• COVID-19
  • About Us
  • Contact Us
  • Events
  • Industries
  • Partners
  • Products & Services
  • Contribute
  • Webinars

Aerospace

  • Québec’s CloudOps Will Build Telesat LightSpeed’s Cloud Network
  • Myriota and Goanna Ag Team Up on IoT Agriculture Solutions
  • Fleet Picks Swissto12 to Deliver Additively Manufactured All-Metal Patch Antennas

Chemical

  • POWER magazine and Chemical Engineering magazine announce Eastman Chemical as the Host Chemical Process Industries (CPI) Sponsor for the 5th annual Connected Plant Conference
  • Evonik deepens partnership with IBM to accelerate AI implementation
  • Achieving Plant Efficiency – the Digital Way

Cybersecurity

  • House Passes Eight Bipartisan Cyber, Homeland Security Bills
  • Biden Administration Targets Electric Utilities For Cybersecurity Protections
  • White House Attributes SolarWinds Hack To Russian Agency

Healthcare

  • CISA Services In High Demand Related To COVID Vaccine Response
  • AI tool detects COVID-19 by listening to patients’ coughs
  • Printing Wearable Sensors Directly onto Skin

Oil & Gas

  • Globalstar Wins Asset Tracking Order from Brazilian Oil and Gas Company
  • Cybersecurity: Continuous Vigilance Required
  • Repsol and Microsoft renew partnership developing AI-powered digital solutions

Power

  • POWER magazine and Chemical Engineering magazine announce Eastman Chemical as the Host Chemical Process Industries (CPI) Sponsor for the 5th annual Connected Plant Conference
  • Self-Tuning Artificial Intelligence Improves Plant Efficiency and Flexibility
  • How to Put the Power Grid to Work to Prevent Wildfires

Transportation

  • Swarm CEO Sara Spangelo Sets Disruptive Pricing on New Satellite IoT Service
  • Trump Issues Cyber Security Plan For Maritime Transportation System
  • Sabic Launches New Compounds for Automotive Radar Sensors

Webinars

  • Anticipating the Unknowns: Accelerating Incident Response Without Losing Control
  • Industrial Endpoint Protection in Operational Technology
  • Known and Unknown: Putting a Stop to OT and IT Threats Before they Act

Sign up today for our free weekly e-letter

sign up
CONNECTING INNOVATIONS
WITH INSIGHT
SIGN UP
LOG IN
  • Aerospace
    Québec's CloudOps Will Build Telesat LightSpeed's Cloud Network
    Read story View all articles
  • Chemical
    POWER magazine and Chemical Engineering magazine announce Eastman Chemical as the Host Chemical Process Industries (CPI) Sponsor for the 5th annual Connected Plant Conference
    Read story View all articles
  • Cybersecurity
    House Passes Eight Bipartisan Cyber, Homeland Security Bills
    Read story View all articles
  • Healthcare
    CISA Services In High Demand Related To COVID Vaccine Response
    Read story View all articles
  • Oil & Gas
    Globalstar Wins Asset Tracking Order from Brazilian Oil and Gas Company
    Read story View all articles
  • Power
    POWER magazine and Chemical Engineering magazine announce Eastman Chemical as the Host Chemical Process Industries (CPI) Sponsor for the 5th annual Connected Plant Conference
    Read story View all articles
  • Transportation
    Swarm CEO Sara Spangelo Sets Disruptive Pricing on New Satellite IoT Service
    Read story View all articles
Cybersecurity
March 5 2021 10:25 pm

Cyber Security Requirements In Weapon System Contracts A Work In Progress, GAO Says

C

Cal Biesecker

The Defense Department and Armed Forces have made progress the past few years in several areas to improve the cyber security of weapon systems but weaknesses remain, and in acquisition programs reviewed during a recent government audit, cyber security requirements didn't exist or weren't clear in contracts.

"The government is less likely to get what it wants if it omits all or part of its cybersecurity requirements," the Government Accountability Office (GAO) says in a report issued March 4.

Of five acquisition programs reviewed–a radar, an anti-jammer, a ship, a ground vehicle, and a missile–three didn't have cyber security requirements at the time of award and three were modified post-award to add requirements, says the 40-page report, Weapon Systems Cybersecurity: Guidance Would Help DoD Programs Better Communicate Requirements to Contractors (GAO-21-179).

None of the programs reviewed included acceptance criteria in contracts for meeting cyber security requirements in terms of performance-based requirements.

"Officials from one program office said they attempted to use performance-based requirements, but could not agree to terms with the contractor," GAO says. "DoD and contractor officials said that many contract requirements focus on cybersecurity controls the system must have as opposed to desired outcomes such as preventing unauthorized users from accessing the system. However, as we have previously reported, the application of controls does not mean that the system is secure."

Additional concerns raised in the report include a complete lack of demonstrating how contracted cyber security requirements would be met, inserting cyber requirements in a contract is challenging and that programs would benefit from better department-level guidance about acceptable risks, and the military services with the exception of the Air Force don't provide guidance on cyber security requirements.

"Army regulation, updated with major revisions in 2019, directs senior leaders to integrate cybersecurity in acquisitions and to ensure that contracts include specific requirements to provide cybersecurity for Army IT, including weapon systems," GAO says. "However, the regulation provides no further detail on how to do so."

Progress in recent years has been made in four areas, including "greater access to cyber expertise, increased use of cyber assessments, better tailoring of security controls, and additional cybersecurity guidance," the report says.

GAO cites a 2019 report by the DoD Office of the Director, Operational Test and Evaluation "that there is a widening gap in capabilities between DoD's cyber test teams and nation-state threats," but notes that the program officials interviewed in its audit said "they had adequate access to cybersecurity expertise despite some challenges hiring and retaining cybersecurity personnel."

A 2018 report by the GAO highlighted a lack of cyber security assessments of weapon systems at the time, and then when problems were discovered it was late in development when it is more costly to fix. The new report says that all the programs reviewed had done or were planning to do cyber security assessments throughout the acquisition process, including during various stages of testing.

"The increased use of cybersecurity assessments is a positive development and may help programs identify vulnerabilities earlier," GAO says. "However, the existence of the assessments alone does not guarantee better outcomes. For example, we previously found that in some systems, the same vulnerabilities were found in multiple rounds of testing, and had gone unaddressed after they were first discovered."

Sign up today for our free weekly e-letter

sign up

Aerospace

Chemical

Cybersecurity

Healthcare

Oil & Gas

Power

Quiz

Transportation

Webinars

About Us

IIoT Connection delivers the latest news, trends, insights, events and research surrounding the dynamic and disruptive Industrial Internet of Things (IIoT) marketplace. Brought to you by the publisher of must-read publications Defense Daily, OR Manager, POWER and Chemical Engineering, as well as the conference producers of SATELLITE, Global Connected Aircraft Summit, Connected Plant Conference and ELECTRIC POWER, IIoT Connection is committed to providing the most comprehensive compilation of products and services dedicated to the Industrial Internet of Things. Key verticals with associated products and services include: aerospace, chemical, cybersecurity, healthcare, oil & gas, power, and transportation.


Advertise

  • Privacy Policy
© 2021 Access Intelligence, LLC - All Rights Reserved.
  • × UPS Partners with Wingcopter to Develop, Certify Drone Delivery Fleet
    Read story View all articles
  • × How Industrial Managers Can Identify and Prevent Failures in Facilities
    Read story View all articles
  • × Federal Agencies Partner To Improve Cyber Security Cooperation In Energy Sector
    Read story View all articles
  • × New service lines can create opportunities for ORs
    Read story View all articles
  • × Equinor and Shell to collaborate on digital solutions
    Read story View all articles
  • × Dobroflot to Manage Fuel Savings With IOT Solution By Orange Business Services
    Read story View all articles
  • × The Future of 5G & IoT Technologies in the Transportation Industry
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles