10 mars 2020 | International, C4ISR, Sécurité

The Pentagon’s first class of cybersecurity auditors is almost here

Mark Pomerleau

The Pentagon hopes to have the first class of auditors to evaluate contractors' cybersecurity ready by April, a top Department of Defense official said March 5.

The auditors will be responsible for certifying companies under the new Cybersecurity Maturity Model Certification (CMMC), which is a tiered cybersecurity framework that grades companies on a scale of one to five. A score of one designates basic hygiene and a five represents advanced hygiene.

Currently, there are no auditors — known as Certified Third-Party Assessment Organizations (C3PAO) — as the accreditation board came about officially in January.

“Our goal is to have, in late April, our pilot pathfinder on the training for the C3PAOs,” Katie Arrington, chief information security officer for the Office of the Under Secretary of Defense for Acquisition, said at an event hosted by DreamPort in Columbia, Maryland.

The accreditation board is working on training the auditors and the accompanying training materials

Arrington said just because there aren't any auditors already working doesn't mean companies shouldn't be getting ready.

“You've got to get prepared for the audit,” she said. “You should be able to say ‘I think I've done my self assessment, I think I'm at this CMMC level.' Waiting for the audit to come in and then decide to get good or to get on track is not the way I would position my business.”

If all goes according to plan, all new contracts in 2025 will feature the security requirements.

Arrington also suggested that the framework has received interest outside the DoD.

“Do I think that other federal agencies are getting on board? Yes they are. They're waiting for me to get through my pathfinder,” she said.

She also referred to comments made by Under Secretary of Defense for Acquisition and Sustainment Ellen Lord, who explained nearly a dozen nations and international organizations are interested in adopting CMMC.

https://www.fifthdomain.com/dod/2020/03/09/the-pentagons-first-class-of-cybersecurity-auditors-is-almost-here/

Sur le même sujet

  • Rheinmetall supplies AI-powered navigation system for UK MoD’s Project Theseus 2.2

    16 août 2022 | International, Terrestre

    Rheinmetall supplies AI-powered navigation system for UK MoD’s Project Theseus 2.2

    Rheinmetall has secured a contract with the United Kingdom Ministry of Defence’s Project Theseus 2.2, an initiative to automate supply delivery to soldiers in hostile environments and first systems have already...

  • Infantry Squad Vehicle is a cramped ride, but US Army says it meets requirements

    26 janvier 2021 | International, Terrestre

    Infantry Squad Vehicle is a cramped ride, but US Army says it meets requirements

    By: Jen Judson WASHINGTON — The U.S. Army's new Infantry Squad Vehicle is a cramped ride and offers limited protection from certain threats, according to a recent report from the Pentagon's chief weapons tester, but it still meets the service's requirements in tests and evaluations, the product lead told Defense News. The ISV “key requirements are being met and we are increasing soldier operational readiness by providing an operationally relevant vehicle that can transport small tactical units to a dismount point faster and in better physical and mental condition for the fight,” said Steven Herrick, the Army's product lead for ground mobility vehicles within the Program Executive Office Combat Support and Combat Service Support. The vehicle was designed for easy transport to operational environments with the infantry's current rotary and fixed-wing transport platforms. The key performance parameters required that the vehicle's weight not exceed 5,000 pounds and that it fit inside a CH-47 Chinook cargo helicopter. Those requirements “force dimensional requirements only allowing the vehicle to be a certain height, width and length,” he said. The requirements led to a vehicle that makes it hard for soldiers with all their gear needed for a 72-hour mission to comfortably fit inside and be able to access rucksacks on the move. The Army assessed three vendors in developmental testing from December 2019 through January 2020. The service chose General Motors Defense to supply the vehicle to the force, with the company beating out an Oshkosh Defense and Flyer Defense team as well as an SAIC and Polaris team. All offerings were capable of carrying a nine-soldier infantry squad with weapons and equipment during movement, the director of operational test and evaluation said in the report. But the Pentagon also noted the ISV “has not demonstrated the capability to carry the required mission equipment, supplies and water for a unit to sustain itself to cover a range of 300 miles within a 72-hour period.” The Army, however, has assessed the ISV requirement and solution set is in alignment, Herrick said. The DOT&E report, he said, “indicates a desire to include more equipment than a standard nine-soldier squad would carry on a 72-hour mission.” This lack of space, the report stated, “may create a logistics and operational burden” and might limit the type of missions and duration for ISVs. The soldiers that participated in the touch point evaluating the vehicles were asked to bring their Advanced Combat Helmet and Improved Outer Tactical Vest with plates; individual weapon; night vision devices; and ruck with three days' worth of supplies, Herrick said. “All vendors' ISVs are cramped and soldiers cannot reach, stow, and secure equipment as needed, degrading and slowing mission operations,” the report explained. During tests “soldiers on all ISVs could not readily access items in their rucksacks without stopping the movement, dismounting, and removing their rucksacks from the vehicle.” The soldier touch point took into account soldier comfort, visibility and ability to execute the mission, Herrick said. This was all factored into the Army's decision to choose GM Defense's vehicle. “Additionally, no current or planned combat or tactical vehicle allows access to rucksacks while moving to support operator safety,” Herrick noted. “Crew spaces on the ISV are designed to allow mission performance of specific duty tasks.” Units also lacked reliable communication capability, according to the report, using hand-held or manpack radios between 62 and 300 miles. The ISV does not have a mounted radio requirement. “Communication between the squad leader, soldiers, and the platoon leader was intermittent and not reliable,” the report found. Because of the concept of the ISV providing an effective aid to insert soldiers into combat operations, the requirements support just what the soldier carries, so there is no mounted requirement yet, Herrick said. That requirement could be added as a growth capability later. The DOT&E report also noted that the ISV doesn't have an underbody and ballistic survivability requirement, which could mean the unit would be susceptible to certain threats, but the ISV's speed as well as its small, low profile might help deal with those issues. Adding protection to the vehicle would sacrifice the speed the squad needs to rapidly inject itself into operations. Overall, GM Defense's vehicle had the highest reliability among the three vendors, demonstrating 585 mean miles between operational mission failures. The Army's user requirement is 1,200 mean miles for that situation. Herrick noted that reliability and maintainability testing was not scheduled or conducted by Army Test and Evaluation Command or the program office, so the calculations used in the DOT&E report were “not supported by traditional [reliability and maintainability] RAM elements, such as scoring conferences and time for the vendor to implement changes.” The mileage accumulated and referenced in the report was “not meant to evaluate RAM by the Army, but rather to provide the program office and contractor an initial insight on the capability of the system over 500 miles,” Herrick added. The vehicle's RAM testing is scheduled to begin this month, he added.. The service wasn't able to evaluate every aspect of the vehicle before moving into production, but it plans to test the vehicle's ability to be carried by a Chinook during its initial operational test and evaluation this year. Now that the Army has chosen the GM Defense vehicle, it has already initiated developmental testing that will lead to an initial operational test and evaluation in August 2021 at Fort Bragg, North Carolina. That testing began in November 2020. https://www.defensenews.com/land/2021/01/25/infantry-squad-vehicle-is-a-cramped-ride-but-army-says-it-meets-requirements/

  • The Space Force considers a new mission: tactical satellite imagery

    5 février 2021 | International, Aérospatial, C4ISR

    The Space Force considers a new mission: tactical satellite imagery

    Nathan Strout WASHINGTON — The U.S. Space Force is still in its early days, but leaders are already considering adding a new mission for Guardians: providing tactical satellite imagery for beyond-line-of-sight targeting. “That's something that we're thinking through as we speak. I've got a group of folks doing some work on what that design might look like,” Gen. John “Jay” Raymond, the chief of space operations, said Feb. 3 during a Defense Writers Group call. The Space Force, like Air Force Space Command before it, provides the GPS signal, missile warning information, and wideband communications with its on orbit satellites. Tactical satellite imagery, however, has not been part of its workload. “That's largely been more on the intelligence community side,” Raymond said. Specifically, satellite imagery is generally the responsibility of two intelligence agencies: the National Reconnaissance Office and the National Geospatial-Intelligence Agency. While the NRO builds and operates the nation's spy satellites and contracts with commercial providers to access their imagery, NGA sets imagery requirements and transforms that raw satellite data into intelligence products. The military typically relies on NGA for geospatial intelligence (GEOINT) products. “I do think as technology has allowed for smaller satellites to be more operationally relevant and you can do so at a price point that is cheaper, that there is a role for operational level tactical satellites as you described and that the Space Force would have a role in that,” Raymond said “Again, it's early in the study efforts, if you will, and whatever we do we'll make sure that we do it in close partnership with our intelligence partners, because what we don't want to do is duplicate efforts,” he continued. “We want to save dollars and reduce taxpayer dollars, not duplicate.” The proliferation of small and relatively affordable small imaging satellites and the growing commercial satellite imagery market has sparked interest at the Pentagon in using satellites for beyond-line-of-sight (BLOS) targeting. The U.S. Army has been at the forefront of that effort, launching its own small imaging satellite — Kestrel Eye — in 2017. More recently at the Project Convergence 2020 exercise, the Army used commercial satellite imagery to develop targeting data and shoot at BLOS threats. The Air Force and the Navy are also investing in tactical GEOINT products. The Air Force Research Laboratory is investing in commercial tactical GEOINT software to help them find moving targets with satellite imagery, while the Navy is paying for commercial synthetic aperture radar imagery and analytics. Elsewhere in the Department of Defense, the Space Development Agency has set BLOS targeting as one of the main capabilities it is pursuing for its new proliferated constellation in low Earth orbit, which will eventually be made up of hundreds of satellites. “That's where the Army is most affected and that's where we're working very closely with the Army to make sure that we're tied together. So this is the ability to detect and track and maintain custody of anything, say, larger than a truck and to be able to actually give a targeting fire control solution to a weapon in the field in real time anywhere on the globe,” SDA Director Derek Tournear said in 2019. “That's the goal. That's the capability.” The SDA is slated to become part of the Space Force in late 2022. https://www.c4isrnet.com/battlefield-tech/space/2021/02/03/the-space-force-is-considering-adopting-a-tactical-geoint-mission/

Toutes les nouvelles