15 août 2018 | International, C4ISR

Cost Isn’t Everything. Pentagon Should Judge Contractors on Cybersecurity, Report Says

Security would be ‘fourth pillar' in weapons purchase decisions

The Pentagon should take into account the cybersecurity capabilities of defense contractors in addition to cost and performance measures when awarding contracts, a U.S. government-funded think tank recommended in a report published Monday.

Through its buying process, the Pentagon “can influence and shape the conduct of its suppliers,” the Mitre Corp. said in a report titled “Deliver Uncompromised: A Strategy for Supply Chain Security and Resilience in Response to the Changing Character of War.”

The Defense Department “can define requirements to incorporate new security measures, reward superior security measures in the source selection process, include contract terms that impose security obligations, and use contractual oversight to monitor contractor accomplishments,” the report said.

The Pentagon must consider new measures because the very nature of war is changing, the Mitre report said. Adversaries no longer have to engage the United States in direct conflict using weapons but can respond to American military strikes “through blended operations that take place through supply chain, cyber domain, and human elements,” the report noted.

The report recommends that security be made a “primary metric” in Pentagon weapons purchase and sustainment decisions and that the Defense Department increase awareness of risks associated with its supply chains. It also calls for a National Supply Chain Intelligence Center that would include officials from the FBI, Homeland Security, the Pentagon and intelligence agencies to track risks and advise agencies.

When choosing current or new contractors, in addition to considering cost, performance and schedule, the Pentagon must also make security a so-called “fourth pillar,” the report said. Contractors should be continuously monitored and assessed for the degree of risk they pose, the report said.

In addition to measuring a contractor's ongoing performance on a contract, an independent, federally-funded research agency could develop a risk rating similar to credit ratings done by agencies like Moody's, the report said. Mitre is a federally-funded research and development center.

The Pentagon did not respond to an email seeking comment on the report.

The report and its recommendations come as U.S. intelligence officials have become increasingly alarmed at potential cybersecurity risks that may be embedded in vast computer networks and systems that power government agencies as well as weapon systems. Last year the Trump administration banned federal agencies from using a popular anti-virus software made by Kaspersky Labs, which was alleged to have close ties with Russian intelligence services.

Full Article: https://www.rollcall.com/news/politics/pentagon-judge-contractors-cybersecurity

Sur le même sujet

  • ‘Big changes’: Congressional panel proposes new defense budget system

    6 mars 2024 | International, Sécurité

    ‘Big changes’: Congressional panel proposes new defense budget system

    After two years spent studying the Defense Department's resourcing process, the commission recommends wholesale changes to the 60-year-old system.

  • CISA Releases the Marine Transportation System Resilience Assessment Guide | CISA
  • Lockheed, Boeing enter Germany’s heavy transport helicopter race

    15 janvier 2020 | International, Aérospatial

    Lockheed, Boeing enter Germany’s heavy transport helicopter race

    By: Sebastian Sprenger COLOGNE, Germany — Lockheed Martin's Sikorsky and Boeing have submitted their proposals for the German military's envisioned heavy transport helicopter program, the companies announced. Sikorsky is offering a version of the CH-53K designed for the U.S. Marine Corps, while Boeing is pitching the H-47 Chinook. The offers, due on Jan. 13, come in response to a request for proposals published by the Bundeswehr last summer. Government officials will spend the greater part of 2020 analyzing the submissions, with a second and final request for offers pegged for the end the year. The multibillion-dollar STH program, short for Schwerer Transporthubschrauber, is meant to replace the German fleet of decades-old CH-53G copters. Deliveries from the winning bidder are slated to begin in 2024 and last through the early 2030s — that is if the program receives budgetary support from the government and lawmakers when the time comes for a contract next year. Both companies have assembled a group of German suppliers that would oversee areas such as maintenance, simulators and documentation in an effort to maximize domestic industry participation. The Bundeswehr initially wanted a no-frills, off-the-shelf cargo helicopter that would be easy on the defense budget. Notably, the Germans also want to use the STH choppers for combat search-and-rescue operations, with plans to raise that mission profile throughout the Air Force's ranks. But last year's solicitation came with an unexpected level of complexity, Frank Crisafulli, Sikorsky's director of international business development for heavy helicopters, told reporters during a company presentation in Bonn, Germany, on Monday. “Folks were caught by surprise,” he said. The added complications are due, for example, to the Bundeswehr's goal of having the helicopters certified in accordance with European civilian aviation regulations. In addition, German officials want a weather radar better than the one offered in the Marine Corps version of the CH-53K, plus a multilayered radio communications setup," Crisafulli said. As envisioned, the STH program would plunge the German military into a model of contractor-driven support popularized by the U.S. Defense Department under the moniker of performance-based logistics, or PBL. The idea is that the government can save money by dictating to contractors what level of readiness it wants for its hardware, and then letting vendors figure out how to meet those objectives within a given budget. Pentagon auditors previously affirmed the basic premise of performance-based logistics, with one key caveat: The government must have enough insight and clout in the programs to be able to set sensible performance benchmarks at rates favorable to taxpayers. According to Mike Schmidt, CEO of Rheinmetall Aviation Services, one of Sikorsky's key local partners, the concept is relatively new for Germany. At an STH industry day in 2018, “nobody knew what PBL was,” he said. At stake for the contractors is a 40-year relationship with Germany over the life cycle of the program. Boeing has portrayed its Chinook offering as a low-risk and low-cost option because more than 950 of the aircraft are already used by 20 countries. Sikorsky has played up the aerial-refueling capabilities of the CH-53K, especially in conjunction with the Lockheed Martin-made KC-130J tanker, to increase range. https://www.defensenews.com/global/europe/2020/01/14/lockheed-boeing-enter-germanys-heavy-transport-helicopter-race/

Toutes les nouvelles