Even in early draft form, a document like this that has the power to transform Government must address security at a fundamental level. If security is left to be bolted on by individual agency procurements, we'll end up increasing risks and costs.
There should be some high level direction that the introduction of mobile must not increase the risks, and that a common set of standards (not products) across broad groups must be used. This direction would be used to provide for security depth (i.e. encryption, mdm, meap, tcb) at the core of the dialogue.
That would be inline with the CloudFirst and BYOD efforts underway in agencies across the board, and make it easier to implement agency procurements in a safe and efficient manner.