ZeroHour
CyberScooppublished ()ingested @WatermanReports

Audit warns of poor planning on vast Pentagon IT plan

criticalExploit / PoC exploited in the wildimportance 60
Full article953 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

The Pentagon's huge plan to rationalize the U.S. military's sprawling and multifarious IT infrastructure into a single Joint Information Environment is at risk of failure because of poor scheduling and budgeting, inadequate workforce planning and a failure to properly lay out the scope and objectives of the massive undertaking, a new audit says.

The Pentagon’s huge plan to rationalize the U.S. military’s sprawling and multifarious IT infrastructure into a single Joint Information Environment is at risk of failure because of poor scheduling and budgeting, inadequate workforce planning and a failure to properly lay out the scope and objectives of the massive undertaking, a new audit says.

The Department of Defense ‘has not adequately defined the effort’s scope or expected cost,’ write auditors from the Government accountability Office in a report out this week.

For example, auditors state, the 2013 JIE implementation strategy includes software application rationalization and desktop virtualization as part of the project. But ‘briefings provided to congressional staff and to us in 2015 did not specifically include this element.’

‘In addition, DOD has not established a reliable schedule or sufficiently developed workforce and security assessment plans,’ they add.

The huge scale of the JIE undertaking incorporates the U.S. military’s 65,000 servers, and 7 million endpoints — all connected to 15,000 different networks — used by DOD’s 1.3 million military active duty and 742,000 civilian personnel, who are based at more than 555,000 facilities scattered across the globe.

‘As a result of the program’s management and planning weaknesses, DOD decision makers and congressional stakeholders lack reliable information needed to make informed decisions about progress and needed changes,’ the report’s authors state.

In fact, the report says, DOD officials do not even consider JIE to be a program of record. Instead, it is ‘a construct for managing improvement and modernization of DOD’s IT infrastructure and the associated operational concepts, and does not have a discrete beginning or ending such as would be expected with a program.’

Officials are paying for JIE through ‘existing DOD component programs, initiatives, technical refresh plans, acquisition processes, and funding,’ auditors say. Partly as a result, the department has no estimate of how much JIE will eventually cost.

However, officials have costed out a single element of the JIE, the Joint Regional Security Stacks, or JRSS.

According to the audit, ‘JRSS is intended to enhance network command and control, increase bandwidth, and synchronize networks. It is to be used to screen network traffic to and from DOD installations, control traffic flows, identify and block unauthorized traffic, and isolate intrusions.’

To do this, the JRSS’s will replace about 1,000 nonstandardized network security stacks, currently scattered around the world, with 48 of the new standardized stacks at 25 locations, ‘reducing the number of avenues for cyber attack.’

The Pentagon, which started spending on the JRSS in fiscal year 2013, estimates it will have spent over $900 million by the end of the current fiscal year on Sept. 30; and will spend approximately $1.6 billion more in fiscal years 2017 through 2021.

‘Until DOD determines how it will document the costs of its JIE effort and officials and congressional committees are provided accurate information about expected costs, they are limited in their ability to provide oversight for performance and make effective resource decisions,’ the audit concludes.

More Scoops

Chinese-made DJI drones
In this photo illustration, a DJI Mavic 2 Pro and DJi Mavic Mini made by the Chinese drone maker fly near each other on Dec. 15, 2021, in Miami, Florida. (Photo by Joe Raedle/Getty Images)

The pressing threat of Chinese-made drones flying above U.S. critical infrastructure 

Drones from China's DJI contain high-res cameras, advanced sensors and wireless access, opening the door for espionage and sabotage.

Director of the National Security Agency (NSA) and Commander of U.S. Cyber Command General Paul Nakasone arrives at the U.S. Capitol on June 14, 2022 in Washington, DC. Nakasone has advocated for the White House not to change DOD’s cyber operations’ authorities. (Photo by Drew Angerer/Getty Images)

Biden set to approve expansive authorities for Pentagon to carry out cyber operations

U.S. Secretary of Defense Lloyd Austin (2nd L) gives opening remarks as Chairman of the Joint Chiefs of Staff General Mark Milley (R) and Deputy Assistant Secretary of Defense for Russia, Ukraine, Eurasia Laura Cooper (L) listen during a virtual meeting of the Ukraine Defense Contact Group at the Pentagon on May 23. (Photo by Alex Wong/Getty Images)

The Pentagon may require vendors certify their software is free of known flaws. Experts are split.

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/audit-warns-of-poor-planning-on-vast-pentagon-it-plan/