30 septembre 2020 | International, C4ISR, Sécurité

The DoD needs data-centric security, and here’s why

Drew Schnabel

The U.S. Department of Defense is set to adopt an initial zero-trust architecture by the end of the calendar year, transitioning from a network-centric to a data-centric modern security model.

Zero trust means an organization does not inherently trust any user. Trust must be continually assessed and granted in a granular fashion. This allows defense agencies to create policies that provide secure access for users connecting from any device, in any location.

“This paradigm shift from a network-centric to a data-centric security model will affect every arena of our cyber domain, focusing first on how to protect our data and critical resources and then secondarily on our networks,” Vice Adm. Nancy Norton, director of the Defense Information Systems Agency and commander of the Joint Force Headquarters-Department of Defense Information Network, said at a virtual conference in July.

How does the Pentagon's AI center plan to give the military a battlefield advantage?

The Pentagon's artificial intelligence hub is working on tools to help in joint, all-domain operations as department leaders seek to use data to gain an advantage on the battlefield.

Andrew Eversden

To understand how the DoD will benefit from this new zero-trust security model, it's important to understand the department's current Joint Information Environment, or JIE, architecture; the initial intent of this model; and why the JIE can't fully protect modern networks, mobile users and advanced threats.

Evolving DoD information security

The JIE framework was developed to address inefficiencies of siloed architectures. The goal of developing a single security architecture, or SSA, with JIE was to collapse network security boundaries, reduce the department's external attack surface and standardize management operations. This framework helped ensure that defense agencies and mission partners could share information securely while reducing required maintenance and continued infrastructure expenditures.

Previously, there were more than 190 agency security stacks located at the base/post/camp/station around the globe. Now, with the JIE architecture, there are just 22 security stacks centrally managed by the Defense Information Systems Agency to provide consistent security for users, regardless of location.

“This paradigm shift from a network-centric to a data-centric security model will affect every arena of our cyber domain, focusing first on how to protect our data and critical resources and then secondarily on our networks,” Vice Adm. Nancy Norton, director of the Defense Information Systems Agency and commander of the Joint Force Headquarters-Department of Defense Information Network, said at a virtual conference in July.

To understand how the DoD will benefit from this new zero-trust security model, it's important to understand the department's current Joint Information Environment, or JIE, architecture; the initial intent of this model; and why the JIE can't fully protect modern networks, mobile users and advanced threats.

Evolving DoD information security

The JIE framework was developed to address inefficiencies of siloed architectures. The goal of developing a single security architecture, or SSA, with JIE was to collapse network security boundaries, reduce the department's external attack surface and standardize management operations. This framework helped ensure that defense agencies and mission partners could share information securely while reducing required maintenance and continued infrastructure expenditures.

Previously, there were more than 190 agency security stacks located at the base/post/camp/station around the globe. Now, with the JIE architecture, there are just 22 security stacks centrally managed by the Defense Information Systems Agency to provide consistent security for users, regardless of location.

Initially, the JIE was an innovative concept that took the DoD from a highly fragmented architecture, in which each agency managed its own cybersecurity strategy, to an architecture in which there is a unified SSA.

However, one of the early challenges identified for the JIE was managing cloud cybersecurity as part of the SSA. The components in the JIE — the Joint Regional Security Stacks family's internet access points and cloud access points — have traditionally focused on securing the network, rather than the data or user.

As more DoD employees and contractors work remotely and data volumes increase, hardware cannot scale to support them. This has created ongoing concerns with performance, reliability, latency and cost.

A cloud-first approach

In response, the DoD leverages authorized solutions from the Federal Risk and Authorization Management Program, and it references the Secure Cloud Computing Architecture guidance for a standard approach for boundary and application-level security for impact Level 4 and 5 data hosted in commercial cloud environments.

The purpose of the SCCA is to provide a barrier of protection between the DoD Information Services Network and the commercial cloud services that the DoD uses while optimizing the cost-performance trade in cybersecurity.

Defense agencies are now exploring enterprise-IT-as-a-service options to move to cloud, and reduce the need for constant updates and management of hardware. Through enterprise-IT-as-a-service models, defense agencies will be able to scale easily, reduce management costs and achieve a more competitive edge over their adversaries.

Before the pandemic hit, defense agencies were already moving to support a more mobile workforce, where employees can access data from anywhere on any device. However, a cyber-centric military requires security to be more deeply ingrained into employee culture rather than physical protection of the perimeter.

The next evolution to secure DISA and DoD networks is to embrace a secure access edge model with zero-trust capabilities. The SASE model moves essential security functions — such as web gateway firewalls, zero-trust capabilities, data loss prevention and secure network connectivity — all to the cloud. Then, federal employees have direct access to the cloud, while security is pushed as close to the user/data/device as possible.

SP 800-27, zero-trust guidance from the National Institute of Standards and Technology, provides a road map to migrate and deploy zero trust across the enterprise environment. This guidance outlines the necessary tenants of zero trust, including securing all communication regardless of network location, and granting access on a per-session basis. This creates a least-privilege-access model to ensure the right person, device and service have access to the data they need while protecting high-value assets.

As the DoD transforms the JIE architecture to an as-a-service model with zero-trust capabilities, defense agencies will experience cost savings, greater scalability, better performance for the end user and war fighter, improved visibility, and control across DoD networks — and ultimately a stronger and more holistic cybersecurity capability moving forward.

https://www.c4isrnet.com/opinion/2020/09/29/the-dod-needs-data-centric-security-and-heres-why/

Sur le même sujet

  • Airbus Helicopters poursuit la militarisation du H160 et du soutien associé

    7 février 2020 | International, Aérospatial

    Airbus Helicopters poursuit la militarisation du H160 et du soutien associé

    Airbus Helicopters et la Direction Générale de l'Armement (DGA) s'engagent sur des études complémentaires pour la militarisation du H160 et du soutien associé, dans le cadre du programme d'Hélicoptère Interarmées Léger (HIL). Ce marché va permettre le lancement des activités de développement préliminaires de la version militaire du H160, aussi connue sous le nom de Guépard, afin de tenir le calendrier de livraison accéléré annoncé en mai 2019 par la Ministre des armées, Florence Parly. Ces études complémentaires comporteront également un volet visant à définir le modèle optimal du soutien pour cette flotte interarmées. Airbus Helicopters, Safran Helicopter Engines et la DGA travailleront en étroite collaboration avec pour objectif de maximiser le taux de disponibilité des hélicoptères tout en optimisant les coûts de soutien de la flotte. « Le lancement dès la phase de pré-développement de ce travail collaboratif entre l'industriel et le ministère des armées pour définir le modèle de soutien du Guépard et les processus associés est essentiel. Cela permettra de garantir un taux de disponibilité élevé dès son entrée en service au sein des forces armées » a déclaré Alexandra Cros, Directrice des Affaires Gouvernementales France d'Airbus Helicopters. « Ces études s'inscrivent dans la continuité des travaux et des engagements pris récemment dans les contrats « verticalisés » pour les flottes Cougar, Caracal et Tigre des armées françaises ». Hélicoptère modulaire par conception, le Guépard permettra de couvrir avec une plateforme unique des missions allant de l'infiltration de commandos à la lutte antinavire, en passant par l'interception aérienne et l'appui-feu, répondant ainsi aux besoins de l'armée de Terre, de la Marine Nationale et de l'Armée de l'air dans le cadre du programme HIL. Le lancement du HIL anticipé en 2021 permettra de livrer les premiers hélicoptères à l'armée française dès 2026. https://www.air-cosmos.com/article/airbus-helicopters-poursuit-la-militarisation-du-h160-et-du-soutien-associ-22521

  • Contract Awards by US Department of Defense - December 3, 2018

    7 décembre 2018 | International, Aérospatial, Naval, Terrestre, C4ISR, Sécurité

    Contract Awards by US Department of Defense - December 3, 2018

    NAVY The Navy is awarding 1,870 indefinite-delivery/indefinite-quantity, multiple-award contracts (MACs) to businesses in multiple locations across 46 of the 50 United States, the District of Columbia, and Guam for future competition of support service requirements to be solicited by Department of the Navy activities under the SeaPort Next Generation (SeaPort-NxG) multiple-award contract vehicle. All work under the contracts will fall under two categories (engineering support services and program management support services), which are further divided into 23 functional areas. The government estimates approximately $5,000,000,000 of services will be procured per year via orders issued under the SeaPort-NxG multiple award contracts. These awards contain provisions to set aside requirements for small businesses, service-disabled veteran-owned small businesses, 8(a) business development program participants, woman-owned small businesses and historically-underutilized business-zoned small businesses. Under these multiple-award contracts, each contractor will be provided a fair opportunity to nationally compete for individual task orders. The MACs have a five-year base period of performance with an additional five-year ordering period option. No contract funds will be obligated on the basic MAC awards. Contract funds will be obligated at time of task order award. Multiple funding types may be used. The funding for task orders to be issued under these contracts will come from a variety of sources and will be consistent with the purpose for which the funds were appropriated. These contracts were competitively procured via the Federal Business Opportunities website, with 1,894 offers received. The Naval Sea Systems Command, Naval Surface Warfare Center, Dahlgren Division, Dahlgren, Virginia is the contracting activity (N00178-18-R-7000). NOTE: For a list of contractors receiving awards please visit: https://www.navsea.navy.mil/Portals/103/Documents/Small_Business_Forum/SeaPort%20NxG%20Awardees%20List.pdf?ver=2018-11-28-123322-177 Austal USA, Mobile, Alabama, is awarded a $40,369,095 cost-plus-fixed-fee undefinitized contract action for procurement of long lead time material and production engineering for the Expeditionary Fast Transport (EPF) 14. The EPF class provides high speed, shallow draft transportation capability to support the intra-theater maneuver of personnel, supplies and equipment for the Navy, Marine Corps, and Army. Work will be performed in Novi, Michigan (39 percent); Houston, Texas (12 percent); Chesapeake, Virginia (10 percent); Mobile, Alabama (9 percent); Rhinelander, Wisconsin (7 percent); and Iron Mountain, Michigan (3 percent), with other efforts performed at various locations (each less than 1 percent) throughout the U.S. (4 percent); and various locations (each less than 1 percent) outside the U.S. (16 percent), and is expected to complete by July 2022. Fiscal 2019 shipbuilding and conversion (Navy) funding in the amount of $20,184,547 will be obligated at time of award and will not expire at the end of the current fiscal year. This contract was competitively solicited via Federal Business Opportunities website, with one offer received. The Naval Sea Systems Command, District of Columbia, is the contracting activity (N00024-19-C-2227). The Concourse Group, LLC,* Annapolis, Maryland, is awarded a maximum amount $29,000,000 indefinite-delivery/indefinite-quantity contract for professional services in support of the Department of Navy's (DoN) Public Private Venture (PPV) and Real Estate (RE) Programs. The work to be performed will require the contractor to bring professional knowledge, skills, and experience in residential and commercial real estate development and large scale real estate portfolio management to the DoN's PPV and RE programs. The contractor shall provide advice and assistance to the DoN and conduct the necessary research and analysis to present DoN decision-makers with accurate and relevant information. The contractor will bring best business practices from the private sector to assist the DoN with all aspects of the special venture acquisitions, including family and unaccompanied housing public private ventures, enhanced use leasing, and other public-private venture opportunities such as energy, utilities, and lodging, as well as real estate. The work includes technical advisory services to the Naval Facilities Engineering Command (NAVFAC) Headquarters Special Venture Acquisition Office and the NAVFAC component commands for the purpose of providing professional services, project development, execution, portfolio management advice and support consistent with the privatization approach adopted by the DoN, as well as technical advisory services to the NAVFAC RE. Work will be performed in Annapolis, Maryland. The term of the contract is not to exceed 36 months, with an expected completion date of November 2021. Fiscal 2019 operations and maintenance (Navy) contract funds in the amount of $10,000 are obligated on this award and will expire at the end of the current fiscal year. No task orders are being issued at this time. Future task orders will be primarily funded by operations and maintenance (Navy); and family housing, (Navy), operations and maintenance. This contract was competitively procured via the Navy Electronic Commerce Online website, with four proposals received. The Naval Facilities Engineering Command, Atlantic, Norfolk, Virginia, is the contracting activity (N62470-19-D-8008). Northrop Grumman Systems Corp., Military Aircraft Systems, Melbourne, Florida, is awarded $20,987,258 for firm-fixed-price modification P00002 to a previously issued order (N0001918F2334) placed against basic ordering agreement N00019-15-G-0026. This order provides for the installation of aerial refueling retrofit kits on four E-2D Advanced Hawkeye aircraft. Work will be performed in St. Augustine, Florida, and is expected to be completed in June 2020. Fiscal 2019 aircraft procurement (Navy) funds in the amount of $20,987,258 are being obligated on this award, none of which will expire at the end of the current fiscal year. The Naval Air Systems Command, Patuxent River, Maryland, is the contracting activity. The Boeing Co., St. Louis, Missouri, was awarded $10,526,671 for modification P00002 to delivery order N0001918F0520 previously placed against basic ordering agreement N00019-16-G-0001. This modification exercises an option to provide calendar year 2019 Harpoon/SLAM-ER integrated logistics and engineering support services for Navy and Foreign Military Sales (FMS) customers. Work will be performed in St. Charles, Missouri (91.84 percent); St. Louis, Missouri (5.47 percent); Yorktown, Virginia (2.64 percent); and Oklahoma City, Oklahoma (0.05 percent), and is expected to be completed in November 2019. Fiscal 2019 operations and maintenance (Navy); and FMS funds in the amount of $10,526,671 will be obligated at time of award, $2,530,961 of which will expire at the end of the current fiscal year. This modification combines purchases for the Navy ($2,530,961; 24 percent); and FMS ($7,995,710; 76 percent). The Naval Air Systems Command, Patuxent River, Maryland, is the contracting activity. (Awarded Nov. 29, 2018) The Boeing Co., St. Louis, Missouri, was awarded $10,526,671 for modification P00002 to delivery order N0001918F0520 previously placed against basic ordering agreement N00019-16-G-0001. This modification exercises an option to provide calendar year 2019 Harpoon/SLAM-ER integrated logistics and engineering support services for Navy and Foreign Military Sales (FMS) customers. Work will be performed in St. Charles, Missouri (91.84 percent); St. Louis, Missouri (5.47 percent); Yorktown, Virginia (2.64 percent); and Oklahoma City, Oklahoma (0.05 percent), and is expected to be completed in November 2019. Fiscal 2019 operations and maintenance (Navy); and FMS funds in the amount of $10,526,671 will be obligated at time of award, $2,530,961 of which will expire at the end of the current fiscal year. This modification combines purchases for the Navy ($2,530,961; 24 percent); and FMS ($7,995,710; 76 percent). The Naval Air Systems Command, Patuxent River, Maryland, is the contracting activity. (Awarded Nov. 29, 2018) MTU America Inc. (formerly known as Tognum America Inc.), Novi, Michigan, is awarded $7,946,893 for sole-source firm-fixed-price, delivery order N0002419FB028 under previously awarded basic purchase agreement N00024-14-A-4101 to provide the government of Israel with MTU engines and engine components to support the Israeli marine vessels under Foreign Military Sales (FMS) case IS-P-GPB involving FMS to Israel. MTU engines and engine components will be applicable but not limited to the following MTU engine series: M90, M94, TB54, TB82, TB93, TB94, TE83, TE94, and SE84. Work will be performed in Brownstown Township, Michigan, and is expected to be completed by September 2019. Fiscal 2018 FMS funding in the amount of $7,946,893 will be obligated at time of award and will not expire at the end of the current fiscal year. This contract was not competitively procured, in accordance with 10 U.S. Code 2304(c)(4) (international agreement). The Naval Sea Systems Command, Washington, District of Columbia, is the contracting activity. DEFENSE ADVANCED RESEARCH PROJECTS AGENCY Raytheon Co. Missile Systems, Tucson, Arizona, was awarded a $51,895,419 cost-plus-fixed-fee completion contract for a Defense Advanced Research Projects Agency (DARPA) research project. Work will be performed in Tucson, Arizona (78 percent); McKinney, Texas (12 percent); Tewksbury, Massachusetts (5 percent); Richardson, Texas (2 percent); Huntington Beach, California (1 percent); and Ontario, New York (2 percent), with an expected completion date of December 2021. Fiscal 2019 research, development, test and evaluation funds in the amount of $3,242,000 are being obligated at time of award. This contract was a sole-source acquisition. DARPA, Arlington, Virginia, is the contracting activity (HR0011-19-C-0008). U.S. TRANSPORTATION COMMAND Farrell Lines Inc., Reston, Virginia, has been awarded a one-time only task order under indefinite-delivery/indefinite-quantity contract HTC711-15-D-R044 in the amount of $15,747,387. This task order provides cargo transportation services support to the Surface Deployment and Distribution Command, U.S. Army. The task order is in support of an Army unit deployment from Fort Bliss, Texas, to multiple forward operating bases in Afghanistan. Work will be performed in the U.S. and Afghanistan. The period of performance is from Dec. 3, 2018, to Feb. 11, 2019. Fiscal 2019 Transportation Working Capital Funds were obligated at award. This modification brings the total cumulative face value of the contract to $150,886,391 from $135,139,004. U.S. Transportation Command, Directorate of Acquisition, Scott Air Force Base, Illinois, is the contracting activity. DEFENSE LOGISTICS AGENCY Centron Industries Inc.,* Gardena, California, has been awarded a maximum $13,908,602 firm-fixed-price with economic-price-adjustment, indefinite-quantity contract for cables and lighting products. This was a competitive acquisition and three offers were received. This is a three-year base contract, with one two-year option period. Location of performance is California, with a Nov. 25, 2021, performance completion date. Using military services are Army, Air Force, Navy, and Marine Corps. The type of appropriation is fiscal 2019 through 2021 defense working capital funds. The contracting activity is Defense Logistics Agency Aviation, Richmond, Virginia (SPE4AX-19-D-0005). AIR FORCE Utah State University Research Foundation/Space Dynamic Laboratory, North Logan, Utah, has been awarded an $11,477,222 cost-plus-fixed-fee task order (FA9453-19-F-0013) to previously awarded contract FA9453-16-D-0004 for a small satellite utility demonstration. The contractor will provide necessary research and development to maintain essential engineering, research and development capability in the areas of sensor development, image processing and data analysis. Work will be performed at North Logan, Utah, and is expected to be completed by March 14, 2023. This award is the result of a sole-source acquisition. Fiscal 2018 research, development, test, and evaluation funds in the amount of $557,437 are being obligated at the time of award. Air Force Research Laboratory, Kirtland Air Force Base, New Mexico, is the contracting activity. (Awarded Nov. 30, 2018) ARMY General Dynamics Land Systems Inc., Sterling Heights, Michigan, was awarded a $9,430,158 modification (P00007) to contract W56HZV-17-C-0108 to install sensors on doors, build wire harness assemblies, and package all components as part of the Single Channel Ground and Airborne Radio System adapter kits, return sliding ramp assembly material for the vehicles and procure additional drop out factor material items on the Abrams SEPv3 45/60 vehicle production. Work will be performed in Lima, Ohio, with an estimated completion date of Aug. 30, 2019. Fiscal 2018 other procurement, Army funds in the amount of $9,430,158 were obligated at the time of the award. U.S. Army Contracting Command, Warren, Michigan, is the contracting activity. *Small business https://dod.defense.gov/News/Contracts/Contract-View/Article/1704107/source/GovDelivery/

  • Meggitt expands involvement in KFX programme

    11 septembre 2018 | International, Aérospatial

    Meggitt expands involvement in KFX programme

    Jon Grevatt, Bangkok - IHS Jane's Defence Weekly UK company Meggitt has increased its involvement on the South Korean programme to develop the KFX multirole fighter aircraft through a new supply contract announced on 10 September. In a press release, Meggitt said it will develop an engine vibration monitoring unit (EVMU) for KFX prototypes currently under construction by prime contractor Korea Aerospace Industries (KAI). Chris Allen, president of Meggitt Sensing Systems, said, “This contract builds on the development work we have been undertaking with KAI on innovative technology for the KFX. We look forward to continuing our partnership and developing and delivering state of the art prototypes.” The newly announced contract is one of several that Meggitt has secured on the KFX development programme. https://www.janes.com/article/82887/meggitt-expands-involvement-in-kfx-programme

Toutes les nouvelles