18 mars 2020 | International, C4ISR, Sécurité

The Pentagon is handling cyber vulnerabilities inconsistently

Mark Pomerleau

The Department of Defense has not consistently mitigated cyber vulnerabilities identified in a 2012 report, according to the department's inspector general.

The DoD IG issued a follow-on report to its 2012 report, issued March 13 and made public March 17, that determined cyber red teams didn't report the results of assessments to organizations and components didn't effectively correct or mitigate the identified vulnerabilities.

The new report discovered that components didn't consistently mitigate or include unmitigated vulnerabilities identified in the prior audit and during this audit by red teams during combatant command exercises, operational testing assessments and agency-specific assessments in plans of action and milestones.

“Ensuring DoD Components mitigate vulnerabilities is essential to achieve a better return on investment,” the report stated. “In addition, we determined that the DoD did not establish a unified approach to support and prioritize DoD Cyber Red Team missions. Instead, the DoD Components implemented Component-specific approaches to staff, train and develop tools for DoD Cyber Red Teams, and prioritize DoD Cyber Red Team missions.”

The report found that DoD didn't establish a unified approach because it didn't assign an organization with responsibility to oversee and synchronize red team activity based on priorities, it didn't assess the resources needed for each red team and identify requirements to train them to meet priorities and it didn't develop baseline tools to perform assessments.

“Without an enterprisewide solution to staff, train and develop tools for DoD Cyber Red Teams and prioritize their missions, DoD Cyber Red Teams have not met current mission requests and will not meet future requests because of the increased demands for DoD Cyber Red Team services,” the report said. “Until the DoD assigns an organization to assess DoD Cyber Red Team resources, it will be unable to determine the number of DoD Cyber Red Teams and staffing of each team to support mission needs, which will impact the Do D's ability to identify vulnerabilities and take corrective actions that limit malicious actors from compromising DoD operations.”

The DoD IG issued seven recommendations the secretary of defense assign an organization responsibility for. They include:

  • Review and assess red team reports for systemic vulnerabilities and coordinate the development and implementation of enterprise solutions to mitigate them;
  • Ensure components develop and implement a risk-based process to assess the impact of identified vulnerabilities and prioritize funding for corrective actions for high-risk vulnerabilities;
  • Ensure components develop and implement processes for providing reports with red team findings and recommendations to organizations with responsibility for corrective actions;
  • Develop processes and procedures to oversee red team activities, including synchronizing and prioritizing red team missions, to ensure activities align with priorities;
  • Perform a joint DoD-wide mission-impact analysis to determine the number of red teams, minimum staffing levels of each team, the composition of the staffing levels needed to meet current and future mission requests;
  • Assess and identify a baseline of core and specialized training standards, based on the three red team roles that team staff must meet for the team to be certified and accredited; and
  • Identify and develop baseline tools needed by red teams to perform missions.

https://www.fifthdomain.com/dod/2020/03/17/the-pentagon-is-handling-cyber-vulnerabilities-inconsistently/

Sur le même sujet

  • How US Navy experiments could get drones beyond spying and into battle

    11 avril 2024 | International, Terrestre

    How US Navy experiments could get drones beyond spying and into battle

    The Navy is trying to make unmanned systems a more normal part of daily operations, even as experimentation continues to refine concepts of operations.

  • China’s industry reaps the benefits of political connections, international trade

    17 août 2020 | International, Aérospatial, Naval, Terrestre, C4ISR, Sécurité

    China’s industry reaps the benefits of political connections, international trade

    By: Mike Yeo MELBOURNE, Australia — China's defense companies continue their strong showing in the Defense News Top 100 list, with two of its companies in this year's top 10. The Aviation Industry Corporation of China, or AVIC (landing in 6th place), and China North Industries Group Corporation Limited, also known as NORINCO (8th place), reported defense-related revenue figures of $25.07 billion and $14.77 billion respectively. A third Chinese company in last years top 10, China Aerospace and Science Industry Corporation, or CASIC, dropped one place to 11th in this year's list. Overall, eight Chinese state-owned defense companies made it into this year's Top 100 ranking of defense companies around the world, including China's two largest shipbuilding conglomerates — China Shipbuilding Industry Corporation and China State Shipbuilding Corporation — which merged in November 2019 to create China State Shipbuilding Corporation Limited, or CSSC. Signs of growth China's industrial base has been the beneficiary of the country's economic reform efforts and globalization since the 1970s. The state of Chinese industry took a quantum leap with the end of the Cold War; the Asian economic powerhouse reaped the benefit of an exposure to advanced technology and modern manufacturing methods. These advances have transferred over to its defense industry, partly as a result of the transfer of civilian technologies, which are not restricted by Western sanctions on arms sales, implemented in response to China's human rights record, or obtained from countries that are not a party to those sanctions, like Russia and Ukraine. As a result, China's defense industry is today virtually unrecognizable from its early days when it mostly made both licensed and unlicensed copies of Soviet-era equipment. The most obvious of this is the continuing acquisition by China of the Russian Sukhoi Flanker family of fighter jets, which has subsequently seen the Asian country churn out increasingly capable analogs of their Russian counterparts. Beginning in the early 1990s with the acquisition and license production of the Su-27 interceptor, which has since morphed into the Shenyang J-11B equipped with indigenous avionics and weapons, China has subsequently imported the multirole Su-30 and Su-35 interceptors. The former has formed the basis of the Shenyang J-16, and it is likely both Russian types may form the technological basis for continued upgrades to the J-11 design. The unprecedented modernization of the People's Liberation Army over the past two decades in lockstep with China's economic development has also meant that the defense industry has been lavishly funded to equip a captive home market. Meia Nouwens, research fellow for Chinese defense policy and military modernization at the London-based International Institute of Strategic Studies, which helped Defense News compile the Top 100 data for Chinese defense companies, noted that President Xi Jinping is prioritizing defense at a national level as part of an effort to simultaneously pursue geostrategic goals and economic development. The national leadership's political will to transform China into a global power “should not be overlooked,” she said. She added that China's defense industry is capable of producing high-quality, high-tech defense products, although companies “still seeks to cooperate with international counterparts in academia and industry to gain access to cutting-edge know-how, skills and technology.” This has taken place alongside a large investment in domestic research and development, which Nouwens said has led to breakthroughs, specifically in the development of China's air-to-air missiles and quantum technology. For his part, Xi has promoted “the slimming down of large conglomerates, increased coordination with the [People's Liberation Army], enhanced effectiveness and sought to reduce the duplication of efforts,” she added. Export potential China's ongoing military modernization efforts means the local defense industry doesn't need to rely on the export market to sustain itself. Nevertheless, Nouwens said, Chinese defense conglomerates may be encouraged to increase exports given that Xi wants them to become increasingly self-sufficient and globally competitive. She added that the trend of defense exports and transfers being a cornerstone of Chinese diplomacy is likely to continue. The most obvious manifestation of this is China's continued export of materiel to Pakistan as well as the assistance Beijing has provided to developing the South Asian country's own defense industrial base. A side effect of this support included wedging China's geostrategic rival India, who is also frequently at odds with Pakistan. Nouwens also touched on the two-tier policy when it comes to China's defense exports, with its top-of-the-line equipment unavailable for export. However, she noted, China has improved the capabilities of defense articles available for export, including submarine technology, more modern frigates and collaboration with Pakistan in developing the JF-17 fighter jet. The latter has also been exported to Myanmar and Nigeria. One of China's most prominent exports remains its unmanned aircraft, with Nouwens noting that this market segment provided China with a “perfect combination of a capability that addressed a certain gap at a cost significantly cheaper than competitors on the market.” The window of opportunity has narrowed, however, with the U.S. having relaxed its own UAV export regulations. Countries like Jordan, the United Arab Emirates and Saudi Arabia, which have all acquired Chinese unmanned aircraft, may now turn to American designs instead; Jordan has already put up its Chinese-built CH-4 drones for sale. Despite reforms, Nouwens said, China's defense industry is bloated and, in some cases, requires further streamlining, with several of the industry's conglomerates involved in sectors as varied as hospitals and schools. https://www.defensenews.com/top-100/2020/08/17/chinas-industry-reaps-the-benefits-of-political-connections-international-trade/

  • HENSOLDT modernizes German Airforce IFF systems

    29 mai 2020 | International, Aérospatial

    HENSOLDT modernizes German Airforce IFF systems

    Taufkirchen/Germany, May 28, 2020 – As part of the modernization of all NATO's IFF identification systems (IFF = Identification-friend-or-foe) to the new "Mode 5" standard, sensor solution provider HENSOLDT is equipping the Air Force's 90 Tornado fighter aircraft with its Mode 5-capable LTR 400 transponder. An initial order for the delivery of 42 devices worth several million euros has been placed by Panavia Aircraft GmbH - the industrial consortium for the development of the Tornado; the conversion of over one hundred further platforms of the German Armed Forces is planned. As early as October 2019, the additional qualifications required for the LTR 400 transponder system to be installed on the German Tornado at equipment level were successfully completed and the relevant documents handed over to Airbus Defence and Space (ADS). Subsequently, during the test flights carried out by ADS in Manching at the end of 2019, the performance requirements for the IFF system as specified by the responsible military technical service (WTD-61) were verified The IFF technology is of central importance for all military operations. Based on automated electronic signals, it ensures that the armed forces can recognize friends who respond with the correct signal when contacted and identify potentially hostile vehicles who do not. All NATO countries are mandated to migrate to the new Mode 5 standard IFF, which uses advanced cryptographic techniques to secure systems against electronic interference from the enemy. This is important when armed forces operate together, as ensuring that crews of land, air and naval forces can reliably identify their allies is one of the most important ways of preventing so-called "friendly fire" incidents. The LTR 400 transponder is qualified for all flying platforms of the German Air Force and Army and is in use on all Airbus military helicopters. About HENSOLDT HENSOLDT is a pioneer of technology and innovation in the field of defence and security electronics. Based in Taufkirchen near Munich, the company is a German Champion with strategic leadership positions in the field of sensor solutions for defence and non-defence applications. HENSOLDT develops new products to combat a wide range of threats based on innovative approaches to data management, robotics and cyber security. With approximately 5,500 employees, HENSOLDT generated revenues of 1.14 billion euros in 2019. www.hensoldt.net Press contact Lothar Belz Tel.: +49 (0)731.392.3681 lothar.belz@hensoldt.net View source version on HENSOLDT: https://www.hensoldt.net/news/hensoldt-modernizes-german-airforce-iff-systems/

Toutes les nouvelles