DOD gets serious about funding IA improvements
Connecting state and local government leaders
The Defense Department is talking a lot about network and information security these days, and according to Pentagon officials speaking at the Black Hat Federal Briefings in Arlington, Va., it has begun putting some of its money where its mouth is.
The Defense Department is talking a lot about network and information security these days, and according to Pentagon officials speaking at the Black Hat Federal Briefings in Arlington, Va., it has begun putting some of its money where its mouth is.
The department has budgeted $77 million for six years beginning in 2007 to fund new training and certification requirements for systems administrators, said Rick Aldrich of the DOD network defense organization. An additional $500 million has been requested for IT security initiatives resulting from the department's most recent quadrennial review.
This money is in addition to the $2 billion now being spent annually on information assurance from the DOD's $30 billion IT budget.
Linton Wells II, principal deputy assistant secretary for network and information integration, described some of the security initiatives in his opening keynote address at the briefings.
Wells said the four-year review, which began in 2001, went beyond the program and budget level to address new strategic needs for the nation's military. In the future, DOD will depend more on speed and agility than on brute force to address emerging threats.
'That is why the network, which allows you to use your forces in nonconventional ways, is one of the keys to change in the quadrennial review,' Wells said.
But he warned that today's DOD networks are vulnerable and under attack. Some of the attackers are believed to be nations.
'We know our adversaries have the networks in their sights,' he said. 'We have to assume we are facing a patient, skilled and well financed adversary.'
Actions taken in the last six months to address these threats include:
- Setting new standards for training and certifying systems administrators on DOD IT systems, which required legislation enabling the department to pay for commercial certification of its IT professionals
- Standardizing system configurations
- Pushing for the use of the Common Access smart ID card for network access control throughout the department
- Improving network monitoring capabilities
- Establishing greater control over connections between DOD and public networks
NEXT STORY: Army mandates PKI log-on for access to NIPRnet