Back to news

June 25, 2020 | International, C4ISR, Security

Senate wants better threat sharing between Pentagon and industry

The Department of Defense would be required to establish a threat intelligence sharing program with the defense industrial base under the Senate Armed Services Committee's version of the annual defense policy bill.

The committee's version of the fiscal 2021 National Defense Authorization Act, released June 23, also includes other several other provisions designed to give the department increased insight into the cyber hygiene of its contractors.

For example, the legislation would direct the Secretary of Defense to establish a threat intelligence program “to share threat intelligence with, and obtain threat intelligence from, the defense industrial base.” This program would be required to include a mechanism for developing shared and real-time insight into the threat environment, as well as a “joint, collaborative, and co-located analytics.”

The program would also direct the DoD to invest in technology to advance automated threat detection and analysis capabilities for defense contractors.

The program proposed in the Senate NDAA stems from a similar recommendation made by the Cyberspace Solarium Commission's final report, a congressionally mandated document that suggested a comprehensive overhaul of U.S. cyber strategy. That group recommended the DoD force contractors to participate in a threat intelligence sharing program.

“The program's ideal end state is to leverage U.S. government intelligence collection to create a better understanding of adversaries' intelligence collection requirements,” the report read. “This action would help DoD and the intelligence community anticipate where adversaries will seek to collect against DIB targets, and then communicate that information to DIB network owners and operators so that they can proactively defend against impending adversary activities.”

Under the Senate bill, participation in the program would be based on cybersecurity levels assigned to contractors under the Pentagon's Cybersecurity Maturity Model Certification initiative, a new program pushing new cybersecurity requirements on contractors. To increase the participation in the program, the DoD would also have to “prioritize” available funding and support to help affect organizations participate.

The department would be required to produce a report on the program by March 2022.

The Senate bill also included language that would direct the DoD's principal cyber adviser to develop a plan to deploy commercial-off-the-shelf sensors to DIB networks to monitor the cybersecurity of their public-facing websites by February 2021. In addition, the bill directs the department to assess the feasibility of threat hunting on DIB networks by December 2021.

https://www.c4isrnet.com/cyber/2020/06/24/senate-wants-better-threat-sharing-between-pentagon-and-industry/

On the same subject

  • Pentagon re-awards multibillion-dollar office tools contract to CSRA

    November 2, 2020 | International, C4ISR

    Pentagon re-awards multibillion-dollar office tools contract to CSRA

    Andrew Eversden WASHINGTON ― The Pentagon re-awarded its Defense Enterprise Office Solutions contract to CSRA on Friday, nearly 14 months after it awarded it to the General Dynamics Information Technology subsidiary last year. The award to CSRA was delayed several times after the General Services Administration twice took corrective action after protests by Perspecta, the other contractor in the competition. According to the announcement from the General Services Administration and Department of Defense, the blanket purchasing agreement is estimated to be worth $4.4 billion over a decade, with a five-year base. The contract was estimated to be worth $7.6 billion when the award was made last year. The DEOS contract will provide the DoD with productivity tools such as word processing and spreadsheets, email, collaboration, file sharing, and storage across the enterprise. “DEOS is a key part of the Department's Digital Modernization Strategy and its fit-for-purpose cloud offering will streamline our use of cloud email and collaborative tools while enhancing cybersecurity and information sharing based on standardized needs and market offerings,” DoD Chief Information Officer Dana Deasy said in a statement. “The last six months have put enormous pressure on the Department to move faster with cloud adoption. All across the Department there are demand signals for enterprise wide collaboration and ubiquitous access to information.” The DEOS environment is intended to meet DoD Impact Level 5 and Impact Level 6 cloud security standards that allow access to unclassified and classified work, respectively. "“We were determined that the Department could achieve faster department-wide adoption of cloud collaboration capabilities by moving forward in a federated manner to the DoD 365 (IL 5) cloud environment while ensuring the individual components efforts work together to create an enterprise capability,” Deasy added. “This approach required the government team to assume a greater responsibility up front to shape the enterprise standards. With the award of DEOS, the Department will be able to transfer a significant part of the ongoing technical and management load to the integrator and free up strained resources to execute other priority missions.” The DEOS contract award was marred by several errors, detailed by NextGov, including issues with the statement of work, requirements and a subsequent incident in which proprietary information about Perspecta's bid was shared with GDIT. CSRA is partnered with Dell Marketing and Minburn Technology Group for the DEOS contract. DoD components have waited a long time for delivery of the DEOS solution. When the original award was made last year, the Marine Corps deputy director of command, control, communications and computers, Kenneth Bible, said the service was looking forward to the “promise and substantial benefits” of DEOS capabilities in “disconnected, degraded, intermittent and low bandwidth [DDIL] environments that are anticipated in 21st century conflicts.” The DEOS re-award comes nearly two months after the department confirmed its other long-delayed enterprise cloud, the Joint Enterprise Defense Infrastructure, to its original winner, Microsoft. That contract has a $10 billion ceiling. https://www.c4isrnet.com/it-networks/2020/10/30/pentagon-re-awards-multibillion-dollar-office-tools-contract-to-csra/

  • None

    March 5, 2021 | International, Aerospace, Naval, Land, C4ISR, Security

    None

  • New bill would establish AUKUS submarine training program

    June 17, 2022 | International, Naval

    New bill would establish AUKUS submarine training program

    A new training program would enroll young Australian naval officers in U.S. nuclear propulsion and submarine officer schoolhouses, and then send them to sea on a U.S. boat, ahead of Australia developing and fielding its own nuclear-powered sub.

All news