4 juin 2020 | International, C4ISR, Sécurité

Watchdog says Pentagon needs better planning for IP update 17 years after first attempt

A federal watchdog found that poor planning by the Department of Defense has blurred the department's understanding of the risks and costs associated with upgrading the system that routes internet traffic across the globe, known as Internet Protocol version 6 (IPv6).

According to a June 1 report from the Government Accountability Office, the Pentagon needs to improve its transition planning for the most recent effort, which began in April 2017. The DoD has tried twice previously to implement IPv6 in 2003 and 2010, but stopped those transitions after identifying security risks and lacking adequately trained personnel.

The problem for the DoD is that IPv4, the IP management system the DoD uses, is running out of address space. IPv4 only has room for 4.3 billion addresses. In contrast, IPv6, created in the 1990s, provides about 340,000,000,000,000,000,000,000,000,000,000,000,000 (undecillion) IP addresses. The Defense Department owns approximately 300 million IP addresses with about 59.8 million unused and planned for use by future DoD components. The department estimates it will run out of its unused IP addresses by 2030.

The department's IPv6 implementation plan from early 2019 listed 35 actions needed to switch over from IPv4. Eighteen of those steps were scheduled to be completed by March 2020. The report said six of the 18 tasks were completed on time.

Upgrading to IPv6 would increase connectivity, add security, improve the warfighter's connection and communications on the battlefield, and preserve interoperability with allied systems, the GAO wrote.

The watchdog found that the department was not compliant with several IPv6 transition requirements from the White House's Office of Management and Budget. The DoD hasn't completed a cost estimate, developed a risk analysis or finished an inventory of IP compliant devices, the report said. Pentagon officials told the GAO that they knew their time frame for the transition was “optimistic," adding that they thought the pace was reasonable "until they started performing the work,” the GAO wrote.

“Without an inventory, a cost estimate, or a risk analysis, DOD significantly reduced the probability that it could have developed a realistic transition schedule,” the GAO wrote. “Addressing these basic planning requirements would supply DOD with needed information that would enable the department to develop realistic, detailed, and informed transition plans and time frames.”

The Department did meet OMB's requirement to name an official to lead and coordinate the agency planning. But because the Pentagon failed to complete the other three OMB requirements. the move is at risk.

“Without an inventory, a cost estimate, or a risk analysis, DOD's plans have a high degree of uncertainty about the magnitude of work involved, the level of resources required, and the extent and nature of threats, including cybersecurity risks,” the GAO wrote.

Among the DoD's goals it did complete are several IPv6 training programs, information sharing opportunities and a program management office.

The GAO recommended that Defense Secretary Mark Esper direct the DoD chief information officer to complete an inventory of IP-compliant devices, develop a cost estimate and perform a risk analysis. The DoD agreed that it needed to develop a cost estimate and risk analysis but didn't concur that it needed to inventory devices, citing new guidance from OMB and calling an inventory “impractical” because of the department's size.

“The lack of an inventory is problematic due to the role that it should play in developing transition requirements,” the GAO wrote.

https://www.c4isrnet.com/it-networks/2020/06/02/watchdog-says-pentagon-needs-better-planning-for-ip-update-17-years-after-first-attempt/

Sur le même sujet

  • Rheinmetall MAN Military Vehicles UK awarded $354 mln truck order

    6 février 2024 | International, Terrestre

    Rheinmetall MAN Military Vehicles UK awarded $354 mln truck order

  • New US sanctions target Russia's multibillion-dollar defense sector

    7 mars 2022 | International, Aérospatial, Naval, Terrestre, C4ISR, Sécurité

    New US sanctions target Russia's multibillion-dollar defense sector

    The measures, triggered by Moscow's war against Ukraine, target both Russia and its ally Belarus, which has been a staging ground for the invasion.

  • Israel Aerospace considering investment in drone maker Aeronautics

    2 janvier 2019 | International, Aérospatial

    Israel Aerospace considering investment in drone maker Aeronautics

    JERUSALEM (Reuters) - State-owned defense contractor Israel Aerospace Industries (IAI) [ISRAI.UL] said on Tuesday it was in talks to invest in local drone maker Aeronautics (ARCS.TA). The talks were at an early stage, IAI said, and no financial details were disclosed. Meanwhile Aeronautics, which was searched on Monday by Israel Securities Authority investigators, said separately it was also talking to another unidentified group regarding the sale of its 50 percent stake in the surveillance and reconnaissance company Controp Precision Technologies. In August, Aeronautics rejected a 430 million shekel ($115 million) acquisition offer from IAI rival, state-owned Rafael Advanced Defense Systems, and businessman Avihai Stolero. Israel-based Aeronautics manufactures unmanned aerial vehicles for military surveillance and defense purposes, as well as for the commercial sector. On Monday, investigators from the market regulator searched Aeronautics' office, the company said. A court has placed a gag order on details of the investigation. It was not the first time Aeronautics has been probed by Israeli authorities. In August 2017, Aeronautics said the Defence Ministry had suspended the marketing and export license for one of the firm's attack drones to a single, significant customer in a foreign country. It denied it was at fault. Israeli media at the time reported that the ministry had opened an investigation into Aeronautics over whether during a demonstration in Azerbaijan one of its drones was used to attack a military position in the neighboring country of Armenia, and if so, who was at fault. In November that same year Israeli police said they were investigating one of the drone maker's deals but did not give details. Reporting by Ari Rabinovitch; Editing by Alison Williams https://www.reuters.com/article/us-aeronautics-ltd-m-a-il-aerospace-ind/israel-aerospace-considering-investment-in-drone-maker-aeronautics-idUSKCN1OV1JL

Toutes les nouvelles