Theater #2: Stakeholder Cyber Performance Requirements for Fielding Cyber Survivable Capabilities
- Room: Theater #2 - Booth 2300
Thursday, May 08, 2025: 10:45 AM - 11:45 AM
Speaker(s)
Description
The Department of Defense has a challenging situation fielding and sustaining warfighting capabilities, due to the threats targeting survivability of its weapon systems. However, DoD’s cyber vulnerability risk has not been due to a lack of cybersecurity strategies, policies or minimum standards to counter these threats. Instead, DoD’s cyber survivability efforts have highlighted the lack of cybersecurity and cyber resilience performance requirements considered during cost, schedule and performance risk trade space decisions.
Relying on standards compliance alone has not worked and Defense Systems Management College studies have shown:
• 70% of defects were introduced before coding began.
• 80% of defects were found after 95% of funds were committed and too late to influence design.
• 97% of rework costs were unaffordable and risks remain.
• Sponsors were left with the untenable choice of cancelling the program or accepting system risk.
The Cyber Survivability Endorsement (CSE) helps stakeholders (CEO - CMDR, COO – J3, CFO – J8) define plain language, mission focused, threat informed and system specific cyber survivability performance requirements. Acquisition can reuse these cyber performance requirements as requests for information that can act as differentiators during an alternatives analysis and contract source selection to prevent pursuit of inherently flawed capabilities, with no reasoned expectation the vulnerability risks could be cost effectively mitigated to an operationally acceptable risk posture. They can also guide system security engineers to flow zero trust activities and NIST 800-53 controls into system specifications to achieve and sustain an operationally relevant risk posture.
The CSE provides an approach for the DoD to transition the focus from cybersecurity compliance to cyber survivability performance requirements that enable cybersecurity controls and cyber resilience best practices to effectively compete for resources during risk trade-space decisions, at all acquisition milestones and knowledge points to field capabilities that are secure and resilient by design.
Listen Here
Tracks:
Handouts