28 mai 2024 | International, Sécurité

4-Step Approach to Mapping and Securing Your Organization's Most Critical Assets

Not all technology assets are created equal. Identifying business-critical assets is essential for effective cybersecurity governance.

https://thehackernews.com/2024/05/4-step-approach-to-mapping-and-securing.html

Sur le même sujet

  • For the Navy’s hospital ships, networking is yet another challenge

    22 avril 2020 | International, Naval, C4ISR

    For the Navy’s hospital ships, networking is yet another challenge

    Andrew Eversden When the Navy hospital ship Comfort deployed to Haiti in 2010 following devastating earthquakes, media organizations broadcasting in the area ate up so much satellite bandwidth that the ship had to revert to paper processes and adjust its satellite communications for some ship-to-shore messaging. While the outages weren't a widespread issue, said Sean Kelley, who served as the ship's top IT officer at the time, the problem highlighted a challenge these ships face: broadband. Now, the hospital ships Mercy and Comfort are deployed to Los Angeles and New York, respectively, and are in the national spotlight as symbols of the coronavirus pandemic relief effort. But security and IT experts say the ships' mission presents the Navy with distinct networking problems, from cybersecurity to network connection for patients. Onboard devices When disaster strikes, the Navy's hospital ships deploy in a matter of days, mobilizing with a crew of about 100-1,200 personnel. But the influx of staff also leads to an incursion of devices, all of which must be secure and require bandwidth. “You have a lot of different people going to a lot of different places that now have to be acclimated to this environment,” said Kelley, now executive vice president at Unissant, an IT and cybersecurity company. “So that's really one of the biggest challenges, is getting all those things turned on, all those things activated, making sure that they are all compliant with the latest patches and fixes, and making sure they're good.” This process can be a “nightmare,” said retired Rear Adm. Danelle Barrett, former deputy chief information officer of the Navy and cybersecurity division director. “The challenging part is always in the first couple days whenever this happens,” said Barrett, who oversaw communications and cyberspace for Operation Unified Response, the U.S. military's mission in Haiti following the 2010 earthquake. “The team is coalescing about how they want to operate, and they're getting their feet wet, getting new accounts on networks ... [getting] their logins.” Cybersecurity aboard the ships is also complex. Both ships have 1,000 beds, 12 operating rooms, blood banks, labs, medical devices and a multitude of other “internet of things” devices connected to hospital beds. According to a 2018 survey by health care IoT security company Zingbox, each bed can have as many as 10-15 IoT devices. “They have to be cyber-ready, or the mission of the Mercy is considered [degraded],” said Dean Hullings, global defense solutions strategist at Forescout, which handles Comply to Connect — a Defense Department framework created to ensure the cybersecurity of new devices — for the USNS Mercy. Ensuring connectivity For the devices to function, they need connectivity. When the ships arrived in ports in late March, technology firm CenturyLink “donated” connectivity to the Mercy, while Verizon provided connectivity to the Comfort. Former and current Navy officials told C4ISRNET that adequate broadband is the most challenging IT consideration faced by these ships. “Obviously you're going to be transferring imagery of X-rays or things like that that are more dense and require a ... higher data rate, so that bandwidth in port is important,” Barrett said. And with the introduction of patients, bandwidth needs become more complex. “The greatest communications challenge we are going to face during this deployment is the increased need for patients to communicate off the ship during their stay,” Tom Van Leunen, a spokesman for Military Sealift Command, told C4ISRNET. “Our hospital ships are designed to support official communication for the ship's crew and embarked medical community to complete their job. Adding a capability for patients to reach loved ones increases the risk of saturating the bandwidth off the ship.” Aboard both ships, the Navy doubled the bandwidth, he said, adding that Navy personnel also set up separate networks for patients' communications. While this solves one networking problem, it can also create an increased cybersecurity risk. Securing the ships Cybersecurity on the hospital ships follows the same standard practices as the rest of the Navy fleet. Since those aboard are largely Navy medical staff and personnel, they know what activities are acceptable on the network, Barrett said. “You can't just go and plug anything into that network because of potential vulnerabilities that that system may bring that could affect not just the ship, but remember, the ship is then connected to the rest of the [Department of Defense Information Network],” Barrett said. “So risk by one is shared by all.” ForeScout's Hullings said a hospital environment “epitomizes” why the Comply to Connect program is necessary. The ship has desktops, servers, routers, printers and other networks equipment, as well as mobile devices, such as tablets, that health care providers use to track patient care. “The truly unique stuff is the mission systems of the hospital, like X-ray machines, MRI machines, the beds themselves in the post-operative recovery rooms, that are all sensors. And they are all passing data. They have to be protected,” Hullings said. A spokesperson for the Navy told C4ISRNET that the ships are prepared for the cybersecurity challenges associated with their missions, but declined to address what additional cybersecurity challenges are introduced with the addition of private citizens. “These ships have routinely deployed in humanitarian assistance missions such as Pacific Partnership (USNS Mercy) and Continuing Promise (USNS Comfort) that required them to operate in partner nation ports, with foreign national patients being brought to and from the ship,” said Cmdr. Dave Benham, a spokesman for the Navy's 10th Fleet. “In all operating locations, we take appropriate precautions to keep our networks secure, and we do not discuss specific measures in order to protect operational security.” Cybersecurity on the hospital ships follow the same protocols as any other Military Sealift Command ship, said Benham. “Protecting our networks is a continuous challenge, and the overarching concern is to ensure that the right information gets to the right place at the right time with the right level of protection,” he explained. Cybersecurity aboard the hospital ships follow similar efforts to those recommendations made by the Centers for Disease Control and Prevention: Wash your hands. “It's ‘wash your hands' with your computer, too,” Barrett said. “Do good hygiene with your computer.” https://www.c4isrnet.com/it-networks/2020/04/21/for-the-navys-hospital-ships-networking-is-yet-another-challenge/

  • Contract Awards by US Department of Defense - August 9, 2019

    12 août 2019 | International, Aérospatial, Naval, Terrestre, C4ISR, Sécurité

    Contract Awards by US Department of Defense - August 9, 2019

    NAVY Lockheed Martin Corp., Moorestown, New Jersey, is awarded a $176,339,634 firm-fixed-priced, performance-based logistics contract for the repair of 1,672 different head-of-family part numbers in support of the AEGIS SPY-1 Weapon System. The contract is a five-year contract with no option periods. Work will be performed in Moorestown, New Jersey, and is expected to be completed by August 2024. No funds are obligated at the time of award. Working capital funds (Navy) will be obligated as individual task orders are issued and funds will not expire at the end of the current fiscal year. One company was solicited for this sole-source, non-competitive requirement pursuant to the authority set forth in 10 U.S. Code 2304(c)(1) and in accordance with Federal Acquisition Regulation 6.302-1, with one offer received. Naval Supply Systems Command, Weapon Systems Support, Philadelphia, Pennsylvania, is the contracting activity (N00383-19-D-VM01). Raytheon Co., Goleta, California, is awarded $29,790,677 for modification PZ0001 to a previously awarded firm-fixed-price contract (N00019-18-C-1055). This modification provides for Lot 14 full-rate production of 82 F/A18 CD-108B/ALE-50(V) Control, Dispenser, Decoy, Countermeasures Integrated Multi-platform Launch Controllers. Work will be performed in Forrest, Mississippi (45%); Andover, Massachusetts (25%); Goleta, California (20%); and various locations within the continental U.S. (10%), and is expected to be completed in February 2022. Fiscal 2017 and 2019 aircraft procurement (Navy) funds in the amount of $29,790,677 will be obligated at time of award, $26,850,000 of which will expire at the end of the current fiscal year. The Naval Air Systems Command, Patuxent River, Maryland, is the contracting activity. Swift River Versar JV,* Anchorage, Alaska, is awarded a maximum amount $18,000,000 firm-fixed-price, indefinite-delivery/indefinite-quantity contract for mission sustainment and coastal resilience and related environmental planning services. The work to be performed provides for professional services that will support the study and implementation of mission sustainment and coastal readiness measures, including hardened structures and green infrastructure, which will ensure Navy and Marine Corps readiness of installations, ranges and operation areas. This contract will support environmental, asset management and expeditionary support services that will assist Department of Navy and Department of Defense commands in ensuring mission sustainability. All work on this contract will be performed at various Navy and Marine Corps facilities and other government facilities within the Naval Facilities Engineering Command Atlantic area of responsibility including, but not limited to Virginia (28%); North Carolina (22%); South Carolina (22%); Connecticut (7%); Florida (7%); Maine (7%); and Maryland (7%). The term of the contract is not to exceed 60 months with an expected completion date of August 2024. Fiscal 2019 operations and maintenance (Navy) contract funds in the amount of $5,000 are obligated on this award and will expire at the end of the current fiscal year. No task orders are being issued at this time. Future task orders will be primarily funded by operation and maintenance (Navy). This contract was procured on a sole source basis pursuant to Federal Acquisition Regulation 19.805-1(b)(2). Naval Facilities Engineering Command, Atlantic, Norfolk, Virginia, is the contracting activity (N62470-19-D-4004). General Dynamics Electric Boat Corp., Groton, Connecticut, is awarded $15,200,000 for delivery order N62789-19-F-0019 under previously awarded, multiple award, indefinite-delivery/indefinite-quantity contract N00024-16-D-4300 for the planning, material procurement, and repair work for USS Washington (SSN 787). Work will be performed in Groton, Connecticut, and is expected to be complete by December 2019. Fiscal 2019 operations and maintenance (Navy) funding in the amount of $7,600,000 will be obligated at time of award and will expire at the end of the current fiscal year. A Fair Opportunity Notice was issued to both multiple award contract indefinite-delivery/indefinite-quantity holders on July 18, 2019, in accordance with 10 U.S. Code 2304(c)(1). The Supervisor of Shipbuilding, Conversion and Repair, Groton, Connecticut, is the contracting activity. MN&DPI JV LLC, Honolulu, Hawaii, is awarded a $15,000,000 firm-fixed-price modification to increase the maximum dollar value of previously awarded indefinite-delivery/indefinite-quantity contract (N62742-18-D-0001) for architect-engineering services for various structural and waterfront projects and other projects under the cognizance of Naval Facilities Engineering Command (NAVFAC) Pacific. The work to be performed provides for design and engineering services for the execution and delivery of engineering studies; plans, specifications, and cost estimates/parametric cost estimates, including preparation of design-build contract documents or design-bid-build contract documents; and post construction award services. After award of this modification, the total cumulative contract value will be $55,000,000. Work will be performed at various Navy and Marine Corps facilities and other government facilities within the NAVFAC Pacific Area of Responsibility, including Guam (69%); and Hawaii (13%). The term of the contract is not to exceed 60 months, with an expected completion date of December 2022. No funds will be obligated at time of award; funds will be obligated on individual task orders and task order modifications as they are issued. Task orders will be primarily funded by military construction (planning and design). Naval Facilities Engineering Command Pacific, Joint Base Pearl Harbor-Hickam, Hawaii, is the contracting activity. ARMY Federal Contracting Inc., doing business as Bryan Construction Inc., Colorado Springs, Colorado, was awarded a $69,146,753 firm-fixed-price contract for construction of a tactical equipment maintenance facility and ancillary buildings. Bids were solicited via the internet with six received. Work will be performed in Fort Carson, Colorado, with an estimated completion date of April 24, 2021. Fiscal 2019 military construction funds in the amount of $69,146,753 were obligated at the time of the award. U.S. Army Corps of Engineers, Omaha, Nebraska, is the contracting activity (W9128F-19-C-0029). TekSynap Corp.,* Reston, Virginia, was awarded a $31,657,006 firm-fixed-price contract for general program management, technical, research, analytical, and administrative support. Bids were solicited via the internet with one received. Work locations and funding will be determined with each order, with an estimated completion date of Aug. 8, 2024. U.S. Army Mission Installation Contracting Command, Fort Sam Houston, Texas, is the contracting activity (W9124J-19-D-0015). Digital Management LLC, Bethesda, Maryland, was awarded an $19,141,206 modification (P00007) to contract W52P1J-17-F-4020 for interactive Personnel Electronic Record Management System. Work locations and funding will be determined with each order, with an estimated completion date of Aug. 9, 2022. U.S. Army Contracting Command, Rock Island Arsenal, Illinois, is the contracting activity. Dumey Contracting Inc.,* Benton, Missouri, was awarded a $14,714,782 firm-fixed-price contract for construction, and degrading an existing levee and levee with berms and ditches. Bids were solicited via the internet with seven received. Work will be performed in Hornersville, Missouri, with an estimated completion date of Dec. 1, 2021. Fiscal 2019 civil works funds in the amount of $14,714,782 were obligated at the time of the award. U.S. Army Corps of Engineers, Memphis, Tennessee, is the contracting activity (W912EQ-19-C-0008). Manson Construction, Seattle, Washington, was awarded a $13,655,300 firm-fixed-price contract for unrestricted procurement for Houston Ship Channel hopper dredging. Bids were solicited via the internet with three received. Work will be performed in Galveston, Texas, with an estimated completion date of March 27, 2020. Fiscal 2019 civil operations and maintenance funds in the amount of $13,655,300 were obligated at the time of the award. U.S. Army Corps of Engineers, Galveston, Texas, is the contracting activity (W912HY-19-C-0008). RLB Contracting Inc.,* Port Lavaca, Texas, was awarded a $13,584,500 firm-fixed-price contract for maintenance dredging. Bids were solicited via the internet with four received. Work will be performed in Port Arthur, Texas, with an estimated completion date of March 10, 2020. Fiscal 2019 civil operations and maintenance funds in the amount of $13,584,500 were obligated at the time of the award. U.S. Army Corps of Engineers, Galveston, Texas, is the contracting activity (W912HY-19-C-0011). Cottrell Contracting Corp.,* Chesapeake, Virginia, was awarded a $10,437,490 firm-fixed-price contract for Norfolk Harbor Channel maintenance dredging. Bids were solicited via the internet with two received. Work will be performed in Norfolk, Virginia, with an estimated completion date of Jan. 11, 2020. Fiscal 2019 civil construction funds in the amount of $10,437,490 were obligated at the time of the award. U.S. Army Corps of Engineers, Norfolk, Virginia, is the contracting activity (W91236-19-C-0019). Yaeger Architecture Inc.,* Lenexa, Kansas, was awarded a $10,000,000 firm-fixed-price contract for architect and engineering services. Bids were solicited via the internet with three received. Work locations and funding will be determined with each order, with an estimated completion date of Feb. 8, 2025. U.S. Army Corps of Engineers, Kansas City, Missouri, is the contracting activity (W912DQ-19-D-4011). Morrish-Wallace Construction Inc.,* Cheboygan, Michigan, was awarded an $8,243,527 firm-fixed-price contract for repairs and stone revetment along Lake Erie. Bids were solicited via the internet with two received. Work will be performed in Hamburg, New York, with an estimated completion date of April 30, 2021. Fiscal 2010 civil construction funds in the amount of $8,243,527 were obligated at the time of the award. U.S. Army Corps of Engineers, Buffalo, New York, is the contracting activity (W912P4-19-C-0019). AIR FORCE Radiant Geospatial Solutions LLC,* Ypsilanti, Michigan, has been awarded a $14,226,474 cost-plus-fixed-fee contract for Red Wing Next Generation Geospatial Intelligence (GEOINT) Cloud. The objective of this effort is to deliver an automated and efficient workflow for National System of GEOINT analysis by reducing latency for product generation, exploitation and intelligence gathering. This effort will expand the use of Amazon managed services through careful assessment of emerging offerings with the goal of improving resiliency, reducing cost and reducing exposure to cyber threats. Work will be performed at Ypsilanti, Michigan; and Herndon, Virginia, and is expected to be completed by Aug. 7, 2021. This award is the result of a competitive acquisition and two offers were received. Fiscal 2019 research, development, test and evaluation in the amount of $3,713,188 are being obligated at time of award. The Air Force Research Laboratory, Rome, New York, is the contracting activity (FA8750-19-C-1502). Kearney & Co. P.C., Alexandria, Virginia, has been awarded a $13,031,667 firm-fixed-price contract for advisory and assistance services support for the Air Force Warfighting Integration Capability missions. This contract will provide for future and concepts analysis, design blueprints, capability development strategic integration, capability development implementation analysis, assessment of opportunities for new capability, workflow management, strategic communication, special access program integration, simulation studies, war gaming support, decision analytics and strategy, planning, programming, budgeting and execution analysis. Work will be performed at Washington, District of Columbia, and is expected to be completed by Aug. 8, 2020. This award is the result of a competitive acquisition and two offers were received. Fiscal 2019 operations and maintenance funds in the amount of $8,994,101 are being obligated at the time of award. The Air Force District of Washington Contracting Directorate, Joint Base Andrews, Maryland, is the contracting activity (FA7014-19-F-A162). Kearney & Co. P.C., Alexandria, Virginia, has been awarded a $9,620,685 firm fixed price contract modification (P00005) to previously awarded contract FA7014-18-F-1022 for the exercise of Option Period One for advisory and assistance services to support Total Force analysis. This contract modification includes capability and capacity analysis of Air Force mission areas; linking results to the strategy, planning, and programming process; performing planning, programming, and budgeting study excursions; analytically supporting Total Force initiatives, strategy review and assessment and planning support. Work will be performed at Arlington, Virginia, and is expected to be completed by July 31, 2020. Fiscal 2019 operations and maintenance funds in the amount of $9,237,252 are being obligated at the time of award. The Air Force District of Washington Contracting Directorate, Joint Base Andrews, Maryland, is the contracting activity. Midwest Air Traffic Control Service Inc., Overland Park, Kansas, has been awarded an $8,410,622 cost-plus-fixed-fee modification (P00013) to previously awarded contract N65236-14-D-4984 for aviation command and control operations and maintenance services. The contract modification adds five months and 20 days to the current task order. Work will be performed in the Air Force Central Command's area of responsibility and expected to be completed by Feb. 29, 2020. Fiscal 2019 operations and maintenance funds are being obligated in the amount of $8,410,622 at the time of the award. The Air Combat Command, Acquisition Management and Integration Center, Langley Air Force Base, Virginia, is the contracting activity. *Small Business

  • Defense Industry’s Covid Closings Decline, Pentagon Agency Says

    8 juillet 2020 | International, Aérospatial, Naval, Terrestre, C4ISR, Sécurité

    Defense Industry’s Covid Closings Decline, Pentagon Agency Says

    By Anthony Capaccio The defense industry has made major strides reducing the impact of Covid-19 on operations, decreasing total closings of facilities to six on Monday from a high of 148 in mid-April, according to the Pentagon agency that oversees contracts. “We're seeing a significantly smaller fraction of the industrial base impacted on a daily basis” as contractors have become “better at restoring operational capability after potential exposures” to the coronavirus, Army Lieutenant General David Bassett, director of the Defense Contract Management Agency, said in an interview. “We've gone from having a substantial fraction of the industrial base impacted to today,” where it's “just a handful.” In total, 279 defense contracting locations were forced to shut down an average of 20 days since April because of the pandemic. In addition, 149 locations currently have reduced operations because of the virus, according to the agency, which tracks 10,509 locations of major defense contractors and their subcontractors. “These closures have generally been short-term in order to clean facilities” or to “reduce the potential exposure of employees,” according to agency spokesman Matthew Montgomery. Ellen Lord, the Defense Department's acquisitions chief, has warned that pandemic disruptions are expected to result in defense industry claims for reimbursement of more than $10 billion under the Cares Act, which provides economic aid including reimbursing contractors for payments to employees affected by disruptions such as plant closings. She has said a single contractor, which she didn't name, is estimated to have at least $1.5 billion in potential claims. Bassett said the decline in plant closings reflects that companies “have really got a plan in place so that they know what they have to do when they find people who have been exposed, how they have to handle the plant and then what they can do to get back up quickly and safely.” Bassett assumed command of the contract agency on June 3 after a career that included positions as the Army's top program manager for command-and-control networks and for ground-combat vehicles. “As we watch right now and cases are beginning to rise in certain areas of the country, I've asked all of our teams to really think about what we can do right now to make sure if we do end up in a shutdown we can avoid impacts to the industrial base and our deliveries,” he said. https://www.bloomberg.com/news/articles/2020-07-07/defense-industry-s-covid-closings-decline-pentagon-agency-says

Toutes les nouvelles