15 août 2018 | International, C4ISR

Cost Isn’t Everything. Pentagon Should Judge Contractors on Cybersecurity, Report Says

Security would be ‘fourth pillar' in weapons purchase decisions

The Pentagon should take into account the cybersecurity capabilities of defense contractors in addition to cost and performance measures when awarding contracts, a U.S. government-funded think tank recommended in a report published Monday.

Through its buying process, the Pentagon “can influence and shape the conduct of its suppliers,” the Mitre Corp. said in a report titled “Deliver Uncompromised: A Strategy for Supply Chain Security and Resilience in Response to the Changing Character of War.”

The Defense Department “can define requirements to incorporate new security measures, reward superior security measures in the source selection process, include contract terms that impose security obligations, and use contractual oversight to monitor contractor accomplishments,” the report said.

The Pentagon must consider new measures because the very nature of war is changing, the Mitre report said. Adversaries no longer have to engage the United States in direct conflict using weapons but can respond to American military strikes “through blended operations that take place through supply chain, cyber domain, and human elements,” the report noted.

The report recommends that security be made a “primary metric” in Pentagon weapons purchase and sustainment decisions and that the Defense Department increase awareness of risks associated with its supply chains. It also calls for a National Supply Chain Intelligence Center that would include officials from the FBI, Homeland Security, the Pentagon and intelligence agencies to track risks and advise agencies.

When choosing current or new contractors, in addition to considering cost, performance and schedule, the Pentagon must also make security a so-called “fourth pillar,” the report said. Contractors should be continuously monitored and assessed for the degree of risk they pose, the report said.

In addition to measuring a contractor's ongoing performance on a contract, an independent, federally-funded research agency could develop a risk rating similar to credit ratings done by agencies like Moody's, the report said. Mitre is a federally-funded research and development center.

The Pentagon did not respond to an email seeking comment on the report.

The report and its recommendations come as U.S. intelligence officials have become increasingly alarmed at potential cybersecurity risks that may be embedded in vast computer networks and systems that power government agencies as well as weapon systems. Last year the Trump administration banned federal agencies from using a popular anti-virus software made by Kaspersky Labs, which was alleged to have close ties with Russian intelligence services.

Full Article: https://www.rollcall.com/news/politics/pentagon-judge-contractors-cybersecurity

Sur le même sujet

  • Philadelphia shipyard to build new dual-use merchant mariner training ships

    16 avril 2020 | International, Naval

    Philadelphia shipyard to build new dual-use merchant mariner training ships

    By: David B. Larter WASHINGTON — A struggling Philadelphia shipyard got a new lease on life April 8 with the announcement that it had been selected to build up to five training ships for the Maritime Administration destined for use by civilian mariners attending state maritime academies. The contract, issued by Alaska-based company TOTE Services, tapped Philly Shipyard to build the first two national security multimission vessels, or NSMV, for a total of $630 million, according to the trade publication Marine Log. The ships, which will feature the latest navigation and bridge technologies, will be able to accommodate up to 600 cadets but will also be available for use by the federal government for disaster relief operations. The ships come with a roll-on/roll-off ramp and a crane that can be used for moving equipment and containers. The NSMVs will be 525 feet long and about 90 feet wide, or just a little smaller than a Ticonderoga-class cruiser, according to a Maritime Administration fact sheet. MARAD Administrator Mark Buzby said the contract is a win for American shipbuilding jobs. “Investing in maritime education creates more American jobs,” Buzby, a former Navy flag officer, said in a statement. "By the selection of Philly Shipyard, Inc., as the construction shipyard for the NSMV, this effort is not only bolstering the U.S. Merchant Marine, but the U.S. economy and vital transportation infrastructure as well.” Philly Shipyard primarily makes Jones Act ships, or vessels that exist only because the Jones Act mandates that goods shipped between U.S. ports must be sent on U.S.-flagged ships built and crewed by Americans. The rule is designed to preserve the domestic shipbuilding industry as a national security asset. Without it there would essentially be no domestic commercial shipbuilding industry. “Philly Shipyard only received one order per year during the last two years and was in danger of closing during 2020 unless it received additional work,” said Bryan Clark, a senior fellow at the Hudson Institute who recently led a study of the domestic shipbuilding industry. “Philly is important not just because it is a significant employer in the Philadelphia area, but also because it is one of the shipyards the government depends on to build smaller auxiliary and non-combatant ships such as Coast Guard cutters, NOAA research ships, and Navy unmanned surface vessels, survey ships, and towing and salvage vessels.” The vessels could also prove useful in the Navy's quest to identify a flexible hull that can meet a number of missions as it seeks to replace its aging logistics fleet, said Sal Mercogliano, a maritime historian at Campbell University. “I think those vessels serve as a potential hull form for maybe a hospital ship, maybe a command ship, an aviation logistics ship, a sub tender: There's potential there,” Mercogliano said. The Navy planned to develop and field two variants of a Common Hull Auxiliary Multi-Mission Platform, one for sealift purposes and one for other auxiliary ship missions such as submarine tending, hospital ships, and command-and-control platforms. But late last year, the White House blanched at a cost estimate of upward of $1.3 billion for the submarine tender variant of the CHAMP platform, planned for acquisition in 2024. For moving lots of tanks and howitzers across long distances, the NSMV isn't well-suited. But for many of the other missions the Navy needs to recapitalize, including its hospital ships, it could prove useful. “I don't think they'd be good for a roll-on/roll-off — it's not designed for a large mission bay,” Mercogliano said. “But I think for the hospital ship, a command ship, there's a lot of utility there.” https://www.defensenews.com/naval/2020/04/14/philadelphia-shipyard-tapped-to-build-new-merchant-marine-training-ships

  • Pratt Defining Engine Upgrade Package For Block 5 F-35

    18 septembre 2019 | International, Aérospatial

    Pratt Defining Engine Upgrade Package For Block 5 F-35

    Steve Trimble Pratt & Whitney is defining a new engine upgrade option for Block 5 F-35s delivered starting in the 2030s, says Matthew Bromberg, president of Military Engines. The upgrades, the details of which will be defined in about six months, are focused on improvements to the fan and the engine accessories, Bromberg told Aerospace DAILY during a Sept. 17 interview on the sidelines of the Air Force Association's Air, Space and Cyber Conference. The intent is to deliver options for improving thrust by more than 10-12%, reducing fuel consumption by more than 5-6%, increasing vertical lift by about 2% and increasing overall power and thermal management capacity, Bromberg says. Those targets are the proposed baseline improvements advertised for the Growth Option 2.0 upgrade, which remains in discussions for insertion in Block 4.4 aircraft delivered starting in 2028, he says. P&W originally proposed a Growth Option 1.0 upgrade package that offered only thrust and fuel improvements, but no extra capacity for power generation and cooling. “We found it didn't resonate because it didn't have power and thermal management,” Bromberg says. The Growth Option and Engine Enhancement Package upgrades all stem from technologies developed under the Adaptive Engine Technology Program, which is funded by the Air Force Research Laboratory to design a new engine core. Pratt & Whitney completed the detailed design review of the XA101 demonstrator engine recently, Bromberg says. https://aviationweek.com/defense/pratt-defining-engine-upgrade-package-block-5-f-35

  • COVID-19 is changing the Air Force’s cyber training

    29 juillet 2020 | International, C4ISR, Sécurité

    COVID-19 is changing the Air Force’s cyber training

    Mark Pomerleau WASHINGTON — The Air Force is ensuring its mission essential cyber training goes on during the global COVID-19 pandemic but officials are also delaying some training related to the service's networks. “When all this kicked off, we prioritized all of the mission essential courses that are supplying operators to the cyber mission force. We wanted to make sure that those units continue to get the trained operations that they needed so that their readiness levels didn't suffer,” Lt. Col. Jonathan Williams, commander of the 39th Information Operations Squadron, which provides intermediate cyber weapons system training to airmen, told C4ISRNET. The cyber mission force are the teams each of the services provide up to U.S. Cyber Command. In addition to training cyber mission force personnel, the 39th IOS also trains specific weapon systems for the Air Force network (AFNET), which were either postponed or reduced class size to ensure students are safe. The reduction in those Air Force specific courses have allowed the mission essential courses to reduce in person class sizes for classified work that can't be done remotely to ensure the proper social distancing measures are taken. To learn outside the classroom, the schoolhouse is relying on a partnership with Carnegie Mellon for an entirely online cyberspace fundamentals course, Microsoft Teams and WebEx. Students also don't have to necessarily travel to the 39th in Hurlburt Field, Florida for some training. They can remotely take courses such as the cyber fundamentals course online saving money for temporary duty travel. Williams said he expects to see more of that in the future. The remote tools have also allowed students to gain a unique experience with members of the operational force, while simultaneously saving the taxpayer money. Students are able to hear from operational commanders and operators and even participate in exercises with units. Previously, the students would have to travel to those units to participate, but now, they can dial in. “That helps us in the classroom hit it home. We get those war stories to use in the classroom and the students actually, those light bulbs start to turn on and it really starts to hit home,” TSgt Jonathan Zinski, a course instructor, said. “Now that we have more of an eye-opening capability to use some of our virtual tools, we've actually been able to enroll and participate an entire team of instructors and cadre here at the 39th IOS to participate in a no-kidding virtual exercise with an operational unit to not only hone our skills and help some of our instructors here bring the lessons learned into the classroom but to also help the operational units from our standpoint and help them get better at their jobs.” This experience also gives the students a flavor of what to expect at their units prior to arriving. Officials explained that while the actual courseware didn't change, the schoolhouse shifted the courseware and maneuvered the syllabus to accommodate students doing a combination of distance learning and in person classes. They looked at what courses needed to be conducted in person, then worked around that to ensure the class sizes were small enough while supplementing with remote learning tools. The pandemic has also accelerated certain initiatives the school planned to undertake at a later date. Williams said one includes combining cyber mission force and AFNET defensive cyber training. He said they are re-imagining the defensive cyber training pipeline with something they're calling defensive cyber operations initial qualification training. “Instead of creating a blanket training for each of these weapon systems, we're trying to integrate the AFNET systems with the CMF where it makes sense and also tailor the training,” he said, noting this should be up and running in October regardless of COVID-19. This re-imagining was always planned, but Williams said COVID accelerated it. The adaptations the 39th has been forced to make as a result of the pandemic has rendered some valuable lessons as well. Williams said some initiatives never would have been considered if the pandemic didn't hit. He explained officials are turning a conference room into a recording studio so instructors can either deliver training to students in a separate room or record lectures for students to view later. https://www.c4isrnet.com/cyber/2020/07/27/covid-19-is-changing-the-air-forces-cyber-training/

Toutes les nouvelles