3 février 2020 | International, Aérospatial, Naval, Terrestre, C4ISR, Sécurité

Pentagon finalizes first set of cyber standards for contractors

Mark Pomerleau

The Pentagon has finalized the long anticipated cybersecurity standards contractors will have to follow before winning contracts from the Department of Defense, a new process called the Cybersecurity Maturity Model Certification (CMMC) 1.0.

The model is a tiered cybersecurity framework that grades companies on a scale of one to five based on the level of classification and security that necessary for the work they are performing.

“The government and the contractor community must keep working together to address real and growing cybersecurity threats, and we need a robust response to protect our infrastructure, information, and supply chains,” said David Berteau, president and chief executive of the Professional Services Council, a trade association for federal contractors. “With today's announcement, DoD has achieved a significant milestone.

Here's what industry officials need to know about the version finalized Jan. 31.

Why it was needed

Previously, the Pentagon did not have unified standard for cybersecurity that businesses needed to follow when bidding for contracts. Companies could claim to meet certain industry standards for cybersecurity, but those assertions were not tested by auditors, nor did the standards take into account the type of work a company was bidding to complete. Since then, defense officials have said that cybersecurity is not a one size fits all approach.

In the meantime, adversaries have discovered it is easier to target unsuspecting down tier suppliers, rather than prime contractors.

“Adversaries know that in today's great power competition environment, information and technology are both key cornerstones and attacking a sub-tier supplier is far more appealing than a prime,” Ellen Lord, the under secretary of defense for acquisition and sustainment, told reporters in a briefing at the Pentagon Jan. 31.

Officials have said cyber theft by adversaries costs the United States about $600 billion a year.

What will change?

Contracts will mandate bidders reach a certain level of certification to win specific jobs. For example, if businesses aren't bidding on a contract that has extremely sensitive information, they must only achieve the first level of certification, which involves basic cybersecurity such as changing passwords and running antivirus software. More sensitive programs will require more stringent controls.

Smaller companies down the supply chain will not, however, have to have the same level of certification as primes, said Katie Arrington, chief information security officer for the Office of the Under Secretary of Defense for Acquisition and the point person for the certification.

Another significant change with the new process is the creation of an accreditation board and assessors. The board is an outside entity, separate from DoD, that will be charged with approving assessors to certify companies in the process.

The accreditation body was formed earlier this month and officials are working on identifying and training the assessors, which will be called Certified Third-Party Assessment Organizations (C3PAO).

What's next?

Officials explained Jan. 31 that CMMC will follow a crawl, walk, run approach to ensure companies aren't unprepared for the change. The accreditation board is in the process of training the auditors that will oversee the certificaion. Once the requirements are met, a company's certification is good for 3 years.

In the meantime, DoD plans to release 10 requests for information and 10 requests for proposals that will include the new cyber standards this year. The first solicitation could come as early as June.

Arrington said earlier this week that she expects 1,500 companies to be certified by the end of 2021.

She added that all new contracts starting in fiscal year 2026 will contain the cybersecurity requirements, however, Lord noted that they will not be not retroactive to previous contracts.

https://www.fifthdomain.com/dod/2020/01/31/pentagon-finalizes-first-set-of-cyber-standards-for-contractors/

Sur le même sujet

  • What To Watch For As A&D Companies Plan Future With COVID-19

    24 avril 2020 | International, Aérospatial

    What To Watch For As A&D Companies Plan Future With COVID-19

    Michael Bruno Companies have good quarters and bad quarters, but rarely does a whole industry sound like it just got sucker-punched. That's what the next few weeks will be like in the aerospace and defense sector, and for sure there will be headlines describing industrial carnage as the industry gasps for air and works to recover after COVID-19. The truth is the aerospace and defense (A&D) supply chain suddenly is far too large for what is needed, maybe by a quarter or a third of excess capacity. As a result, quick or methodical cutbacks in manufacturing and services are expected throughout the syndicates that make airliners, business jets and other aircraft. As public companies report their latest quarterly financial results in late April and May, they will have to address the year ahead and offer insight into their response plans. Unfortunately, business as usual prior to COVID-19 is not expected until 2022 or later, according to numerous analysts and advisors. And that is just too long to carry extra financial costs, which means all levels will feel pain. “The COVID-19 decline is a serious risk for commercial OEM plays—Boeing, Spirit AeroSystems, Allegheny Technologies, Hexcel, Howmet Aerospace, Triumph Group and Carpenter Technology,” Cowen analysts say. “Aftermarket ‘relative safe havens' Honeywell International, Heico and TransDigm Group also face stiff near-term headwinds, with more serious risks at General Electric.” If OEMs and their Tier 1 and 2 suppliers are already cutting their workforces, slashing executive salaries and suspending shareholder returns—as dozens have announced since the novel coronavirus began sweeping through the U.S. in March—then it is easy to imagine that much lower tiers with their even thinner margins could face existential reckonings. “People who didn't plan for it were unreasonably naive,” asserts Avitas consultant Adam Pilarski, a longtime expert who espoused a bearish view on commercial aviation long before the Boeing 737 MAX crisis started gumming up business models. “There is no magic potion here. You will have less production.” While Pilarski's comment may come across as harsh, it accurately describes the depth of the coming paradigm shift for commercial aviation. Yes, perhaps it was too much to have asked OEMs and suppliers to model for a 95% collapse in passenger air traffic and two-thirds of large commercial aircraft fleets getting parked—including brand-new deliveries. But practically no one seemed to imagine simultaneous cuts to new orders, standing backlogs and aftermarket revenue streams. Indeed, Pilarski was one of the few who envisioned an environment with much less than the traditional 5% annual growth in air traffic. That is now changing: Airbus has revealed narrowbody and widebody production rate cuts of about a third, and Boeing is expected to follow suit any day. According to Credit Suisse analysts, such sudden rate changes will have a materially negative impact on the supply chain because the effect is exponential. “[The supply chain] will need to cut production by much more as Airbus consumes its inventories—for instance, potentially going to rate 20 on the A320 for some months and ramping up again to 40,” the Credit Suisse analysts say. Boeing's inventory—including roughly 800 MAXs that are backed up with its customers and supplier Spirit AeroSystems and are waiting to join its own fleets—is worse. Still, it is not that simple to look at customers such as Airbus and Boeing and draw a direct line to suppliers to guess their fate. While the vast majority of publicly traded A&D companies have shelved the 2020 forecasts they offered just weeks before, almost no one has outlined new plans. For one thing, few suppliers had even received change orders as of early April, Ken Herbert of Canaccord Genuity says. Here are three factors to watch for in earnings reports to discern how the supply chains will change. First, how much U.S. government aid will companies receive? This is a significant variable, and as of mid-April, we still did not know how much even sector leader Boeing will receive (presuming it does). “Most suppliers we have spoken with are still waiting for more clarity on the exact terms available under the CARES Act,” says Herbert, who has deep ties in the A&D supply chain. Meanwhile, many public companies have been able to tap short-term financing or debt markets to boost liquidity—a testament to their prior investment grades. Second, the supply chain has experienced robust vetting and stress-testing over the past decade. Did it work? Record growth, record mergers and acquisitions, and record private equity involvement have dramatically consolidated industry (for better or worse). Yes, it meant elimination of countless companies, and some smaller survivors remain stressed by technology investments and meager working capital accounts. But top-tier companies have been working to eliminate chokepoints and shore up weak links in their supply chains for the last few years, ironically as they sought to raise rates. Finally, many companies became less susceptible one way or another, especially through revenue diversification (see chart). Take the new Raytheon Technologies, the first supplier to rival its OEM customers in annual sales. Manufacturers elbowed into the aftermarket; commercial providers and defense suppliers tapped into each other's markets; and venture capitalists and billionaire competitors entered into and prodded new technology advances that legacy industry had resisted funding, among other trends. Will this lead to resilience? Some think so. “In many ways, the supply chain is now more mature, diversified and well-positioned to handle this economic downturn versus in 2001 and 2008,” says Alex Krutz, managing director at Patriot Industrial Partners, an advisory firm focused on operations and supply chain. “A large number of suppliers over this last decade have taken significant steps to ensure their long-term success.” There are sure to be industrial casualties as A&D faces its greatest business falloff in history. We should mourn the loss of skilled workers and devoted people who are forced to exit the sector, but there are still new aircraft to build. And there will be supply chains to do it. https://aviationweek.com/aerospace/manufacturing-supply-chain/what-watch-ad-companies-plan-future-covid-19

  • How the new acting Pentagon chief views cybersecurity

    26 décembre 2018 | International, C4ISR

    How the new acting Pentagon chief views cybersecurity

    By: Justin Lynch President Donald Trump announced in a Dec. 23 tweet that Patrick Shanahan will become acting secretary of defense Jan. 1, replacing outgoing Pentagon chief Jim Mattis two months early. While it is not clear how long Shanahan will remain in the job, he is on the short list of officials who could become the full-time Pentagon chief. Regardless of the length of his tenure, Shanahan, the Pentagon deputy since 2017, has been one of the Pentagon's top advocates for stronger contractor cybersecurity and IT acquisition and will lead the department months after it was given expansive and loosely defined authorities to conduct offensive cyber operations. How Shanahan will handle these greater cyber authorities, even on a temporary basis, remains an open question that will be tested immediately amid evolving challenges, such as an alleged hacking campaign from China. Unclear views on cyber operations In August, the secretary of defense was given the ability to conduct offensive cyber operations without informing the president as long as it does not interfere with the “national interest” of the United States, four current and former White House and intelligence officials have told Fifth Domain. A Pentagon official told Fifth Domain that while there is a general outline of what specific operations may affect the American “national interest,” some details are not explicitly defined. And a review of his public remarks show that Shanahan has not made significant comments about how America should conduct offensive cyber operations. He has shiedaway from giving detailed responses about U.S. Cyber Command. “There are two new war-fighting domains, cyber and space, for which we are developing doctrine and capabilities,” Shanahan said Sept. 19. A spokesperson for Shanahan did not respond to questions from Fifth Domain. Focus on defense contractors As deputy, Shanahan has focused on “re-wiring” the Pentagon. He has called good cybersecurity “foundational” to working with the department. “Cybersecurity is, you know, probably going to be what we call the ‘fourth critical measurement.' We've got quality, cost, schedule, but security is one of those measures that we need to hold people accountable for,” Shanahan said Sept. 19 during an Air Force Association conference. Shanahan's focus on contractor cybersecurity comes as China is believed to be targeting defense contractors, particularly those on the lower end of the supply chain, in an attempt to steal sensitive American secrets, according to intelligence officials and industry executives. Shanahan, however, has placed responsibility among the top defense firms. “I'm a real strong believer that the Tier 1 and Tier 2 leadership has a responsibility to manage the supply chain,” Shanahan said in the Sept. 19 speech. In October, Shanahan was put in charge of a new Pentagon task force to combat data exfiltration that focuses in part on these defense firms. “Together with our partners in industry, we will use every tool at our disposal to end the loss of intellectual property, technology and data critical to our national security,” Shanahan told Fifth Domain in October. A specific area of focus inside the department is finding out which companies are in the Pentagon's supply chain, according to officials involved in the process, but it is not clear if it is specifically part of Shanahan's task force. Inside the Pentagon, Shanahan has also emphasized the need for smarter IT acquisition. In an October. interview with Fifth Domain, Shanahan expressed frustration with the Pentagon's procurement process, but said to expect “a number of things that are foundational to being able to achieve enterprise solutions.” He hinted that those changes are focused on the “right platforms and the right level of integration” that can support high-end computing and artificial intelligence. “I'm super frustrated that we can't go faster on like basic things like the cloud,” Shanahan said. “Most of everything we do is software-driven.” Aaron Mehta contributed to this report. https://www.fifthdomain.com/dod/2018/12/24/how-the-new-acting-pentagon-chief-views-cybersecurity

  • Emirates says orders 15 Airbus A350-900 worth $6 bln | Reuters

    16 novembre 2023 | International, Aérospatial

    Emirates says orders 15 Airbus A350-900 worth $6 bln | Reuters

    Dubai's Emirates Airline on Thursday anounced an order for 15 Airbus A350-900 wide-body jets, which it said was worth $6 billion.

Toutes les nouvelles