Back to news

August 14, 2018 | International, Aerospace, Naval, Land, C4ISR

Pentagon is rethinking its multibillion-dollar relationship with U.S. defense contractors to boost supply chain security

By Ellen Nakashima

The Pentagon has a new goal aimed at protecting its $100 billion supply chain from foreign theft and sabotage: to base its weapons contract awards on security assessments — not just cost and performance — a move that would mark a fundamental shift in department culture.

The goal, based on a strategy called Deliver Uncompromised, comes as U.S. defense firms are increasingly vulnerable to data breaches, a risk highlighted earlier this year by China's alleged theft of sensitive information related to undersea warfare, and the Pentagon's decision last year to ban software made by the Russian firm Kaspersky Lab.

On Monday, President Trump signed into a law a provision that would bar the federal government from buying equipment from Chinese telecommunications firms Huawei and ZTE Corp., a measure spurred by lawmakers' concerns about Chinese espionage.

“The department is examining ways to designate security as a metric within the acquisition process,” Maj. Audricia Harris, a Pentagon spokeswoman, said in a statement. “Determinations [currently] are based on cost, schedule and performance. The department's goal is to elevate security to be on par with cost, schedule and performance.”

The strategy was written by Mitre Corp., a nonprofit company that runs federally funded research centers, and the firm released a copy of its reportMonday.

“The major goal is to move our suppliers, the defense industrial base and the rest of the private sector who contribute to the supply chain, beyond a posture of compliance — to owning the problem with us,” said Chris Nissen, director of asymmetric-threat response at Mitre.

Harris said the Pentagon will review Mitre's recommendations before proceeding. She added that the Department of Defense, working with Congress and industry, “is already advancing to elevate security within the supply chain.”

Testifying to Congress in June, Kari Bingen, the Pentagon's deputy undersecretary for intelligence, said: “We must have confidence that industry is delivering capabilities, technologies and weapon systems that are uncompromised by our adversaries, secure from cradle to grave.”

Security should be seen not as a “cost burden,” she told the House Armed Services Committee, “but as a major factor in their competitiveness for U.S. government business.”

The new strategy is necessary, officials say, because U.S. adversaries can degrade the military's battlefield and technological advantage by using “blended operations” — hacking and stealing valuable data, manipulating software to sabotage command and control systems or cause weapons to fail, and potentially inducing a defense firm employee to insert a faulty component or chip into a system.

“A modern aircraft may have more than 10 million lines of code,” Mitre's report said. “Combat systems of all types increasingly employ sensors, actuators and software-activated control devices.”

The term “Deliver Uncompromised” grew out of a 2010 meeting of senior counterintelligence policy officials, some of whom lamented that the Defense Department was tolerating contractors repeatedly delivering compromised capabilities to the Pentagon and the intelligence community.

Addressing the security issue requires greater participation by counterintelligence agencies, which can detect threats against defense firms, the report said, and ideally, the government should establish a National Supply Chain Intelligence Center to monitor threats and issue warnings to all government agencies.

Ultimately, the military's senior leaders bear responsibility for securing the supply chain and must be held accountable for it, the report said.

The Defense Department, although one of the world's largest equipment purchasers, cannot control all parts of the supplier base. Nonetheless, it has influence over the companies it contracts with as it is the principal source of business for thousands of companies. It can shape behavior through its contracts to enhance supply-chain security, the report said.

Legislation will be needed to provide incentives to defense and other private-sector companies to boost security, Mitre said. Congress should pass laws that shield firms from being sued if they share information about their vulnerabilities that could help protect other firms against cyberattacks; or if they are hacked by a foreign adversary despite using advanced cybersecurity technologies, the report said.

Contractors should be given incentives such as tax breaks to embrace supply chain security, the report suggested.

The Department of Homeland Security is addressing the security of the information technology supply chain through its newly established National Risk Management Center. “What we're saying is you should be looking at what vendors are doing to shore up their cybersecurity practices to protect the supply chain,” said Christopher Krebs, DHS undersecretary for the National Protection and Programs Directorate.

The National Counterintelligence and Security Center, an agency of the Office of the Director of National Intelligence that coordinates the government's counterintelligence strategy, said in a report last month that software-supply-chain infiltration has already threatened critical infrastructure and is poised to endanger other sectors. According to the NCSC, last year “represented a watershed in the reporting of software supply chain” attacks. There were “numerous events involving hackers targeting software supply chains with back doors for cyber espionage, organizational disruption or demonstrable financial impact,” the agency found.

https://www.washingtonpost.com/world/national-security/the-pentagon-is-rethinking-its-multibillion-dollar-relationship-with-us-defense-contractors-to-stress-supply-chain-security/2018/08/12/31d63a06-9a79-11e8-b60b-1c897f17e185_story.html?noredirect=on&utm_term=.265ce85b6eb1

On the same subject

  • 10 Biggest DoD Contract Awards for July 2022

    August 3, 2022 | International, Aerospace, Naval, Land, C4ISR, Security, Other Defence

    10 Biggest DoD Contract Awards for July 2022

    The 10 biggest contracts in July totaled $16,472,333,580, coming in at $10 billion less than June 2022 contracts.

  • Bell Invictus to Offer Army ‘Lower-Risk Path’ to FARA Capabilities

    December 16, 2019 | International, Aerospace

    Bell Invictus to Offer Army ‘Lower-Risk Path’ to FARA Capabilities

    By Brian Garrett-Glaser ARLINGTON, Texas — Bell's offering for the Army's Future Attack Reconnaissance Aircraft (FARA) contest, the 360 Invictus, is intended to offer the Army an insurance policy by presenting a lower-risk path to the capabilities it hopes to acquire as a “knife fighter” light attack helicopter to replace the retired OH-58 Kiowa Warriors. The Invictus, with its low-drag tandem cockpit design, draws from a lot of the development Bell has put into the 525 Relentless, a super-medium utility aircraft it hopes will be the first fly-by-wire rotorcraft certified for the civil market. Though Bell's FARA program is newer than some of its competitors, such as Sikorsky's S-97 Raider — Bell officials said the program had just three employees at this time last year and now comprises over 200 — the company believes its reliance on systems which it already has at a high technology readiness level due to work on the 525 will provide the Army with a compelling aircraft inside of its cost and timeline objectives. “It's still a very advanced aircraft. But by using technologies that we already had high TRLs in, or high manufacturing readiness levels in, we are ahead on that timeline piece,” Frank Lazzara, director of advanced vertical lift systems, told Avionics International during a press visit to the company's Flight Research Center here. The Invictus design meets or exceeds Army requirements in every area, according to Lazzara, due in part to the clean-sheet engineering that went into the Bell 525, including in the main and tail rotor systems. That aircraft has flown in excess of 200 knots without issue, despite being designed for 160 knots cruise speed. Bell intends the Invictus to cruise efficiently at 180 knots. “We flew [the 525] until we said we're done, but that rotor wasn't done,” said Josh O'Neill, senior manager for technology and evaluation on the Bell 525 program. “So we went not just 201 knots. It was a good bit more than that.” The 525 Relentless was the first aircraft Bell designed “totally in the 3D space,” O'Neill said, and the Invictus is similarly using a digital thread, enabling things like virtual reality maintaining exercises to provide design feedback without a physical product. “You have a digital thread, the same part that's used when you design your aircraft is used in the maintenance training, used throughout the product,” said O'Neill. “You design the aircraft in 3D, lay out all the systems and you're able to go in there with an actual maintainer. So we pulled [a line maintainer] and had him put the gloves on and go maintain the aircraft. And you can see in the 3D space, I need to reach around this piece, I need to turn my hand in a way that the human hand doesn't like to be turned. So we need to move that item.” As a fly-by-wire aircraft designed with a modular open systems architecture (MOSA) approach, Bell believes Invictus will provide the Army with an path to autonomy — or enable a single person in the aircraft to focus on mission functionality — similar to Bell's approach with the V-280 Valor, its offering for the Future Long-Range Assault Aircraft (FLRAA) competition. Bell officials said they are currently introducing autonomous flight software and performing software regression tests for that aircraft and intend to begin autonomous flight tests within the next few months. In March 2020, when the Army narrows the FARA competition from five companies to two, Bell's team will be nine months into design. After that, two of the five designs — selected from Sikorsky, Bell, Karem Aircraft, AVX/L3Harris, and Boeing — will be selected to participate in a fly-off slated for the second half of 2022. The Army hopes to field the first FARA aircraft in 2028. https://www.aviationtoday.com/2019/12/15/bell-invictus-offer-army-lower-risk-path-fara-capabilities/

  • Russian air defence systems destroy 41 Ukraine-launched drones -Russian defence ministry | Reuters

    December 5, 2023 | International, Aerospace

    Russian air defence systems destroy 41 Ukraine-launched drones -Russian defence ministry | Reuters

    Russian air defence systems destroyed or intercepted a total of 41 Ukraine-launched drones overnight and early morning on Tuesday, the Russian defence ministry said.

All news