14 août 2018 | International, Aérospatial, Naval, Terrestre, C4ISR

Pentagon is rethinking its multibillion-dollar relationship with U.S. defense contractors to boost supply chain security

By Ellen Nakashima

The Pentagon has a new goal aimed at protecting its $100 billion supply chain from foreign theft and sabotage: to base its weapons contract awards on security assessments — not just cost and performance — a move that would mark a fundamental shift in department culture.

The goal, based on a strategy called Deliver Uncompromised, comes as U.S. defense firms are increasingly vulnerable to data breaches, a risk highlighted earlier this year by China's alleged theft of sensitive information related to undersea warfare, and the Pentagon's decision last year to ban software made by the Russian firm Kaspersky Lab.

On Monday, President Trump signed into a law a provision that would bar the federal government from buying equipment from Chinese telecommunications firms Huawei and ZTE Corp., a measure spurred by lawmakers' concerns about Chinese espionage.

“The department is examining ways to designate security as a metric within the acquisition process,” Maj. Audricia Harris, a Pentagon spokeswoman, said in a statement. “Determinations [currently] are based on cost, schedule and performance. The department's goal is to elevate security to be on par with cost, schedule and performance.”

The strategy was written by Mitre Corp., a nonprofit company that runs federally funded research centers, and the firm released a copy of its reportMonday.

“The major goal is to move our suppliers, the defense industrial base and the rest of the private sector who contribute to the supply chain, beyond a posture of compliance — to owning the problem with us,” said Chris Nissen, director of asymmetric-threat response at Mitre.

Harris said the Pentagon will review Mitre's recommendations before proceeding. She added that the Department of Defense, working with Congress and industry, “is already advancing to elevate security within the supply chain.”

Testifying to Congress in June, Kari Bingen, the Pentagon's deputy undersecretary for intelligence, said: “We must have confidence that industry is delivering capabilities, technologies and weapon systems that are uncompromised by our adversaries, secure from cradle to grave.”

Security should be seen not as a “cost burden,” she told the House Armed Services Committee, “but as a major factor in their competitiveness for U.S. government business.”

The new strategy is necessary, officials say, because U.S. adversaries can degrade the military's battlefield and technological advantage by using “blended operations” — hacking and stealing valuable data, manipulating software to sabotage command and control systems or cause weapons to fail, and potentially inducing a defense firm employee to insert a faulty component or chip into a system.

“A modern aircraft may have more than 10 million lines of code,” Mitre's report said. “Combat systems of all types increasingly employ sensors, actuators and software-activated control devices.”

The term “Deliver Uncompromised” grew out of a 2010 meeting of senior counterintelligence policy officials, some of whom lamented that the Defense Department was tolerating contractors repeatedly delivering compromised capabilities to the Pentagon and the intelligence community.

Addressing the security issue requires greater participation by counterintelligence agencies, which can detect threats against defense firms, the report said, and ideally, the government should establish a National Supply Chain Intelligence Center to monitor threats and issue warnings to all government agencies.

Ultimately, the military's senior leaders bear responsibility for securing the supply chain and must be held accountable for it, the report said.

The Defense Department, although one of the world's largest equipment purchasers, cannot control all parts of the supplier base. Nonetheless, it has influence over the companies it contracts with as it is the principal source of business for thousands of companies. It can shape behavior through its contracts to enhance supply-chain security, the report said.

Legislation will be needed to provide incentives to defense and other private-sector companies to boost security, Mitre said. Congress should pass laws that shield firms from being sued if they share information about their vulnerabilities that could help protect other firms against cyberattacks; or if they are hacked by a foreign adversary despite using advanced cybersecurity technologies, the report said.

Contractors should be given incentives such as tax breaks to embrace supply chain security, the report suggested.

The Department of Homeland Security is addressing the security of the information technology supply chain through its newly established National Risk Management Center. “What we're saying is you should be looking at what vendors are doing to shore up their cybersecurity practices to protect the supply chain,” said Christopher Krebs, DHS undersecretary for the National Protection and Programs Directorate.

The National Counterintelligence and Security Center, an agency of the Office of the Director of National Intelligence that coordinates the government's counterintelligence strategy, said in a report last month that software-supply-chain infiltration has already threatened critical infrastructure and is poised to endanger other sectors. According to the NCSC, last year “represented a watershed in the reporting of software supply chain” attacks. There were “numerous events involving hackers targeting software supply chains with back doors for cyber espionage, organizational disruption or demonstrable financial impact,” the agency found.

https://www.washingtonpost.com/world/national-security/the-pentagon-is-rethinking-its-multibillion-dollar-relationship-with-us-defense-contractors-to-stress-supply-chain-security/2018/08/12/31d63a06-9a79-11e8-b60b-1c897f17e185_story.html?noredirect=on&utm_term=.265ce85b6eb1

Sur le même sujet

  • These two countries are teaming up to develop AI for cybersecurity

    24 avril 2023 | International, C4ISR

    These two countries are teaming up to develop AI for cybersecurity

    Singapore's Ministry of Defence and France's Ministry of the Armed Forces will jointly develop artificial intelligence capabilities, with potential research areas that include natural language processing.

  • Lockheed’s Raider X enters construction in advance of US Army’s decision on way forward

    21 février 2020 | International, Aérospatial

    Lockheed’s Raider X enters construction in advance of US Army’s decision on way forward

    WEST PALM BEACH, Fla. — Lockheed Martin's Sikorsky is already building its prototype for the U.S. Army's Future Attack Reconnaissance Aircraft competition ahead of the service actually choosing companies to build prototypes. While the Army will select two companies to proceed next month, Lockheed is already using funding as part of its contract to build its Raider X coaxial helicopter, Tim Malia, Sikorsky's FARA director, told a group of reporters Feb. 19 at the company's flight test facility. The Army awarded full-scope contracts to the five teams selected to design FARA; those deals included funding to build aircraft. But when the Army chooses which two teams will move forward, that funding spigot essentially turns off for those that aren't picked. When asked what happens with Raider X, should the Army decides to go with other teams, Malia said: “I don't anticipate that problem.” The five teams that won awards in April 2019 to design FARA were: AVX Aircraft partnered with L3 Technologies; Bell Helicopter; Boeing; a Karem Aircraft, Northrop Grumman and Raytheon team; and Sikorsky. Sikorsky's offering is based on its X2 coaxial technology seen in its S-97 Raider and the Sikorsky-Boeing developed SB-1 Defiant, which are now both flying. The prototype aircraft are expected to start flying in the fourth quarter of fiscal 2022, and the flight test is expected to run through 2023. The engineering and manufacturing development phase is expect to begin in FY24. “This is the culmination of years of investment in the X2 Technology Demonstrator and the S-97 Raider aircraft that have proven the advanced technology and shown its ability to change the future battlefield,” Malia told Defense News when the company first unveiled its design for FARA. FARA is intended to fill a critical capability gap currently being filled by AH-64E Apache attack helicopters teamed with Shadow unmanned aircraft following the retirement of the OH-58D Kiowa Warrior helicopters. The service has tried and failed three times to fill the gap with an aircraft. The Army also plans to buy another helicopter to fill the long-range assault mission, simultaneously replacing some UH-60 Black Hawk helicopters in the fleet. The SB-1 Defiant is a possible candidate for that future aircraft. https://www.defensenews.com/land/2020/02/20/lockheeds-raider-x-already-under-construction/

  • Navy Issues Sikorsky $550.4 Million Modification for 6 CH-53Ks

    29 octobre 2020 | International, Aérospatial, Naval

    Navy Issues Sikorsky $550.4 Million Modification for 6 CH-53Ks

    Mallory Shelbourne This post has been updated to include a new photo of the CH-53K from Sikorsky. The Navy has issued Lockheed Martin-owned Sikorsky a $550.4 million contract modification for the next lot of the Marine Corps' new heavy-lift helicopter. The Navy awarded Sikorsky the funds for six CH-53K King Stallions as part of lot 4 of the program's low-rate initial production phase, according to an Oct. 26 Pentagon contract announcement. “The production of this CH-53K helicopter represents a new era in capabilities, technologies, safety and mission flexibility for the U.S. Marine Corps,” Bill Falk, the CH-53K program director for Sikorsky, said in a statement. “Sikorsky is committed to supporting the Marine Corps to maximize the benefits of this all-new helicopter,” he added. “Pilots are already training on state-of-the art flight training devices to prepare in a safe, cost-effective manner for operational deployment.” The Navy anticipates Sikorsky finishing the work in July 2024, according to the announcement. USNI News previously reported that the Navy restructured the CH-53K test program to address technical deficiencies discovered on the test aircraft. Sikorsky and the Marine Corps announced the two had found a fix to one of the main problems – exhaust gas reingestion – in December 2019. The Navy decreased the number of aircraft it planned to purchase in the Fiscal Year 2021 budget request because it had not yet identified fixes to several technical problems. Lt. Gen. Steven Rudder, the former Deputy Commandant of the Marine Corps for Aviation, told the House Armed Service tactical air and land forces subcommittee earlier this year that the service was ready to increase the rate of production in hopes of bringing cost of the aircraft down. “The higher the numbers, the greater the learning curve from production,” Rudder told the panel of lawmakers at the time. “As we saw with F-35, as we ramp production, the cost curve comes down.” https://news.usni.org/2020/10/27/navy-issues-sikorsky-550-4-million-modification-for-6-ch-53ks

Toutes les nouvelles