Defense Supply Chain Management Systems Are Vulnerable, GAO Says

June 24, 2021 by Reece Nations
Defense Supply Chain Management Systems Are Vulnerable, GAO Says
The Pentagon

WASHINGTON — The Government Accountability Office issued a report this week addressing cybersecurity vulnerabilities in the Department of Defense inventory management systems used to manage the national defense supply chain.

Risks in six inventory management systems run by the Defense Logistics Agency were reviewed in the report, along with what steps have already been taken to mitigate the potential danger. GAO has identified defense cybersecurity as a high-risk area since 1997.

“To carry out the agency’s missions and account for its resources, DLA relies on information systems to access and manage supply chain, inventory, and other logistics data,” GAO officials wrote in a letter to the House Committee on Armed Services. “As such, the security of these systems and data is vital to public confidence and the nation’s safety, prosperity, and well-being. However, cyber-based intrusions and attacks on both federal and nonfederal systems have become not only more numerous and diverse, but also more damaging and disruptive.”

GAO issued a series of five recommendations in the report, ranging from revising standard operating procedures to include system-specific monitoring strategies to ensuring the DLA director incorporates residual risk information in corrective action plans. 

Another recommendation directs the DLA director to update and institute an assessment plan approval process, ensuring a designated authorizing official reviews and approves system assessment plans before the system’s evaluation.

The office also wants the DLA director to revise and carry out the agency’s process for obtaining waivers that accept “identified ongoing risk,” including 338 pending corrective action plans still awaiting waivers. 

Another recommendation of the report dictates the DLA cybersecurity Office to design and produce a process for program offices to review the consistency and completeness of authorization documentation before submitting packages to the designated authorizing officials.

“We supplemented our analysis of documents and data by interviewing officials in DLA’s Cybersecurity Office and the system program offices about their efforts to assess, document, and review security controls for their respective systems,” the GAO report read. “We then made determinations about the extent to which each system’s program office had fully addressed, partially addressed, or not addressed all aspects of the required tasks for the risk management step based on the documents and data provided.”

Of the five recommendations in the report, DLA agreed with two and partially agreed with three. DLA issued partial concurrences with the recommendations and advised a revision of standard operating procedures, the instituting of the assessment plan approval process, and the creation of a process for reviewing authorization documentation.

DLA disagreed that there weren’t monitoring strategies determining the effectiveness of security controls and that there were “missed opportunities for risk-based decisions” regarding authorization issuances. It also did not agree that there is no process for reviewing authorization documentation before submitting requests for authorization.

GAO found the agency only fully addressed and remedied two of its six risk management steps for the inventory management systems: the categorization of systems and establishing an implementation approach. According to the report, the DLA partially addressed the selection of security controls, assessment of the controls, and system authorization and monitoring of security controls.

Until the DLA addresses all of the identified deficiencies, the agency’s control over cyber risks presented to critical systems will be “impeded and potentially pose risks to other DOD systems” should the DLA systems be compromised.

“This report does not address the extent to which DLA and the selected systems’ countermeasures are able to successfully prevent certain cyberattacks,” the report’s text continued. “Rather, it focuses on DLA’s efforts to manage the cybersecurity of these six systems through a risk management framework that is intended to help managers make informed decisions about cyber threats, and to prioritize mitigations and responses to threats in the most cost-effective manner.” 

A+
a-
  • cybersecurity
  • Defense Department
  • Government Accountability Office
  • supply chain
  • In The News

    Health

    Voting

    Defense

    US Adults Fracture Along Party Lines in Support for Ukraine Military Funding, AP-NORC Poll Finds

    WASHINGTON (AP) — As Russia makes battlefield advances and Ukrainian soldiers run short on ammunition, U.S. adults have become fractured along party... Read More

    WASHINGTON (AP) — As Russia makes battlefield advances and Ukrainian soldiers run short on ammunition, U.S. adults have become fractured along party lines in their support for sending military aid to Kyiv, according to a poll from The Associated Press-NORC Center for Public Affairs Research. Democrats are more likely... Read More

    Biden Warns Opposing Ukraine Funding Plays 'Into Putin's Hands,' but Faces Resistance in House

    WASHINGTON (AP) — President Joe Biden on Tuesday called for House Republicans to urgently bring a $95.3 billion aid package... Read More

    WASHINGTON (AP) — President Joe Biden on Tuesday called for House Republicans to urgently bring a $95.3 billion aid package for Ukraine, Israel and Taiwan to a vote, warning that refusal to take up the bill, passed by the Senate in the morning, would be "playing... Read More

    December 22, 2023
    by Dan McCue
    President Signs Order Giving Civilian Fed Workers 5.2% Raise

    WASHINGTON — President Joe Biden on Thursday signed an executive order fulfilling his promise to provide civilian federal workers with... Read More

    WASHINGTON — President Joe Biden on Thursday signed an executive order fulfilling his promise to provide civilian federal workers with an average 5.2% pay raise starting in mid-January. Biden had proposed the bump in salaries in the 2024 budget proposal he released last March. According to... Read More

    December 8, 2023
    by Dan McCue
    House and Senate Reach Agreement on NDAA, Votes Expected Next Week

    WASHINGTON — The Senate and House Armed Services committees announced Thursday that they’ve reached an agreement on the FY 2024... Read More

    WASHINGTON — The Senate and House Armed Services committees announced Thursday that they’ve reached an agreement on the FY 2024 National Defense Authorization Act, jettisoning some, but not all, of the controversial amendments added by House Republicans last summer. Sens. Jack Reed, D-R.I., and Roger Wicker,... Read More

    Pence Calls Trump's Attacks on Milley 'Utterly Inexcusable' at AP-Georgetown Foreign Policy Forum

    WASHINGTON (AP) — Former Vice President Mike Pence on Tuesday criticized his former boss-turned-rival, Donald Trump, for calling retired Gen. Mark Milley, the former... Read More

    WASHINGTON (AP) — Former Vice President Mike Pence on Tuesday criticized his former boss-turned-rival, Donald Trump, for calling retired Gen. Mark Milley, the former chairman of the Joint Chiefs of Staff, a traitor over phone calls he made to China in the final stormy months of their administration. “Frankly what... Read More

    August 25, 2023
    by Tom Ramstack
    Lawmakers Assure Pacific Island Leaders US Will Help Them Stand Up to China

    WASHINGTON — Pacific island political leaders advised a congressional committee Thursday that China’s threat to them and the United States... Read More

    WASHINGTON — Pacific island political leaders advised a congressional committee Thursday that China’s threat to them and the United States is growing as its military prepares for a possible invasion of Taiwan. Guam, Micronesia and the Marshall Islands could reemerge as a focal point of conflict,... Read More

    News From The Well
    scroll top