3 février 2020 | International, Aérospatial, Naval, Terrestre, C4ISR, Sécurité

Pentagon finalizes first set of cyber standards for contractors

Mark Pomerleau

The Pentagon has finalized the long anticipated cybersecurity standards contractors will have to follow before winning contracts from the Department of Defense, a new process called the Cybersecurity Maturity Model Certification (CMMC) 1.0.

The model is a tiered cybersecurity framework that grades companies on a scale of one to five based on the level of classification and security that necessary for the work they are performing.

“The government and the contractor community must keep working together to address real and growing cybersecurity threats, and we need a robust response to protect our infrastructure, information, and supply chains,” said David Berteau, president and chief executive of the Professional Services Council, a trade association for federal contractors. “With today's announcement, DoD has achieved a significant milestone.

Here's what industry officials need to know about the version finalized Jan. 31.

Why it was needed

Previously, the Pentagon did not have unified standard for cybersecurity that businesses needed to follow when bidding for contracts. Companies could claim to meet certain industry standards for cybersecurity, but those assertions were not tested by auditors, nor did the standards take into account the type of work a company was bidding to complete. Since then, defense officials have said that cybersecurity is not a one size fits all approach.

In the meantime, adversaries have discovered it is easier to target unsuspecting down tier suppliers, rather than prime contractors.

“Adversaries know that in today's great power competition environment, information and technology are both key cornerstones and attacking a sub-tier supplier is far more appealing than a prime,” Ellen Lord, the under secretary of defense for acquisition and sustainment, told reporters in a briefing at the Pentagon Jan. 31.

Officials have said cyber theft by adversaries costs the United States about $600 billion a year.

What will change?

Contracts will mandate bidders reach a certain level of certification to win specific jobs. For example, if businesses aren't bidding on a contract that has extremely sensitive information, they must only achieve the first level of certification, which involves basic cybersecurity such as changing passwords and running antivirus software. More sensitive programs will require more stringent controls.

Smaller companies down the supply chain will not, however, have to have the same level of certification as primes, said Katie Arrington, chief information security officer for the Office of the Under Secretary of Defense for Acquisition and the point person for the certification.

Another significant change with the new process is the creation of an accreditation board and assessors. The board is an outside entity, separate from DoD, that will be charged with approving assessors to certify companies in the process.

The accreditation body was formed earlier this month and officials are working on identifying and training the assessors, which will be called Certified Third-Party Assessment Organizations (C3PAO).

What's next?

Officials explained Jan. 31 that CMMC will follow a crawl, walk, run approach to ensure companies aren't unprepared for the change. The accreditation board is in the process of training the auditors that will oversee the certificaion. Once the requirements are met, a company's certification is good for 3 years.

In the meantime, DoD plans to release 10 requests for information and 10 requests for proposals that will include the new cyber standards this year. The first solicitation could come as early as June.

Arrington said earlier this week that she expects 1,500 companies to be certified by the end of 2021.

She added that all new contracts starting in fiscal year 2026 will contain the cybersecurity requirements, however, Lord noted that they will not be not retroactive to previous contracts.

https://www.fifthdomain.com/dod/2020/01/31/pentagon-finalizes-first-set-of-cyber-standards-for-contractors/

Sur le même sujet

  • From laundry to cleaning, military willing to pay for creative solutions to pandemic problems

    15 juin 2020 | International, Terrestre

    From laundry to cleaning, military willing to pay for creative solutions to pandemic problems

    'We know that there is some innovation out there that can help us do those things better and sometimes faster' David Burke · CBC News · Posted: Jun 14, 2020 6:00 AM AT | Last Updated: June 14 The Department of National Defence is reaching out to Canadians for innovative solutions to problems it's facing due to COVID-19. The department is willing to pay $15 million for that assistance. The effort is being funded through DND's Innovation for Defence Excellence and Security program, which pays for research by outside organizations, typically businesses and universities. In this case, DND has three specific goals. The military wants to be able to rapidly sanitize workplaces and vehicles containing sensitive equipment like computers. It wants to be able to quickly clean uniforms and COVID-19 protective gear so it can be reused. It's also looking for ways to gather data to support the early detection and monitoring of contagious disease outbreaks. "We're reaching out to Canadian innovators because we know that there is some creativity out there, we know that there is some innovation out there that can help us do those things better and sometimes faster," said Eric Fournier, director general of innovation for DND. He said DND is working with the Centre for Security Science Program, the National Research Council of Canada, the Public Health Agency of Canada and Health Canada to hunt for solutions that will benefit the whole country. If a solution to any of the problems is found, it will be passed along to federal, provincial and municipal agencies. "Although the program doing this is a national defence program," said Fournier, "we are doing this for public safety across Canada. So it's for the first responders, it's also for national defence, it's for everybody and those solutions will be made available to all those government entities." Rapid, thorough cleaning is DND's goal. Fournier said it can take a lot of time to sanitize by hand. During a crisis, that time can be in short supply, he said. He said if a military aircraft is used to transport a COVID-19 patient, the entire vehicle, along with the uniforms and the personal protective equipment worn by the crew, would have to be cleaned. "We want to make sure that the people are ready to respond, again and again and again and again," said Fournier. "In a pandemic like this, we see that people have to work constantly." While dropping uniforms and flight suits into the washing machine might be an option, the military wants something faster. "So we want to make sure you can do it quickly," Fournier said. "In some cases just putting it in the laundry might work, but we might not have the time to do it that way. We might need something to clean it up faster for reuse in a few hours, for example." It's the same thing with cleaning vehicles by hand. It works, but getting it done fast is hard to do. Finding a way to sanitize aircraft, ambulances, offices and other spaces without damaging computers or other electronics is essential, Fournier said. He said it's also important to find ways to collect data on how the virus is moving through the population and to locate hot spots. DND will choose several winners in each of the three categories. The winners will be given up to $200,000 and up to six months to deliver on their solution. If the solution works, DND could provide them with more funding for fine-tuning or to adapt it for more widespread use. Anyone looking to apply for the program can go to the Innovation for Defence Excellence and Security website. There have only been a handful of applications, but Fournier said that number usually jumps up in the final days before the deadline. Applications for the program are due June 23. https://www.cbc.ca/news/canada/nova-scotia/military-dnd-covid-19-research-solutions-1.5607535

  • Swedish defence group Saab raises outlook after Q3 profit jumps, shares rise | Reuters

    26 octobre 2023 | International, Aérospatial

    Swedish defence group Saab raises outlook after Q3 profit jumps, shares rise | Reuters

    Swedish defence contractor Saab reported on Thursday a jump in third-quarter profit helped by high demand and raised its full-year sales outlook, sending its shares up 7% in early trade.

  • How Top Military Contractors Raytheon And BAE Systems Are Drawing Non-Traditional Suppliers Into Defense

    24 janvier 2020 | International, Aérospatial

    How Top Military Contractors Raytheon And BAE Systems Are Drawing Non-Traditional Suppliers Into Defense

    During the long years that U.S. forces were fighting Islamic extremists in Southwest Asia, Russia and China were investing in new warfighting technologies. Russia's hybrid military campaign against Ukraine in 2014 was a wake-up call for Washington to start paying more attention to “near-peer” threats. China's steadily increasing investment in long-range anti-ship missiles, anti-satellite weapons and cyber warfare reinforced awareness that America's military might be falling behind in the capabilities needed for winning high-end fights. These trends led the Trump Administration to produce a new national defense strategy in 2018 focused mainly on countering the military challenges posed by Moscow and Beijing. Most of that strategy's content is secret, but one element is clear enough: the Pentagon wants novel solutions to emerging near-peer threats, and it wants them fast. Policymakers in both the Obama and Trump administrations have repeatedly stated non-traditional military suppliers are a vital part of the Pentagon's effort to get ahead of overseas rivals and stay there. “Non-traditional” has a specific legal definition in defense acquisition policy that potentially allows suppliers to bypass burdensome regulations when offering commercial products from outside traditional military channels. In more common-sense usage, non-traditional simply means any company capable of offering the military a better mousetrap that doesn't usually do business with the five-sided building. That includes a majority of tech companies in places like Austin, Boston and Silicon Valley, especially startups with cutting-edge ideas. It may also include larger industrial companies like General Motors that are re-entering the military market after a long absence. The challenge facing policymakers is how to leverage the skills and intellectual property of these non-traditional players without suffocating them under a blanket of bureaucratic requirements that contribute little to finding novel solutions. One way to tap the dynamism of commercial enterprises is to partner them with longtime military contractors who can assume most of the burden for negotiating the bureaucratic landscape. Here is how two companies, Raytheon and BAE Systems, have stepped up to the challenge. Raytheon. Massachusetts-based Raytheon has been a major military contractor since it pioneered radar during World War Two. It is in the process of merging with United Technologies, an aerospace conglomerate that has long managed to operate successfully in military and commercial markets (both companies contribute to my think tank). Raytheon executives say the pace of change and the expectations of military customers have changed radically in recent years. It is not uncommon for military customers to seek new ways of sensing, processing or communicating that must be delivered within months rather than years. This emerging dynamic has led the company to rethink who it partners with in producing such solutions, and how to interact with them. Raytheon has a cultural affinity for diversity, which may help it to think outside the box about who its partners should be. Although not all of the non-traditional suppliers with whom it teams are Silicon Valley startups, a majority have not previously offered defense products as part of their portfolios. The role the company has fashioned for itself in partnering with such enterprises is to act as a translator between the fluid world of commercial innovation and the rule-based environment of military acquisition. Raytheon has always been driven by its engineering culture, so the company knows how to identify promising technologies that can be assimilated into cutting-edge combat systems. But it also knows the ins and outs of a baroque acquisition system that outsiders frequently find impenetrable. Raytheon seeks to leverage the energy of non-traditional sources while remaining in compliance with relevant government standards. For instance, there needs to be effective communication between the company and commercial sources, but the ability of the partner to observe the intricacies of sensitive projects must be tightly constrained. The tension of being a valued supplier but not accustomed to working in a classified environment must be managed. Non-traditional partners provide Raytheon with base technologies that potentially enable unique military capabilities, and they often can generate novel solutions to technical challenges quickly, thanks to their entrepreneurial cultures. Raytheon configures and integrates these inputs for military customers while translating the needs of those customers into terms the non-traditional supplier can understand. BAE Systems. The military electronics unit of another major defense contractor, BAE Systems, Inc., is headquartered across the border from Raytheon's home state in Nashua, New Hampshire. BAE concentrates on many of the same technologies Raytheon does such as sensors, signal processing and secure communications—which isn't surprising, since the core of its electronics operation was founded after World War Two by former Raytheon employees. BAE is a consulting client, which has given me some insight into how the company views non-traditional suppliers. In addition to pursuing partnering initiatives such as those at Raytheon, BAE Systems has fashioned an internal mechanism for leveraging the technology of entrepreneurial startups by helping them to finance their businesses. That mechanism is called FAST Labs, and as the name implies it was conceived to help generate novel solutions to military challenges quickly. Beyond determining whether the company should manufacture key technology inputs internally or go outside, FAST Labs continuously scouts for promising innovations that are emerging from U.S. startups. When it finds ideas with high potential, it seeks to build trusted partnerships with the enterprises, venture capital investors, universities and government agencies aimed at speeding the pace of innovation. For example, BAE has sponsored technology accelerators at places like MIT. Most of the startups FAST Labs assists are commercial companies with “dual-use” technologies potentially applicable to military purposes. Although the company has a significant commercial electronics business, the focus of FAST Labs is mainly on meeting the demands of military customers. It takes its cues as to what might be most worthy of support from agencies like the Air Force Research Lab and the Defense Advanced Research Projects Agency. FAST Labs seems to be a unique business model within the U.S. defense sector. Because the electronics technologies on which the Nashua operation concentrates are fungible across diverse markets, BAE Systems has benchmarked FAST Labs against renowned commercial R&D centers such as the old Bell Labs. It is an unusual approach to military innovation, but like executives at Raytheon, BAE execs say the usual approach to developing warfighting systems just doesn't cut it anymore with their Pentagon customer. https://www-forbes-com.cdn.ampproject.org/c/s/www.forbes.com/sites/lorenthompson/2020/01/24/how-top-military-contractors-raytheon-and-bae-systems-are-drawing-non-traditional-suppliers-into-defense/amp/

Toutes les nouvelles