Cyber strategies, cyber implementation plans, cyber mission forces – whether it’s plans, policies or people, the Defense Department is all over the cyber domain. But for all the focus on governance and the technologies for offense and defense, there’s another major area Pentagon officials must deal with: a cultural change across the department.
It turns out, defining and implementing a “cyber culture” may not be as easy as creating doctrine and training troops. That’s a chief reason Defense Secretary Ash Carter, along with other DoD officials, are focusing on culture as part of a new DoD Cybersecurity Culture Compliance Initiative, or DC3I, unveiled in a recent internal memo.
“Technical upgrades and cyber organizational changes…are only part of the solution to reliable enterprise security,” Carter and then-Joint Chiefs of Staff Chairman GEN Martin Dempsey wrote in the memo, dated Sept. 30 but released in October. “Each of us, as network users and providers, has an individual responsibility to protect the [DoD Information Networks, or DoDIN]. Nearly all past successful network penetrations can be traced to one or more human errors…raising the level of individual human performance in cybersecurity provides tremendous leverage in defending the DoDIN.”
To do that, the DC3I centers on five operational excellence principles central to the DoDIN and DoD’s cyber enterprise: integrity, level of knowledge, procedural compliance, formality and backup, and a questioning attitude, according to the memo.
Major paths toward tackling those areas will involve training, especially in what’s known as cyber hygiene – the basics of operational security on the network – and measuring what and how DoD organizations are performing against established standards and mandates.
“We are expanding what we look at in a cyber scorecard – I do think what you measure will get attention, and we are now measuring those things,” DoD CIO Terry Halvorsen said Oct. 29 at a Christian Science Monitor event in Washington. “Basic things, like are we doing two-factor authentication? Are all systems administrators using tokens so that we actually know what systems administrators are on the network? Have we put all of our public-facing and forward-facing servers behind the right set of firewalls, or other security boundaries? Have we looked at how all of our data is encrypted, or not – when should it be? There are times when data should be encrypted, so are we following all of those processes?”
Information-sharing and coordinating with industry will also be a key area that DoD will continue to build on, Halvorsen said. Already, the Pentagon engages industry in sharing cyber threat information, and Carter recently established a Silicon Valley outpost for DoD to find and onboard innovative technologies.
“We’re having a lot more discussion with industry about how we better share all of the data that’s available from both industry and the DoD, what the threats are, and then passing that around to our partners in industry and our partners inside DOD,” Halvorsen said. “All of that has to be synchronized and orchestrated in the right way to get that culture change, and that’s what we’re trying to do, and that’s what my role is – to make sure it gets done. We’re doing the measurements and trying to make sure the orchestration and all the players get connected at the right time and the right data.”




