Back to news

December 19, 2018 | International, C4ISR

DoD IG: Military networks are exposed to ‘unnecessary’ cyber risks

By:

The military services are exposing networks to “unnecessary cybersecurity risks” thanks in part to a lack of visibility over software application inventories, according to a Department of Defense Inspector General report.

The IG investigated whether DoD components rationalized their software applications by identifying and eliminating any duplicative or obsolete applications. Rationalizing software applications seeks to improve enterprise IT by identifying all software applications on the network; determining if existing applications are needed, duplicative or obsolete; and determining if applications already existing within the network prior to purchasing new ones.

The audit — which focused on Marine Corps, Navy and Air Force commands and divisions — found that the groups examined did not consistently perform this rationalization process. By not having visibility into software application inventories, these organizations were unable to identify the extent of existing vulnerabilities within their applications, the report found.

Moreover, such a process could lead to cost savings associated with eliminating duplicative and obsolete applications.

Fleet Forces Command was the only command the IG reviewed that had a process in place for eliminating duplicative or obsolete applications. The Air Force did not have a process in place to prevent duplication when purchasing new applications.

The report placed blame on the DoD chief information officer for not implementing a solution for software rationalization in response to Federal Information Technology Acquisition Reform Act requirements.

The IG made three recommendations for the CIO, who did not provide a response to draft recommendations:

  • Develop an enterprisewide process for conduction software application rationalization throughout DoD;
  • Establish guidance requiring DoD components to conduct rationalization and require DoD component CIOs to develop implementation guidance outlining responsibilities for rationalization. Such a policy should also require components on at least an annual basis to validate the accuracy of their owned and in use software applications inventory; and
  • Conduct periodic review to ensure components are regularly validating the accuracy of their inventory and they are eliminating duplicative and obsolete applications.

https://www.fifthdomain.com/dod/2018/12/18/dod-ig-military-networks-are-exposed-to-unnecessary-cyber-risks

On the same subject

  • Snowbirds, CF-18 Demo Team wrap up spring training - Skies Mag

    May 27, 2024 | International, Aerospace

    Snowbirds, CF-18 Demo Team wrap up spring training - Skies Mag

    Both the CF Snowbirds and CF-18 Demonstration Team are moving ahead with celebrating the Royal Canadian Air Force’s 100th anniversary in Canada and beyond.

  • Northrop looks to adapt electronic attack system for smaller ships

    January 11, 2022 | International, Naval

    Northrop looks to adapt electronic attack system for smaller ships

    Northrop Grumman is looking to adapt its SEWIP Block 3 capability built for Arleigh Burke-class destroyers to smaller ship types.

  • U.S. Marine Corps awards BAE Systems team a contract to develop ACV family of vehicles

    June 26, 2019 | International, Land

    U.S. Marine Corps awards BAE Systems team a contract to develop ACV family of vehicles

    BAE Systems, along with teammate Iveco Defence Vehicles, has been awarded a $67 million contract modification by the U.S. Marine Corps to develop new variants for the Amphibious Combat Vehicle (ACV) Family of Vehicles program for enhancing battlefield situational awareness and firepower. “The ACV has proven to be a versatile platform capable of numerous configurations to meet current and future mission requirements,” said John Swift, director of amphibious programs at BAE Systems. “With this award, BAE Systems will be able to develop a family of vehicles that will deliver the technology and capability the Marines require to accomplish their mission in support of our national security.” The contract calls for the design and development of the command (ACV-C) and the 30mm medium caliber cannon (ACV-30) variants. The ACV-C incorporates seven work stations to provide situational awareness and control of the battle space. The ACV-30 integrates a 30mm cannon to provide the lethality and protection the Marines need while leaving ample room for troop capacity and payload. BAE Systems was previously awarded a low-rate initial production contract in June 2018 for the personnel variant (ACV-P). The Marine Corps announced the ACV had successfully completed anticipated requirements testing and would no longer be pursuing an envisioned incremental ACV 1.1 and ACV 1.2 development approach. The program is now known as the ACV Family of Vehicles, which encompasses the breadth and depth of the vehicle's capabilities and multiple variants. BAE Systems has a long legacy of designing and building amphibious vehicles and is a leading provider of combat vehicles, having produced more than 100,000 systems for customers worldwide. Iveco Defence Vehicles brings additional proven experience, having designed and built more than 30,000 multi-purpose, protected, and armored military vehicles in service today. The development of the ACV variants will take place in Stafford, Virginia; San Jose, California; Sterling Heights, Michigan; Aiken, South Carolina; and York, Pennsylvania. https://www.baesystems.com/en/article/us-marine-corps-awards-bae-systems-team-a-contract-to-develop-acv-family-of-vehicles

All news