Back to news

August 15, 2018 | International, C4ISR

Cost Isn’t Everything. Pentagon Should Judge Contractors on Cybersecurity, Report Says

Security would be ‘fourth pillar' in weapons purchase decisions

The Pentagon should take into account the cybersecurity capabilities of defense contractors in addition to cost and performance measures when awarding contracts, a U.S. government-funded think tank recommended in a report published Monday.

Through its buying process, the Pentagon “can influence and shape the conduct of its suppliers,” the Mitre Corp. said in a report titled “Deliver Uncompromised: A Strategy for Supply Chain Security and Resilience in Response to the Changing Character of War.”

The Defense Department “can define requirements to incorporate new security measures, reward superior security measures in the source selection process, include contract terms that impose security obligations, and use contractual oversight to monitor contractor accomplishments,” the report said.

The Pentagon must consider new measures because the very nature of war is changing, the Mitre report said. Adversaries no longer have to engage the United States in direct conflict using weapons but can respond to American military strikes “through blended operations that take place through supply chain, cyber domain, and human elements,” the report noted.

The report recommends that security be made a “primary metric” in Pentagon weapons purchase and sustainment decisions and that the Defense Department increase awareness of risks associated with its supply chains. It also calls for a National Supply Chain Intelligence Center that would include officials from the FBI, Homeland Security, the Pentagon and intelligence agencies to track risks and advise agencies.

When choosing current or new contractors, in addition to considering cost, performance and schedule, the Pentagon must also make security a so-called “fourth pillar,” the report said. Contractors should be continuously monitored and assessed for the degree of risk they pose, the report said.

In addition to measuring a contractor's ongoing performance on a contract, an independent, federally-funded research agency could develop a risk rating similar to credit ratings done by agencies like Moody's, the report said. Mitre is a federally-funded research and development center.

The Pentagon did not respond to an email seeking comment on the report.

The report and its recommendations come as U.S. intelligence officials have become increasingly alarmed at potential cybersecurity risks that may be embedded in vast computer networks and systems that power government agencies as well as weapon systems. Last year the Trump administration banned federal agencies from using a popular anti-virus software made by Kaspersky Labs, which was alleged to have close ties with Russian intelligence services.

Full Article: https://www.rollcall.com/news/politics/pentagon-judge-contractors-cybersecurity

On the same subject

  • Amazon Denounces DoD JEDI ‘Do-Over’

    March 25, 2020 | International, C4ISR

    Amazon Denounces DoD JEDI ‘Do-Over’

    The Pentagon's request to reconsider narrow technical aspects of the award to Microsoft, Amazon argues, ignores a wide range of fundamental flaws. By SYDNEY J. FREEDBERG JR. WASHINGTON: Amazon Web Services has publicly denounced the Defense Department's latest legal maneuver in the months-long public battle over the JEDI cloud computing contract, awarded to Microsoft last year. No, Amazon said in a statement this morning, the Pentagon should not get to redo a particular piece of the award process the judge found flawed, because that was just one flaw among many and fixing it is a distraction from the larger issues. “We're pleased to see the DoD recognize the need to take corrective action,” the Amazon statement began, “but we're concerned that the proposed approach is not designed to provide a complete, fair, and effective re-evaluation.” “Both earlier in the adjudication process when we submitted 265 questions to the DoD that they refused to answer, and in our protest where we outlined numerous significant flaws in the evaluation, it's been clear that there were many problems with the DoD's initial decision,” the statement continues. “Instead of addressing the breadth of problems in its proposed corrective action, the DoD's proposal focuses only on providing Microsoft a ‘do-over' on its fatally flawed bid while preventing AWS from adjusting its own pricing in response to the DoD's new storage criteria.” “This attempt to gerrymander the corrective action without fixing all of the serious flaws pointed out in our complaint raises significant questions,” the statement concludes. The Pentagon's plan to consolidate many — but not all — of its 500-plus cloud contracts into a single Joint Enterprise Defense Infrastructure (JEDI). Note the suggestion that the single “pathfinder” contract for JEDI might evolve into multiple JEDI contracts. An email circulated by Amazon went further: “DoD's proposed corrective action seeks to resurrect Microsoft's award eligibility and directly and unreasonably benefits Microsoft's deficient approach. DoD's proposed corrective action does not meaningfully address the numerous errors identified in AWS's protest. These errors were pervasive, impacting all six of the technical evaluation factors” — that is, not just the one the Pentagon is asking to redo. “From the President's order to ‘screw' Amazon out of the contract, to the Secretary halting the award for an 85-day ‘examination,' to the Secretary's bizarre recusal after an award decision had been made, to the numerous inexplicable evaluation errors, to the refusal to substantively address AWS's 265 post-award debriefing questions, to the blatant political interference which impacted the award decision – the history of this procurement casts serious doubt on the rationality and fairness of DoD's proposed correction action,” the email said bluntly. Some backstory might help in parsing all this. (Click here for more detail). On Feb. 13, the court had granted Amazon a preliminary injunction, saying the company would “likely” be able to prove the Department of Defense had erred in one particular portion of its process – an evaluation of the two companies called Price Scenario 6 – when it awarded the potentially $10 billion contract to Microsoft Azure. On March 12th, DoD responded by asking the judge to “remand” the case back to DoD so it could correct and redo Price Scenario 6, giving Microsoft and Amazon the opportunity to submit updated bids – albeit with very strict limits on those updates. “During the proposed remand,” DoD's motion said, “the agency potentially could make decisions that would moot this action, in whole or in part, and may obviate the need for further litigation in this Court.” In other words, the Pentagon is asking the judge: let us fix this one thing, and then there might be nothing left for Amazon to object to, and you can dismiss the case. Today, Amazon replied: We have plenty more to object to – and we think the judge will side with us. https://breakingdefense.com/2020/03/amazon-denounces-dod-jedi-do-over

  • Businesses reposition amid growing demand for solid rocket motors

    October 31, 2023 | International, Naval, C4ISR

    Businesses reposition amid growing demand for solid rocket motors

    Companies in the rocket propulsion industry are making their own moves, reshuffling the market with potentially wide-ranging effects.

  • House defense bill would add more test F-35s as upgrades remain behind

    May 23, 2024 | International, Aerospace

    House defense bill would add more test F-35s as upgrades remain behind

    Rep. Rob Wittman has repeatedly expressed concern about delays in the F-35's upgrades and the need for more test jets.

All news