Back to news

August 14, 2018 | International, Aerospace, Naval, Land, C4ISR

Pentagon is rethinking its multibillion-dollar relationship with U.S. defense contractors to boost supply chain security

By Ellen Nakashima

The Pentagon has a new goal aimed at protecting its $100 billion supply chain from foreign theft and sabotage: to base its weapons contract awards on security assessments — not just cost and performance — a move that would mark a fundamental shift in department culture.

The goal, based on a strategy called Deliver Uncompromised, comes as U.S. defense firms are increasingly vulnerable to data breaches, a risk highlighted earlier this year by China's alleged theft of sensitive information related to undersea warfare, and the Pentagon's decision last year to ban software made by the Russian firm Kaspersky Lab.

On Monday, President Trump signed into a law a provision that would bar the federal government from buying equipment from Chinese telecommunications firms Huawei and ZTE Corp., a measure spurred by lawmakers' concerns about Chinese espionage.

“The department is examining ways to designate security as a metric within the acquisition process,” Maj. Audricia Harris, a Pentagon spokeswoman, said in a statement. “Determinations [currently] are based on cost, schedule and performance. The department's goal is to elevate security to be on par with cost, schedule and performance.”

The strategy was written by Mitre Corp., a nonprofit company that runs federally funded research centers, and the firm released a copy of its reportMonday.

“The major goal is to move our suppliers, the defense industrial base and the rest of the private sector who contribute to the supply chain, beyond a posture of compliance — to owning the problem with us,” said Chris Nissen, director of asymmetric-threat response at Mitre.

Harris said the Pentagon will review Mitre's recommendations before proceeding. She added that the Department of Defense, working with Congress and industry, “is already advancing to elevate security within the supply chain.”

Testifying to Congress in June, Kari Bingen, the Pentagon's deputy undersecretary for intelligence, said: “We must have confidence that industry is delivering capabilities, technologies and weapon systems that are uncompromised by our adversaries, secure from cradle to grave.”

Security should be seen not as a “cost burden,” she told the House Armed Services Committee, “but as a major factor in their competitiveness for U.S. government business.”

The new strategy is necessary, officials say, because U.S. adversaries can degrade the military's battlefield and technological advantage by using “blended operations” — hacking and stealing valuable data, manipulating software to sabotage command and control systems or cause weapons to fail, and potentially inducing a defense firm employee to insert a faulty component or chip into a system.

“A modern aircraft may have more than 10 million lines of code,” Mitre's report said. “Combat systems of all types increasingly employ sensors, actuators and software-activated control devices.”

The term “Deliver Uncompromised” grew out of a 2010 meeting of senior counterintelligence policy officials, some of whom lamented that the Defense Department was tolerating contractors repeatedly delivering compromised capabilities to the Pentagon and the intelligence community.

Addressing the security issue requires greater participation by counterintelligence agencies, which can detect threats against defense firms, the report said, and ideally, the government should establish a National Supply Chain Intelligence Center to monitor threats and issue warnings to all government agencies.

Ultimately, the military's senior leaders bear responsibility for securing the supply chain and must be held accountable for it, the report said.

The Defense Department, although one of the world's largest equipment purchasers, cannot control all parts of the supplier base. Nonetheless, it has influence over the companies it contracts with as it is the principal source of business for thousands of companies. It can shape behavior through its contracts to enhance supply-chain security, the report said.

Legislation will be needed to provide incentives to defense and other private-sector companies to boost security, Mitre said. Congress should pass laws that shield firms from being sued if they share information about their vulnerabilities that could help protect other firms against cyberattacks; or if they are hacked by a foreign adversary despite using advanced cybersecurity technologies, the report said.

Contractors should be given incentives such as tax breaks to embrace supply chain security, the report suggested.

The Department of Homeland Security is addressing the security of the information technology supply chain through its newly established National Risk Management Center. “What we're saying is you should be looking at what vendors are doing to shore up their cybersecurity practices to protect the supply chain,” said Christopher Krebs, DHS undersecretary for the National Protection and Programs Directorate.

The National Counterintelligence and Security Center, an agency of the Office of the Director of National Intelligence that coordinates the government's counterintelligence strategy, said in a report last month that software-supply-chain infiltration has already threatened critical infrastructure and is poised to endanger other sectors. According to the NCSC, last year “represented a watershed in the reporting of software supply chain” attacks. There were “numerous events involving hackers targeting software supply chains with back doors for cyber espionage, organizational disruption or demonstrable financial impact,” the agency found.

https://www.washingtonpost.com/world/national-security/the-pentagon-is-rethinking-its-multibillion-dollar-relationship-with-us-defense-contractors-to-stress-supply-chain-security/2018/08/12/31d63a06-9a79-11e8-b60b-1c897f17e185_story.html?noredirect=on&utm_term=.265ce85b6eb1

On the same subject

  • State Department OKs $6.9 billion in arms sales in one day

    November 21, 2019 | International, Aerospace, Naval, Land

    State Department OKs $6.9 billion in arms sales in one day

    By: Aaron Mehta WASHINGTON — The U.S. State Department on Wednesday cleared four potential foreign military sales packages, which combine for an estimated price tag of over $6.9 billion. The four packages, if approved by Congress, would involve AH-64E Apache helicopters for Morocco ($4.25 billion), C-130J aircraft for New Zealand ($1.4 billion), naval guns for India ($1.02 billion), and jammers for improvised explosive devices to Australia ($245 million). The notifications were posted on the website of the Defense Security Cooperation Agency. DSCA notifications are not final sales; once cleared by Congress, the sales enter negotiations, during which quantities and costs can shift. The largest package, Morocco's Apache request, is the first from that country for fiscal 2020 after dropping six FMS requests in FY19, to the tune of $7.27 billion. Read more about the Apache request here. New Zealand's request would cover five C-130J transport aircraft, manufactured by Lockheed Martin. That nation currently operates the older C-130H aircraft, so it's familiar with the airframe. “This proposed sale will provide the capability to support national, United Nations, and other coalition operations,” the DSCA notification reads. “This purchase also includes sensors and performance improvements that will assist New Zealand during extensive maritime surveillance and reconnaissance as well as improve its search and rescue capability. Additionally, the extra cargo capacity and aircraft performance will greatly increase New Zealand's Antarctic mission capabilities while simultaneously increasing safety margins.” India's request covers as many as 13 MK 45 5-inch/62-caliber (MOD 4) naval guns, along with 3,500 rounds of D349 Projectile ammunition. Those weapons will be used for “antisurface warfare and anti-air defense missions,” according to DSCA. The program will be managed by BAE Systems, with some sort of industrial offset to be arranged later. Australia, meanwhile, wants up to 850 Joint Counter Radio-Controlled Improvised Explosive Device Electronic Warfare Increment 1 Block 1 systems, or JCREW I1B1 for short. These are anti-IED jammer systems; the DSCA announcement says Australia is “interested in procuring the dismounted and mounted variants that have a modular, open architecture and are upgradeable in order to maintain capability against evolving global threats.” Those systems are produced by Northrop Grumman. The start of FY20 has been good for FMS requests. Since the fiscal year started on Oct. 1, there have been 13 requests cleared by the State Department, with a total estimated value of $13.439 billion in potential sales. The head of the DSCA, Lt. Gen. Charles Hooper, has said he hopes a series of reforms will help keep sales strong. https://www.defensenews.com/global/asia-pacific/2019/11/21/state-department-oks-69-billion-in-arms-sales-in-one-day

  • April 26, 2021 | International, Aerospace

    JUST IN: Air Force Research Lab Targets Precision, Navigation and Timing Technology

  • North Korean Hackers Deploy OtterCookie Malware in Contagious Interview Campaign

    December 29, 2024 | International, C4ISR, Security

    North Korean Hackers Deploy OtterCookie Malware in Contagious Interview Campaign

    OtterCookie, a new JavaScript malware by North Korean hackers, steals data via Socket.IO and funds nuclear programs.

All news