GAO: DoD Just Beginning to Grapple with Scale of Cyber Vulnerabilities in Major Weapons Systems
In a new report, the Government Accountability Office examined the significant challenges facing the Department of Defense in protecting its weapons systems from increasingly sophisticated cyber threats. GAO noted that the department got a late start prioritizing cybersecurity in its weapons systems and has only a nascent understanding of how to develop more secure systems. Complicating the issue is DoD’s increased use of software and automation, and the higher likelihood that weapons are networked with each other and other defense systems.
In operational testing, DoD has routinely found mission-critical cyber vulnerabilities in systems that were under development, but program officials still told GAO they believed their weapons were secure. These officials also scoffed at some test results as unrealistic. However, GAO noted that testers were able use relatively simple tools and techniques to hijack systems and were able to operate largely undetected, due to poor password management and unencrypted communications, among other issues.
GAO also noted that DoD is likely unaware of the scope of its vulnerabilities, due to testing limitations. For example, not all programs have been tested and tests do not reflect the full range of threats. While the department has taken steps to improve weapons system cybersecurity, GAO found these actions could be limited due to workforce challenges and the difficulty sharing threat information and lessons learned.
[pdf-embedder url=”https://staging.pub-k.org/wp-content/uploads/2018/10/694913.pdf”]

