26 juin 2024 | International, Sécurité

Practical Guidance For Securing Your Software Supply Chain

Explore key strategies to secure software supply chains effectively amidst rising cyber threats. Learn about SBOMs, SLSA, and DevSecOps best practices

https://thehackernews.com/2024/06/practical-guidance-for-securing-your.html

Sur le même sujet

  • Contract Awards by US Department of Defense - December 10, 2020

    11 décembre 2020 | International, Aérospatial, Naval, Terrestre, C4ISR, Sécurité

    Contract Awards by US Department of Defense - December 10, 2020

    NAVY BAE Systems Land and Armaments L.P., Sterling Heights, Michigan, is awarded an $184,444,865 fixed-price-incentive (firm target) modification to previously awarded contract M67854-16-0006 for amphibious combat vehicles (ACV). This modification provides for the procurement of 36 full rate production ACVs and other associated production costs for the Marine Corps. Work will be performed in York, Pennsylvania (60%); Aiken, South Carolina (15%); San Jose, California (15%); Sterling Heights, Michigan (5%); and Stafford, Virginia (5%). Work is expected to be completed in November 2022. Fiscal 2021 procurement (Marine Corps) funds in the amount of $184,444,865 are being obligated at the time of award, none of which will expire at the end of the current fiscal year. The Marine Corps Systems Command, Quantico, Virginia, is the contracting activity (M67854-16-C-0006). Raytheon Space and Airborne Systems, Marlborough, Massachusetts, is awarded a $91,296,293 modification to a previously awarded Navy multiband terminals (NMT) firm-fixed-price contract to increase the ceiling and extend the engineering support services contract line item numbers to address obsolescence issues and other in-scope engineering service efforts over a three-year period. NMT is a multiband capable satellite communications terminal that provides protected and wideband communications. Work will be performed in Largo, Florida (54%); South Deerfield, Massachusetts (25%); Stow, Massachusetts (13%); Marlborough, Massachusetts (8%), and is expected to be completed by December 2023. No funds were obligated at the issuance of this contract modification. This sole-source contract was not competitively procured in accordance with 10 U.S. Code 2304(c)(1). The Naval Information Warfare Systems Command, San Diego, California, is the contracting activity (N00039-16-C-0050). Raytheon Missiles and Defense, Marlborough, Massachusetts, is awarded a $38,786,218 firm-fixed-price and cost-plus-fixed-fee modification to previously awarded contract N00024-19-C-5112 for the production of two Fire Control System MK 99 ship sets and the associated technical engineering services in support of the Aegis Combat System on DDG-51 class ships. Work will be performed in Andover, Massachusetts (81%); Marlborough, Massachusetts (10%); Chesapeake, Virginia (3%); Portsmouth, Rhode Island (3%); San Diego, California (2%); and Burlington, Massachusetts (1%), and is expected to be completed by August 2024. Fiscal 2020 shipbuilding and conversion (Navy) funds in the amount of $38,786,218 will be obligated at the time of award and will not expire at the end of the current fiscal year. The Naval Sea Systems Command, Washington, D.C., is the contracting activity. Pacific Architects and Engineers Applied Technologies LLC, Fort Worth, Texas, is awarded a $30,969,685 cost-plus-fixed-fee, cost reimbursable contract. This contract provides for the procurement of various types of support including system operations, laboratory and field testing, marine operations and target support services, engineering, range sustainability, maintenance, data reduction and analysis. Work will be performed in Patuxent River, Maryland, and is expected to be completed in April 2021. Fiscal 2021 research, development, test and evaluation (Navy) funds in the amount of $9,957,500; and fiscal 2021 working capital (Navy) funds in the amount of $501,000 will be obligated at time of award, $501,000 of which will expire at the end of the current fiscal year. This contract was not competitively procured pursuant to 10 U.S. Code 2304(c)(1). The Naval Air Warfare Center Aircraft Division, Patuxent River, Maryland, is the contracting activity (N00421-21-C-0011). DCS Corp., Alexandria, Virginia, is awarded a $27,750,407 cost-plus-fixed-fee, cost-reimbursable, indefinite-delivery/indefinite-quantity contract. This contract provides for design, development, integration, test, evaluation, installation, maintenance, configuration management and logistics in support of the Air Traffic Control and Landing Systems Division systems and equipment. Work will be performed in Saint Inigoes, Maryland (80%); and Lexington Park, Maryland (20%), and is expected to be completed in December 2025. No funds will be obligated at the time of award. Funds will be obligated on individual orders as they are issued. This contract was competitively procured via an electronic request for proposal; one offer was received. The Naval Air Warfare Command Aircraft Division, Patuxent River, Maryland, is the contracting activity (N00421-21-D-0011). Fincantieri Marine Systems North America Inc., Chesapeake, Virginia, is awarded a $13,343,620 modification to exercise Option Year Four of previously awarded firm-fixed price, indefinite-delivery/indefinite-quantity contract N55236-17-D-0009 to provide maintenance support for the Mine Countermeasure-1 Class main propulsion diesel engine and ship service diesel generator. The overall total contract value ceiling remains unchanged at $86,268,629. Work will be performed in the homeports of Sasebo, Japan; and Manama, Bahrain, and ports-of-call as required according to individual task orders, and is scheduled to be completed by January 2022. No funding is being obligated at time of award. The Southwest Regional Maintenance Center, San Diego, California, is the contracting activity. U.S. SPECIAL OPERATIONS COMMAND Raytheon Technologies, McKinney, Texas (H92408-21-D-0001), was awarded a $99,000,000 cost-plus-fixed-fee, firm-fixed-price, time and materials, cost reimbursement, no-fee contract for the procurement of Next-Generation Special Mission Processors (NextGen SMP) in support of U.S. Special Operations Command (USSOCOM) requirements. NextGen SMP enable Special Operations Forces tactical mission systems to integrate with AC/MC-130J aircraft controls and provide future software capabilities. Fiscal 2021 research, development, test and evaluation funds in the amount of $1,692,070; and procurement funds in the amount of $8,245,404 are being obligated at time of award. The work is expected to be completed by December 2027. This action is a follow-on production contract in accordance with 10 U.S. Code § 2371b (f) authorized or required by statue. USSOCOM, Tampa, Florida, is the contracting activity. AIR FORCE Northrop Grumman Systems Corp., Hill Air Force Base, Utah, has been awarded a $73,194,742 firm-fixed-price delivery order under the Ground Subsystems Sustainment contract FA8214-15-D-0001 for Remote Visual Assessment II production and deployment for the Minutemen III. This delivery order provides for modification to the Remote Visual Assessment program by adding six capabilities to procure, produce, remove, install, audit, test and document the equipment. Work will be performed at Malmstrom Air Force Base, Montana; Minot AFB, North Dakota; and F.E. Warren AFB, Wyoming, and is expected to be completed July 31, 2023. This award is the result of a sole-source acquisition. Fiscal 2020 missile procurement funds in the amount of $1,140,137 are being obligated at the time of award. The Air Force Nuclear Weapons Center, Hill AFB, Utah, is the contracting activity (FA8214-21-F-0078). DEFENSE LOGISTICS AGENCY Ortho-Clinical Diagnostics Inc., Raritan, New Jersey, has been awarded a maximum $49,500,000 fixed-price with economic-price-adjustment, indefinite-delivery/indefinite-quantity contract for laboratory supplies and wares. This was a competitive acquisition with one response received. This is a five-year contract with no option periods. Location of performance is New Jersey, with a Dec. 9, 2025, ordering period end date. Using customers are Army, Navy, Air Force, Marine Corps and federal civilian agencies. Type of appropriation is fiscal 2021 through 2026 defense working capital funds. The contracting activity is the Defense Logistics Agency Troop Support, Philadelphia, Pennsylvania (SPE2DE-21-D-0007). ARMY ORBCOMM Inc., Rochelle Park, New Jersey, was awarded a $45,611,528 firm-fixed-price contract for next-generation transponders. Bids were solicited via the internet with five received. Work locations and funding will be determined with each order, with an estimated completion date of Dec. 9, 2024. The U.S. Army Contracting Command, Rock Island Arsenal, Illinois, is the contracting activity (W52P1J-21-D-0007). RiverRestoration LLC,* Carbondale, Colorado, was awarded a $40,000,000 firm-fixed-price contract for civil works and hydrology and hydraulics services. Bids were solicited via the internet with 15 received. Work locations and funding will be determined with each order, with an estimated completion date of Dec. 10, 2025. The U.S. Army Corps of Engineers, Albuquerque, New Mexico, is the contracting activity (W912PP-21-D-0002). Direct Steel and Construction,* Crystal Lake, Illinois, was awarded a $16,880,228 firm-fixed-price contract for construction of the 69th ADA Supply Support Activity warehouse at Fort Hood. Bids were solicited via the internet with three received. Work will be performed at Fort Hood, Texas, with an estimated completion date of June 15, 2022. Fiscal 2018 military construction (Army) funds in the amount of $16,880,228 were obligated at the time of the award. The U.S. Army Corps of Engineers, Fort Worth, Texas, is the contracting activity (W9126G-21-C-0003). The Boeing Co., Mesa, Arizona, was awarded a $13,900,000 modification (P00066) to contract W58RGZ-16-C-0023 for software upgrades to the flight management computer for the AH-64E. Work will be performed in Mesa, Arizona, with an estimated completion date of Dec. 31, 2024. Fiscal 2020 aircraft procurement (Army) funds in the amount of $2,780,000 were obligated at the time of the award. The U.S. Army Contracting Command, Redstone Arsenal, Alabama, is the contracting activity. General Dynamics Information Technology Inc., Falls Church, Virginia, was awarded a $12,432,932 modification (P00017) to contract W81K04-18-C-0001 for specialty medical training, equipment/site maintenance and administration support services. Work will be performed in Dublin, California; Fort Gordon, Georgia; and Fort McCoy, Wisconsin, with an estimated completion date of Dec. 31, 2021. Fiscal 2021 and 2022 operation and maintenance (Army Reserve) funds in the amount of $12,432,932 were obligated at the time of the award. The U.S. Army Health Contracting Activity, San Antonio, Texas, is the contracting activity. Lockheed Martin Corp., Orlando, Florida, was awarded a $10,395,412 modification (P00044) to contract W31P4Q-19-C-0071 for engineering services in support of the Hellfire Missile and Joint-Air-to-Ground Missile. Work will be performed in Orlando, Florida, with an estimated completion date of May 9, 2022. Fiscal 2020 and 2021 missile procurement (Army); 2021 research, development, test and evaluation (Navy); and 2020 missile procurement (Air Force) funds in the amount of $10,395,412 were obligated at the time of the award. The U.S. Army Contracting Command, Redstone Arsenal, Alabama, is the contracting activity. WASHINGTON HEADQUARTERS SERVICES Millennium Enterprises, doing business as Millennium Health and Fitness Inc., Scottsdale, Arizona (HQ0034-21-D-0005), is awarded an indefinite-delivery/indefinitely-quantify contract with a maximum amount of $25,000,000. The Defense Civilian Personnel Advisory Service (DCPAS) has a requirement to procure wellness and health promotion support services. The principal objective is for the contractor to provide the necessary staff to operate and manage Department of Defense wellness fitness centers, as well as agency specific programs and services to meet customer needs. The contractor shall provide all personnel, equipment, supplies, facilities, transportation, tools, materials, supervision and other items and non-personal services necessary to perform wellness and health promotion services in support of DCPAS. Work performance will take place in the Northern Capital Region, including Arlington, Virginia; Crystal City, Virginia; and Washington, D.C. No funds will be obligated at time of the award. Appropriate fiscal operations and maintenance funds will be obligated on all subsequent task orders. The expected completion date is Dec. 9, 2025. Washington Headquarters Services, Arlington, Virginia, is the contracting activity. DEFENSE FINANCE AND ACCOUNTING SERVICE Kearney and Company PC, Alexandria, Virginia, is being awarded a labor-hour contract option with a maximum value of $10,160,250 for audit services of the Defense Health Program (DHP). Work will be performed in various locations including the DHP headquarters, Falls Church, Virginia, as well as other federal locations in Texas, Ohio, Indianapolis, Maryland, Colorado, New York and Maine, with an expected completion date of Dec. 31, 2021. This contract is the result of a competitive acquisition in which two bids were received. This award brings the total cumulative value of the contract to $46,758,510. Fiscal 2021 operation and maintenance (Defense-wide) funds in the amount of $10,160,250 are being obligated at the time of this option award. The Defense Finance and Accounting Service, Contract Services Directorate, Columbus, Ohio, is the contracting activity (HQ0423-17-F-0096). DEFENSE ADVANCED RESEARCH PROJECTS AGENCY Battelle Memorial Institute, Columbus, Ohio, has been awarded a $9,472,919 cost-plus-fixed-fee contract for Defense Advanced Research Projects Agency's Rational Integrated Design of Energetics (RIDE) program. In Phase One, Battelle Memorial Institute proposes to develop a semi-automated system in order to provide an energetics formulation platform that addresses both powder-pressed and cast-cured formulations for explosives and propellants in support of the RIDE program. Work will be in Columbus, Ohio (25%); West Jefferson, Ohio (55%); and Centerbrook, Connecticut (20%), with an estimated completion date of March 2022. Fiscal 2020 and 2021 research, development, test and evaluation funds in the amount of $5,658,142 are being obligated at time of award. The Defense Advanced Research Projects Agency, Arlington, Virginia, is the contracting activity (HR0011-21-C-0027). *Small business https://www.defense.gov/Newsroom/Contracts/Contract/Article/2443378/source/GovDelivery/

  • Indian Air Force restructures $17 billion fighter jet program

    22 mai 2020 | International, Aérospatial

    Indian Air Force restructures $17 billion fighter jet program

    By: Vivek Raghuvanshi NEW DELHI — The Indian Air Force is overhauling its plan to induct 114 medium-weight multirole fighters, with a senior service official saying the aircraft will be built in India with significant foreign technology transfer and no foreign procurement. The effort will cost about $17 billion under the Make in India economic policy. The Air Force official said the project is very much alive, but that the “final nitty-gritties have yet to be worked out, and that will take time because it will require manufacturing capability building in the country.” Daljit Singh, a retired Indian Air Force air marshal and current defense analyst, agreed that India must move quickly to create the capability to manufacture high-tech systems at home. “The main aim should be to extract the maximum [transfer of technology] from the OEM [original equipment manufacturer] and start manufacturing subcomponents through Indian companies," Singh said. Finance Minister Nirmala Sitharaman announced Saturday that the government will create a separate budget for domestic procurement of weapons and equipment to help reduce the imports bill. A Ministry of Defence official said a formal budget allocation of about $17 billion for the multirole fighters project will be granted sometime next year, and will be launched under the Strategic Partners procurement policy. Under that policy, the multirole fighters will be manufactured by domestic private defense companies with one of the original equipment manufacturers approved by the government. The process for selecting contractors is yet to begin, but the MoD official said the businesses will be selected within three years. No private defense company in India has made fighter jets before, but several have expressed interest in participating in the program, including Tata Advanced Systems, Adani Defence, Reliance Defence, Mahindra Defence and Bharat Forge Limited. Reliance Defence has created a joint venture with France's Dassault Aviation, which currently manufactures components for Rafale fighters. Meanwhile, Tata Advanced Systems has teamed with Lockheed Martin, an American company that produces the F-35 Joint Strike Fighter. Adani Defence has announced a teaming arrangement Sweden's Saab AB, which makes the Gripen jet. Another Indian Air Force official said a request for information was sent in June 2018 to foreign original equipment manufacturers for the multirole fighters. Among those who have responded to the RFI are: Boeing, Lockheed Martin, Dassault Aviation, Saab AB, Airbus Defence and Space, Russian Aircraft Corporation, and Sukhoi Company. The Indian Air Force plans to induct all 114 multirole fighters within 12 years after the contract is awarded. The official added that the RFI included the requirement for transfer of technology, including the transfer of design, development, manufacturing and repair expertise. It also included the requirement for the unilateral capability to integrate weapons, systems and sensors. The capability to upgrade the aircraft and a provision on exporting the aircraft is also part of the program. India is also seeking transfer of technology for stealth technology, active electronically scanned array radars, avionics, electronic warfare systems and engines. “The advantage of making a fighter aircraft in India is that the customer can select the types of sensors, EW equipment, avionics and weapons, as per operational requirements. Subsequently, the customer is assured of full logistic and upgrade support without any restriction. However, it is important to embed most of these systems in the aircraft design itself to ensure low observability and systems compatibility,” he said. However, Singh, the defense analyst, said any transfer of technology agreement would need to make business sense to the OEM. “Propriety Items could still be under the control of the OEM,” he said. https://www.defensenews.com/global/asia-pacific/2020/05/21/indian-air-force-restructures-17-billion-fighter-jet-program/

  • LEONARDO TO LEAD OCEAN2020 PROGRAM, THE FIRST AND MOST IMPORTANT EUROPEAN DEFENCE AGENCY RESEARCH TENDER FOR NAVAL SURVEILLANCE TECHNOLOGY

    16 février 2018 | International, Aérospatial, Naval, C4ISR

    LEONARDO TO LEAD OCEAN2020 PROGRAM, THE FIRST AND MOST IMPORTANT EUROPEAN DEFENCE AGENCY RESEARCH TENDER FOR NAVAL SURVEILLANCE TECHNOLOGY

    OCEAN2020, a European Defence Fund initiative, will boost technological research in the naval domain also by the integration of unmanned platforms in surveillance and interdiction missions Leonardo is a leader in systems integration and will lead a team of 42 partner companies including Saab, Safran, PGZ and MBDA, research bodies such as NATO CMRE and the defence ministries of five countries The first operational demonstration will take place in 2019 in the Mediterranean Sea. The demo will involve Leonardo's ‘Hero' and ‘Solo' unmanned helicopters, naval vessels and systems from a number of partners, including Italian Navy's vessels equipped with Leonardo's systems Leonardo was awarded the most important project related to the first European Defence Found's initiative, OCEAN2020, to boost Europe's defence capabilities, issued by the European Union under the ‘Preparatory Action on Defence Research' programme. The competitive selection was conducted by the European Defence Agency and will be contracted in the coming weeks. The OCEAN2020 team, which will be led by Leonardo, comprises 42 partners from 15 European countries. These include the Ministries of Defence of Italy, Greece, Spain, Portugal and Lithuania, with additional support from the Ministries of Defence of Sweden, France, the United Kingdom and Estonia and the Netherlands. European industrial partners include Indra, Safran, Saab, MBDA, PGZ/CTM, Hensoldt, Intracom-IDE, Fincantieri and QinetiQ. A number of research centres include Fraunhofer, TNO, CMRE (NATO) and IAI. “We are extremely pleased with this result, the OCEAN2020 initiative has a high level of strategic and technological-operational value” said Alessandro Profumo, CEO of Leonardo. “It is the leading technological research project dedicated to the very topical issue of maritime surveillance, which is of interest across Europe and to the Mediterranean region in particular. This success has been made possible thanks to the strong collaboration between all 42 team partners which we have the honour to lead.” OCEAN2020 is the first example of a cross-European military research programme to-date. The Leonardo-led bid required a thorough analysis of operational requirements and a technologically-innovative yet operationally-realistic proposal. The research project also will see the integration of unmanned platforms in surveillance and interdiction missions. The success in winning the tender both highlights, and will enhance, Leonardo's strength in naval products and integrated systems. The company's expertise in the domain includes command and control systems, unmanned aircraft, sensors, helicopters for naval applications, communications and weapon systems, on the surface and underwater. OCEAN2020 will see unmanned platforms of different type (fixed wing, rotary wing, surface and underwater) integrated with naval units' command and control centres, allowing for data exchange via satellite, with command and control centres on land. The joint and cooperative use of both manned and unmanned vehicles will also be demonstrated as part of the project. Leonardo would like to thank the Italian Navy which, as a key OCEAN2020 partner, has and will continue to make important contributions to the project. This includes the development of operational scenarios and making available naval assets and helicopters, which will take part in demonstrations. In addition to complex simulation work, OCEAN2020 project will involve two live demonstrations of maritime surveillance and interdiction operations, conducted by European fleets using unmanned aircraft, surface vessels and underwater systems. The first demo, scheduled to take place in the Mediterranean Sea in 2019, will be coordinated by the Italian Navy and will see Leonardo's ‘Hero' and ‘Solo' unmanned helicopters operate from Italian naval units alongside other European partners. The second demonstration, which will take place in 2020 in the Baltic Sea, will be coordinated by the Swedish Navy. The data collected by various systems during these two demos will be processed and sent to a prototype European command and control centre in Brussels. http://www.leonardocompany.com/en/-/ocean-2020

Toutes les nouvelles