 2 cascades these expectations into the Defense Industrial Base supply chain.
Regulators
- OMB (Office of Management and Budget)
- CISA (Cybersecurity & Infrastructure Security Agency)
- GAO + agency Inspectors General
- FedRAMP PMO
- DoD (CMMC for defense supply chain)
Industry-specific challenges
The IAM challenges that recur in Government.
- Phishing-resistant MFA mandates apply to all access paths
- PIV / CBA across legacy infrastructure
- FedRAMP authorization for every cloud service
- Multi-agency federation requirements
- CISA Emergency Directives interrupt planned roadmaps
- Supply-chain identity flow-down to contractors
The canonical Government resources
Everything we’ve published, organized by topic.
Compliance + audit
Architecture + reference
Incident + risk tracking
Sector-relevant insights
Government IAM engagement