19 décembre 2018 | International, C4ISR

DoD IG: Military networks are exposed to ‘unnecessary’ cyber risks

By:

The military services are exposing networks to “unnecessary cybersecurity risks” thanks in part to a lack of visibility over software application inventories, according to a Department of Defense Inspector General report.

The IG investigated whether DoD components rationalized their software applications by identifying and eliminating any duplicative or obsolete applications. Rationalizing software applications seeks to improve enterprise IT by identifying all software applications on the network; determining if existing applications are needed, duplicative or obsolete; and determining if applications already existing within the network prior to purchasing new ones.

The audit — which focused on Marine Corps, Navy and Air Force commands and divisions — found that the groups examined did not consistently perform this rationalization process. By not having visibility into software application inventories, these organizations were unable to identify the extent of existing vulnerabilities within their applications, the report found.

Moreover, such a process could lead to cost savings associated with eliminating duplicative and obsolete applications.

Fleet Forces Command was the only command the IG reviewed that had a process in place for eliminating duplicative or obsolete applications. The Air Force did not have a process in place to prevent duplication when purchasing new applications.

The report placed blame on the DoD chief information officer for not implementing a solution for software rationalization in response to Federal Information Technology Acquisition Reform Act requirements.

The IG made three recommendations for the CIO, who did not provide a response to draft recommendations:

  • Develop an enterprisewide process for conduction software application rationalization throughout DoD;
  • Establish guidance requiring DoD components to conduct rationalization and require DoD component CIOs to develop implementation guidance outlining responsibilities for rationalization. Such a policy should also require components on at least an annual basis to validate the accuracy of their owned and in use software applications inventory; and
  • Conduct periodic review to ensure components are regularly validating the accuracy of their inventory and they are eliminating duplicative and obsolete applications.

https://www.fifthdomain.com/dod/2018/12/18/dod-ig-military-networks-are-exposed-to-unnecessary-cyber-risks

Sur le même sujet

  • Intelligence Community’s IT roadmap shows way to a data-centric future

    2 juillet 2024 | International, C4ISR

    Intelligence Community’s IT roadmap shows way to a data-centric future

    Opinion: To achieve data-centricity at scale, the IC must govern and manage data cohesively, at every point of the data lifecycle.

  • Cyber Security Today, April 8, 2024 – Crooks are hijacking Facebook pages to spread phoney AI applications | IT World Canada News

    8 avril 2024 | International, Sécurité

    Cyber Security Today, April 8, 2024 – Crooks are hijacking Facebook pages to spread phoney AI applications | IT World Canada News

    Crooks are hijacking Facebook pages to spread phoney AI applications. Welcome to Cyber Security Today. It's Monday April, 8th, 2024. I'm Howard Solomon with a roundup of the latest cybersecurity news. Cybercrooks are taking over poorly-protected Facebook profiles to spread links to fake artificial intelligence applications. That's according to researchers at Bitdefender. They say the

  • Netherlands ‘very welcome’ to join European sub program — with a caveat

    5 avril 2018 | International, Naval

    Netherlands ‘very welcome’ to join European sub program — with a caveat

    By: Sebastian Sprenger COLOGNE, Germany — The Netherlands would be welcome to join a German-Norwegian submarine acquisition program, even as the door is closing for final design work on the boats, the Norwegian defense ministry said. The statement comes as German defense industry officials have talked for weeks about what they believe is an impending move to reshuffle big-ticket shipbuilding programs by way of a new naval cooperation umbrella with the Dutch. In that telling, The Hague would join the purchase of 212CD-class submarines, built by Thyssen Krupp Marine Systems' undersea division, and gain a say in the fate of Germany's Mehrzweck-Kampfschiff 180 frigate program, from which the surface division of TKMS was excluded last month. While Berlin and The Hague have officially kept mum about details, several German industry officials and analysts surveyed for this article believe the prospect of a Dutch move is keeping the MKS-180 program's fate unpredictable. When asked about the Netherlands' interest in the German combat ship effort, Dutch defense ministry spokesman Peter Valstar only wrote in an email to Defense News that senior acquisition officials from both countries had met recently to discuss “various topics like possible cooperations on all kinds of defense projects.” As for submarines, “We're currently in the B-phase (research) of our so-called ‘Defence Material Process,‘” Valstar wrote. “The ‘need' (A-phase) of a submarine purchase is clear. The C-phase (further research) and D-phase (product and supplier) are still to come.” Norway has always considered the door open for additional submarine buyers since Oslo teamed with Berlin last year. The joint acquisition would see Norway buy four boats and Germany two. Buying and maintaining identical submarines would keep cost down for both countries, the argument goes. “Norway and Germany would like to see additional partners joining the cooperation, and it would be very welcome if the Netherlands should decide to join,” Norwegian defense ministry spokeswoman Ann Kristin Salbuvik wrote in an email to Defense News. “We are working together towards several potential nations, and we have a good dialogue with potential partners,” Salbuvik added when asked if the Dutch had formally expressed an interest. But the door is closing for would-be partners to have a say in the boats' configurations. “The design of the German-Norwegian submarines will soon be frozen in order for the supplier, TKMS, to be able to provide a binding offer in July 2018,” the spokeswoman wrote. “After this point in time, design changes will be costly, and will also have a negative impact on time and delivery schedules for the German-Norwegian submarine building program,” she added. “If additional partners join the cooperation, it will be beneficial for them to strive for as identical a design as possible.” It is unclear how far discussions for a Dutch-German naval armaments pact have bubbled up toward the defense ministries' leaders. But the issue is “very much a topic of conversation in political Berlin,” one source noted. If given the chance to tweak the MKS-180 configuration, the Dutch would push for a smaller ship design than is currently envisioned, one industry source predicted. With Damen Shipyards, the Dutch already have local industry in the running for the program, teaming with Germany's Blohm &Voss, which is now part of the German Lürssen group. https://www.defensenews.com/global/europe/2018/04/04/netherlands-very-welcome-to-join-european-sub-program-with-a-caveat/

Toutes les nouvelles