18 mars 2020 | International, C4ISR, Sécurité

The Pentagon is handling cyber vulnerabilities inconsistently

Mark Pomerleau

The Department of Defense has not consistently mitigated cyber vulnerabilities identified in a 2012 report, according to the department's inspector general.

The DoD IG issued a follow-on report to its 2012 report, issued March 13 and made public March 17, that determined cyber red teams didn't report the results of assessments to organizations and components didn't effectively correct or mitigate the identified vulnerabilities.

The new report discovered that components didn't consistently mitigate or include unmitigated vulnerabilities identified in the prior audit and during this audit by red teams during combatant command exercises, operational testing assessments and agency-specific assessments in plans of action and milestones.

“Ensuring DoD Components mitigate vulnerabilities is essential to achieve a better return on investment,” the report stated. “In addition, we determined that the DoD did not establish a unified approach to support and prioritize DoD Cyber Red Team missions. Instead, the DoD Components implemented Component-specific approaches to staff, train and develop tools for DoD Cyber Red Teams, and prioritize DoD Cyber Red Team missions.”

The report found that DoD didn't establish a unified approach because it didn't assign an organization with responsibility to oversee and synchronize red team activity based on priorities, it didn't assess the resources needed for each red team and identify requirements to train them to meet priorities and it didn't develop baseline tools to perform assessments.

“Without an enterprisewide solution to staff, train and develop tools for DoD Cyber Red Teams and prioritize their missions, DoD Cyber Red Teams have not met current mission requests and will not meet future requests because of the increased demands for DoD Cyber Red Team services,” the report said. “Until the DoD assigns an organization to assess DoD Cyber Red Team resources, it will be unable to determine the number of DoD Cyber Red Teams and staffing of each team to support mission needs, which will impact the Do D's ability to identify vulnerabilities and take corrective actions that limit malicious actors from compromising DoD operations.”

The DoD IG issued seven recommendations the secretary of defense assign an organization responsibility for. They include:

  • Review and assess red team reports for systemic vulnerabilities and coordinate the development and implementation of enterprise solutions to mitigate them;
  • Ensure components develop and implement a risk-based process to assess the impact of identified vulnerabilities and prioritize funding for corrective actions for high-risk vulnerabilities;
  • Ensure components develop and implement processes for providing reports with red team findings and recommendations to organizations with responsibility for corrective actions;
  • Develop processes and procedures to oversee red team activities, including synchronizing and prioritizing red team missions, to ensure activities align with priorities;
  • Perform a joint DoD-wide mission-impact analysis to determine the number of red teams, minimum staffing levels of each team, the composition of the staffing levels needed to meet current and future mission requests;
  • Assess and identify a baseline of core and specialized training standards, based on the three red team roles that team staff must meet for the team to be certified and accredited; and
  • Identify and develop baseline tools needed by red teams to perform missions.

https://www.fifthdomain.com/dod/2020/03/17/the-pentagon-is-handling-cyber-vulnerabilities-inconsistently/

Sur le même sujet

  • Australia, Naval Group conclude sub negotiations

    17 décembre 2018 | International, Naval

    Australia, Naval Group conclude sub negotiations

    By: Nigel Pittaway MELBOURNE, Australia – Australian Defence Minister Christopher Pyne confirmed that the Australian government has finally concluded negotiations for the formal signing of a strategic partnering agreement for 12 large conventionally-powered attack submarines from Naval Group. Australia is acquiring the vessels under its $50 billion (U.S. $36.12 billion) Project Sea 1000 (Future Submarine) to replace its existing fleet of six Collins Submarines from the early 2030s. The subs will be the ‘Attack' class with the lead vessel named HMAS Attack. They will be fabricated in Australia to a design previously known as the Shortfin Barracuda 1A. Recent local media reports have suggested that negotiations between the parties had stalled, placing the government's timeline for the Collins replacement in jeopardy, but Pyne said on Thursday the program was still on track. “There's been a lot of ill-informed mythmaking around the negotiations but I'm very happy to say today the negotiations are complete,” Pyne said during sod-turning event at the site of the Future Submarine Construction Yard at Osborne in South Australia. “The strategic planning agreement will be signed in February next year and we can continue to get on with the submarine project, which has been under the design and mobilization contract for the last two years.” Declining to provide details of the intricacies of the agreement due to their commercial nature, Pyne said the negotiations were officially concluded at an Australian Government National Security Committee meeting in Melbourne on Dec. 10. “Suffice to say the Australian government's interests, the Australian taxpayer's interests, have been taken care of,” he said. “Naval Group Australia will deliver 12 regionally-superior submarines on time and on budget.” Australia's Chief of Navy, Vice Adm. Mark Noonan, also denied reports of an emerging capability gap between the retirement of the first Collins submarines and the Attack boats entering service, which some analysts have suggested might require a ‘Plan B' to be formulated. “I don't believe that's the case,” he told reporters. “We've got a very solid plan to ensure that there is no gap in our nation's submarine capability, and there is a very advanced plan that will see a number of our current Collins class submarines going through a life of type extension program, which will ensure that capability gap doesn't exist.” https://www.defensenews.com/global/asia-pacific/2018/12/14/australia-naval-group-conclude-sub-negotiations/

  • COVID Drives AUSA Mega-Conference Online: Gen. Ham

    22 juillet 2020 | International, Aérospatial, Naval, Terrestre, C4ISR, Sécurité

    COVID Drives AUSA Mega-Conference Online: Gen. Ham

    Bringing together an estimated 33,000 soldiers and civilians from around the world was just too dangerous in the coronavirus era. By SYDNEY J. FREEDBERG JR.on July 21, 2020 at 3:42 PM WASHINGTON: Every October, the Walter E. Washington convention center in downtown DC – a behemoth building covering two whole city blocks – fills with soldiers, contractors, and reporters. Over 30,000 people pack shoulder-to-shoulder in conference rooms to hear from Army leaders, speak face to face, line up for fried chicken, shake hands, hug, and handle military hardware from prototype rifles to full-sized tanks. But with COVID-19 cases rising alarmingly around the country, none of that will happen this October. “We've made the difficult decision to convert the 2020 AUSA Annual Meeting from an in-person meeting to a virtual experience,” said retired Gen. Carter Ham, the Association of the US Army's president and CEO, in a statement Tuesday afternoon. The mega-conference – historically one of the biggest in-person gatherings for the defense industry in the DC area – will now take place entirely online over Oct. 13-16. Breaking Defense plans to cover the virtual event as exhaustively (and as exhaustingly for our reporters) as it has the physical one every year since 2011. “With recent trends, it just became clear to me that we simply could not, in any reasonable manner, ensure a safe, secure environment for the 32,000-plus people we expected this October,” Gen. Ham told me in an follow-up email. “We are working very closely with the Army to craft an agenda which provides opportunities for key leaders to connect with our members and constituents.” “One of the keys to that is finding ways to connect Army leaders with the businesses, large and small, who normally are present in the exhibition hall,” Ham said. “Finding a way to do something similar to that experience in the virtual world will be a challenge, but it is an integral part of the AUSA Annual Meeting, so we'll figure it out.” AUSA is still working out the logistics of this massive switch. Registrations and sponsorship agreements from the in-person version of the event will not automatically carry over. “Registration for the new virtual meeting is expected to open by September,” the AUSA statement says. “AUSA is now coordinating details for the virtual event, and team members will be reaching out directly to exhibitors and sponsors about new opportunities.” With over 600 sponsors in a typical year – ranging from small businesses with a single, small booth to titans like Boeing and Lockheed Martin – the Annual Meeting is a major source of revenue for AUSA. How this will impact the association's budget is unclear – even to AUSA itself at this point. Breaking Defense graphic from AUSA data “The AUSA Annual Meeting is our most important revenue-generating event of the year,” Ham said bluntly. “The revenue from this event is largely what allows us to conduct other events throughout the year. So, I don't know yet precisely what the impact will be, but there will be some effect. Fortunately, AUSA is in a strong financial position so we will be able to sustain this change.” AUSA's latest annual report said the 2018 conference “generated $16 million in revenue,” just under half the association's total projected revenue of $33 million for the 2018-2019 fiscal year. (The report for 2019-2020 hasn't been published yet). But AUSA also reported its investment portfolio was worth $51 million; that was as of May 2019, before COVID roiled the stock market, but the portfolio should still be large enough to offer at least some buffer. The initial wave of the COVID-19 coronavirus forced AUSA to cancel its Global Force conference in Huntsville, Ala. this March just a week ahead of opening day. That gave the association no time to schedule virtual alternatives, although multiple events from Army aircraft announcements to Shark Tank-style pitch meetings were hastily turned into teleconferences or webcasts. Global Force had expected some 6,000 attendees. Since then, AUSA has held a host of online events, largely but by no means entirely without glitches, but they were all much smaller in scale. The Annual Meeting had expected some 33,000 attendees. Moving that conference online will be a vastly larger organizational and technical challenge. It's also an opportunity, Ham argued. “While we will all certainly miss the opportunity to be together with the broader Army Family, choosing to provide our programs in a virtual environment does offer us an opportunity to connect with audiences who might not know AUSA all that well or who have simply not been able to travel to Washington DC for the event in prior years,” he told me. “I view this very much as a chance to extend our reach and to more effectively fulfill our mission to support the Army.” Even if nothing glitches, though, the virtual Annual Meeting won't replace the human connection that came from the Army's annual gathering of its disparate tribes. “What will I miss? This is the Army's family reunion,” Ham said. “Every October, the opportunity to see old friends and to make new friends is the most enjoyable part of the Annual Meeting. I'll miss that, to be sure, but I also know that via this virtual experience, we will make new connections, new relationships that will make AUSA 2021 even better when we can all be together again.” https://breakingdefense.com/2020/07/covid-drives-ausa-mega-conference-online/

  • UK fighter concept emphasizes stealth, next generation sensors

    17 août 2018 | International, Aérospatial

    UK fighter concept emphasizes stealth, next generation sensors

    BY TOM RISEN Britain wants to build a twin-engine stealth fighter jet that the Defense Ministry says would enable the United Kingdom to stay competitive in air-to-air combat technology and maintain its domestic fighter industry. U.K. Defense Secretary Gavin Williamson unveiled a full-scale model of the Tempest at the Farnborough Airshow in July as a commitment that Britain would remain “a world leader in the combat air sector.” The U.K. contractors chosen to design the plane must first present a business case for the fighter to the ministry by the end of the year to begin the approval process for funding. The ministry has promised to draw 2 billion pounds ($2.6 billion) for the Tempest over several years from the ongoing Future Combat Air System Technology Initiative enacted in 2015 that ends in 2025 to develop a successor to the twin-engine Eurofighter Typhoon. Team Tempest, the name for the government agencies and companies working on the project, shared limited details about the design in progress beyond the concept they showcased. With their near diamond shape, the Tempest wings resemble those of the YF-23 stealth fighter demonstrator built in 1990 for the U.S. Air Force by Northrop and McDonnell Douglas, notes Adam Routh, an aerospace researcher at the Center for a New American Security in Washington, D.C. The YF-23 was flown in 1990 but lost the competition for the Air Force contract to what became the Lockheed Martin F-22 Raptor, which ended mass production in 2011. The F-22 engines include thrust vectoring to maneuver the plane around enemy aircraft at close range, which the YF-23 lacked. Thrust vectoring engines were not presented as part of the Tempest concept, possibly because “next generation stealth and guided missiles may undermine the benefits of maneuverability by allowing planes to attack from a significant distance,” Routh says. Pilots of future air-to-air combat won't often find themselves in dogfights won with maneuverability, Routh says, because guided missiles and stealth “will allow aircraft to engage opposing aircraft from a significant distance.” Full article: https://aerospaceamerica.aiaa.org/uk-fighter-concept-emphasizes-stealth-next-generation-sensors

Toutes les nouvelles