Back to news

August 15, 2018 | International, C4ISR

Cost Isn’t Everything. Pentagon Should Judge Contractors on Cybersecurity, Report Says

Security would be ‘fourth pillar' in weapons purchase decisions

The Pentagon should take into account the cybersecurity capabilities of defense contractors in addition to cost and performance measures when awarding contracts, a U.S. government-funded think tank recommended in a report published Monday.

Through its buying process, the Pentagon “can influence and shape the conduct of its suppliers,” the Mitre Corp. said in a report titled “Deliver Uncompromised: A Strategy for Supply Chain Security and Resilience in Response to the Changing Character of War.”

The Defense Department “can define requirements to incorporate new security measures, reward superior security measures in the source selection process, include contract terms that impose security obligations, and use contractual oversight to monitor contractor accomplishments,” the report said.

The Pentagon must consider new measures because the very nature of war is changing, the Mitre report said. Adversaries no longer have to engage the United States in direct conflict using weapons but can respond to American military strikes “through blended operations that take place through supply chain, cyber domain, and human elements,” the report noted.

The report recommends that security be made a “primary metric” in Pentagon weapons purchase and sustainment decisions and that the Defense Department increase awareness of risks associated with its supply chains. It also calls for a National Supply Chain Intelligence Center that would include officials from the FBI, Homeland Security, the Pentagon and intelligence agencies to track risks and advise agencies.

When choosing current or new contractors, in addition to considering cost, performance and schedule, the Pentagon must also make security a so-called “fourth pillar,” the report said. Contractors should be continuously monitored and assessed for the degree of risk they pose, the report said.

In addition to measuring a contractor's ongoing performance on a contract, an independent, federally-funded research agency could develop a risk rating similar to credit ratings done by agencies like Moody's, the report said. Mitre is a federally-funded research and development center.

The Pentagon did not respond to an email seeking comment on the report.

The report and its recommendations come as U.S. intelligence officials have become increasingly alarmed at potential cybersecurity risks that may be embedded in vast computer networks and systems that power government agencies as well as weapon systems. Last year the Trump administration banned federal agencies from using a popular anti-virus software made by Kaspersky Labs, which was alleged to have close ties with Russian intelligence services.

Full Article: https://www.rollcall.com/news/politics/pentagon-judge-contractors-cybersecurity

On the same subject

  • Garantir l’indépendance de la BITD, enjeu essentiel pour la souveraineté

    November 26, 2020 | International, Aerospace, Naval, Land, C4ISR, Security

    Garantir l’indépendance de la BITD, enjeu essentiel pour la souveraineté

    DEFENSE Garantir l'indépendance de la BITD, enjeu essentiel pour la souveraineté A l'occasion du Paris Air Forum, Françoise Dumas, Présidente de la commission de Défense nationale et des forces armées de l'Assemblée Nationale, Antoine Bouvier, Directeur de la stratégie, des fusions acquisitions et des affaires publiques chez Airbus, Thomas Courbe, Directeur général des entreprises, et François Mestre, chef du Service des Affaires industrielles et de l'Intelligence économique à la DGA, ont participé à une table-ronde consacrée aux enjeux de la préservation de la Base Industrielle et Technologique de Défense (BITD) française. L'importance de l'autonomie industrielle a été soulignée : la BITD française est la seule en Europe à être capable de répondre à tous les besoins des armées. L'État doit garantir les moyens d'assurer la course technologique et éviter la captation des entreprises ou des données par d'autres puissances. Il est également fondamental de préserver dans le pays les compétences : très longues à acquérir, elles disparaissent très rapidement, et ne peuvent plus être retrouvées, explique Françoise Dumas. Le soutien à l'apprentissage est également essentiel, et les investissements consentis par l'État, autant en R&D que par la commande publique, sont des leviers très importants, sans oublier les fonds mis à la disposition, notamment, des PME. Antoine Bouvier a souligné la grande cohérence de la filière en France, qui va des donneurs d'ordre aux PME capables de produire des composants. La Tribune du 25 novembre

  • Lockheed, IBM's Red Hat team up to speed AI development for Pentagon

    October 25, 2022 | International, Aerospace, C4ISR

    Lockheed, IBM's Red Hat team up to speed AI development for Pentagon

    The U.S. Department of Defense is increasingly interested in artificial intelligence and machine learning, both on and off the battlefield.

  • Lockheed, Rheinmetall pair up to build Europe-made rocket launcher

    June 23, 2023 | International, Land

    Lockheed, Rheinmetall pair up to build Europe-made rocket launcher

    The companies have an eye on the business of replacing the Bundeswehr's MARS 2 weapons.

All news