Since at least 2001. HSPD-12 doomed all the tiny independent .gov IT operations... PKI management at scale is too hard without dedicated staff and infrastructure.
Yep, smaller agencies lean on larger ones for PKI and other issues. Entities like FedRamp exist to provide common standards for the baby agencies who cannot perform testing, evaluation, configuration management, etc. due to small staff size.
Since at least 2001. HSPD-12 doomed all the tiny independent .gov IT operations... PKI management at scale is too hard without dedicated staff and infrastructure.
Yep, smaller agencies lean on larger ones for PKI and other issues. Entities like FedRamp exist to provide common standards for the baby agencies who cannot perform testing, evaluation, configuration management, etc. due to small staff size.