[House Hearing, 118 Congress]
[From the U.S. Government Publishing Office]


                                     

                          [H.A.S.C. No. 118-68]

                                HEARING

                                   ON
 
                   NATIONAL DEFENSE AUTHORIZATION ACT

                          FOR FISCAL YEAR 2025

                                  AND

              OVERSIGHT OF PREVIOUSLY AUTHORIZED PROGRAMS

                               BEFORE THE

                      COMMITTEE ON ARMED SERVICES

                        HOUSE OF REPRESENTATIVES

                    ONE HUNDRED EIGHTEENTH CONGRESS

                             SECOND SESSION

                               __________

    SUBCOMMITTEE ON CYBER, INFORMATION TECHNOLOGIES, AND INNOVATION

                                   ON

                            CYBER IN AN ERA

                       OF PERSISTENT ENGAGEMENT:

                  THE FISCAL YEAR 2025 BUDGET REQUEST

              FOR U.S. CYBER COMMAND AND CYBER OPERATIONS

                               __________

                              HEARING HELD
                             APRIL 10, 2024


                                     




                            ______

             U.S. GOVERNMENT PUBLISHING OFFICE 
 56-081          WASHINGTON : 2025











                                     
  


    SUBCOMMITTEE ON CYBER, INFORMATION TECHNOLOGIES, AND INNOVATION

                  MIKE GALLAGHER, Wisconsin, Chairman

MATT GAETZ, Florida                  RO KHANNA, California
LISA C. McCLAIN, Michigan            SETH MOULTON, Massachusetts
PAT FALLON, Texas                    WILLIAM R. KEATING, Massachusetts
DALE W. STRONG, Alabama              ANDY KIM, New Jersey
MORGAN LUTTRELL, Texas               ELISSA SLOTKIN, Michigan
JENNIFER A. KIGGANS, Virginia        JARED F. GOLDEN, Maine
NICK LaLOTA, New York                PATRICK RYAN, New York
RICHARD McCORMICK, Georgia           CHRISTOPHER R. DELUZIO, 
                                         Pennsylvania

               Joshua Stiefel, Professional Staff Member
               Michael Hermann, Professional Staff Member
                    Brooke Alred, Research Assistant
                            C O N T E N T S

                              ----------                              
                                                                   Page

              STATEMENTS PRESENTED BY MEMBERS OF CONGRESS

Gallagher, Hon. Mike, a Representative from Wisconsin, Chairman, 
  Subcommittee on Cyber, Information Technologies, and Innovation     1

                               WITNESSES

Haugh, Gen Timothy D., USAF, Commander, U.S. Cyber Command; 
  Director, National Security Agency/Chief, Central Security 
  Service........................................................     4
Manning, Ashley, Performing the Duties of the Assistant Secretary 
  of Defense for Cyber Policy....................................     3

                                APPENDIX

Prepared Statements:

    Haugh, Gen Timothy D.........................................    45
    Khanna, Mr. Ro...............................................    27
    Manning, Ashley..............................................    29

Documents Submitted for the Record:

    Gallagher, Hon. Mike.........................................    63

Witness Responses to Questions Asked During the Hearing:

    [There were no Questions submitted during the hearing.]

Questions Submitted by Members Post Hearing:

    Mrs. McClain.................................................    87
    Mr. LaLota...................................................    89
    Mr. Wittman..................................................    92
 CYBER IN AN ERA OF PERSISTENT ENGAGEMENT: THE FISCAL YEAR 2025 BUDGET 
          REQUEST FOR U.S. CYBER COMMAND AND CYBER OPERATIONS

                              ----------                              

                  House of Representatives,
                       Committee on Armed Services,
      Subcommittee on Cyber, Information Technologies, and 
                                                Innovation,
                         Washington, DC, Wednesday, April 10, 2024.
    The subcommittee met, pursuant to call, at 3:33 p.m., in 
room 2212, Rayburn House Office Building, Hon. Mike Gallagher 
(chairman of the subcommittee) presiding.

OPENING STATEMENT OF HON. MIKE GALLAGHER, A REPRESENTATIVE FROM 
          WISCONSIN, CHAIRMAN, SUBCOMMITTEE ON CYBER, 
             INFORMATIONCHNOLOGIES, AND INNOVATION

    Mr. Gallagher. The subcommittee will come to order.
    This will likely be my final hearing as chairman of the 
subcommittee. And before we get underway, I want to thank--
well, he is not here. I was going to--I had this whole nice 
thing prepared to thank Ro Khanna for his partnership. We will 
have to save all the sappy stuff for when he actually gets 
here. But he is amazing, and we have had a great partnership.
    And being on this committee for 8 years has been a 
highlight of my time in office, and I want to thank all the 
members. And Matt and I have sat next to each other for 8 years 
now and had a lot of late-night debates during NDAA [National 
Defense Authorization Act] markup, and I have--and often 
collaborations when it comes to AUMF [Authorization for Use of 
Military Force] issues. And I have sincerely enjoyed that.
    So today we are going to--we are going to hear from the 
Department on its budget request and plan for cyberspace 
operations for the coming fiscal year. From 2013 to 2023, 
Congress tried to address force design and readiness through 24 
different pieces of legislation, civilian and military 
workforce issues via 45 separate provisions of law, and cyber 
security at the Defense Industrial Base in 42 provisions of 
law. That is a lot of activity.
    Through this latest NDAA, we incorporated new requirements, 
reports, and mandates into each of those same categories, and 
yet here we are. There are still significant issues with our 
force design, our civilian and military workforce issues remain 
as challenging as they have been in the past 10 years, and 
several cyber incidents targeting the Defense Industrial Base 
have demonstrated that we are as vulnerable now as we were a 
decade ago.
    And just as I said when we were here a year ago for this 
same cyber posture hearing, insanity is doing the same thing 
over and over again and expecting different outcomes. I believe 
that almost everyone here today is familiar with a report 
published just 2 weeks ago by the Foundation for the Defense of 
Democracies on the issue of a cyber force, a proposed new 
branch of the armed forces dedicated to the cyber domain.
    This new force would be responsible for organizing, 
training, and equipping for the cyber domain, no different from 
the Navy for combat at sea or the Air Force as the service 
responsible for air warfare.
    The report is very compelling. And, as I said, in an event 
we did a couple of weeks ago, I came in as a skeptic, but I 
think they have raised some very important issues that need to 
be addressed, and it is a debate that is worth having because I 
think the status quo right now is unacceptable.
    But the arguments were not--the cogent arguments in the 
report are not the only thing that stood out. Included in the 
report were personal accounts provided anonymously by more than 
75 active and recently separated service members representing 
every military branch and rank from E-7 to O-7 as well as 
senior civilians. Not a single individual that was approached 
declined to respond, nor did any one of them argue in favor of 
the current approach in which the operational force is sourced 
from four separate military services.
    I, therefore, ask unanimous general consent to enter this 
report into the record. So ordered.
    [The information referred to can be found in the Appendix 
on page 63.]
    Mr. Gallagher. I will admit, again, I had concerns at the 
start of this debate, but over the last 18 months I have been 
presented with an astounding array of data and arguments in 
favor of a cyber force, as well as a number of convincing 
arguments opposing such a force. In my mind, the most logical 
way to address this question is a fully independent evaluation 
of the notional cyber force to be led by an entity other than 
the Department of Defense--other than the Department of Defense 
is critical.
    If anyone is opposed to a study of this question, I believe 
there is only one way to interpret that opposition, which is 
that if you are unwilling to ask the question, what you are 
really saying is that you are scared of the answer you might 
receive and the actions we will have to take to address the 
problem. When it comes to national security, that way of 
thinking--acceptance of risk because of fear--I think is 
unacceptable.
    And while I may not be chair of this subcommittee during 
this year's NDAA markup, I hope my colleagues will make the 
right decision and work collectively to ensure the Department 
of Defense is directed to conduct such a study when the time 
comes.
    With that as context, I am very eager to hear from both of 
our witnesses--thank you for being here--each appearing for 
their inaugural cyber posture hearing. There is a whole set of 
elaborate initiation events that we have to do afterwards. It 
is highly top secret. But we are joined by Ms. Ashley Manning, 
a career senior executive performing the duties of Assistant 
Secretary of Defense for Cyber Policy, and General Tim Haugh, 
the Commander of the United States Cyber Command. Thank you 
both for appearing today.
    At this point, I would turn it over to the ranking member. 
He is not yet here. Here is on his way from an oversight 
hearing, but I ask that his opening remarks be entered into the 
record. I ask unanimous consent for that to happen, and then 
something magically happens and it goes into the record.
    [The prepared statement of Mr. Khanna to can be found in 
the Appendix on page 27.]
    Mr. Gallagher. And, with that, we go to Ms. Manning first, 
correct, for 5 minutes.

   STATEMENT OF ASHLEY MANNING, PERFORMING THE DUTIES OF THE 
        ASSISTANT SECRETARY OF DEFENSE FOR CYBER POLICY

    Ms. Manning. Chairman Gallagher, Ranking Member Khanna, and 
distinguished members of the committee, thank you for inviting 
me to testify on the Department of Defense's cyber posture and 
the advancements we continue to make operationalizing the 
Department's priorities in cyberspace. It is an honor to appear 
alongside General Haugh.
    In my role Performing the Duties of Assistant Secretary of 
Defense for Cyber Policy, I am committed to providing overall 
supervision of the Department's policy for cyber, advancing the 
Department's strategic approach to cyberspace, and ensuring our 
readiness to counter emerging cyber threats.
    Mr. Chairman, I look forward to working with this committee 
through my newly established office to further these 
objectives.
    I come to this role as a career civilian with almost 20 
years of service in the Department of Defense. I have had the 
privilege of working across a wide range of regional and 
functional issues, serving most recently as the Acting Deputy 
Assistant Secretary of Defense for the Middle East and the 
Principal Director for Plans and for Posture. And in my 
previous positions, I have witnessed the cross-cutting role 
cyber plays in the defense of our Nation and our allies and 
partners.
    The President has nominated Dr. Michael Sulmeyer as the ASD 
[Assistant Secretary of Defense] for Cyber Policy. Should he be 
confirmed, I look forward to serving as the Principal Deputy 
Assistant Secretary of Defense for Cyber Policy.
    Our National Defense Strategy makes clear that the People's 
Republic of China remains an enduring cyber threat and the 
Department's pacing challenge in cyberspace, as the PRC 
[People's Republic of China] continues to target U.S. networks 
in prolonged campaigns of espionage and to pre-position its 
cyber forces for future operations.
    Russia remains a persistent threat to the United States and 
our allies and partners, as it continues to leverage cyberspace 
to target critical infrastructure networks and enable its 
malign influence operations. The ongoing, unprovoked, further 
invasion of Ukraine serves as a stark reminder of Russia's 
willingness to employ cyber capabilities to disrupt defensive 
military operations and sow discord.
    Following Hamas's attack against Israel on October 7 of 
last year, Iran has exploited cyberspace to create additional 
disruptions and challenges in Israel. While many of these 
malicious cyberspace activities have been relatively limited in 
their impact, the ability of both state and non-state actors to 
act against Israel in the immediate aftermath of the attack by 
Hamas is a reminder of what to expect in future conflicts.
    Additionally, the United States continues to face the 
still-growing threat posed by for-profit cyber criminals that 
target a wide array of vulnerable sectors, conducting 
ransomware attacks that impact the daily lives of Americans 
across the country.
    In response to these evolving challenges, the Department 
issued its fourth DOD [Department of Defense] Cyber Strategy 
last May. Looking ahead, we are committed to implementing our 
strategy and monitoring progress through the forthcoming cyber 
posture review in fiscal year 2026.
    We understand the Department cannot advance its defense 
priorities without a ready, capable, and informed joint force. 
To achieve this end, we will invest in our people, in our 
capabilities, and in our information needs to support and 
enable the full range of cyber activities.
    In partnership with USCYBERCOM [U.S. Cyber Command], we are 
refining options for the secretary on how to improve the way in 
which forces are presented to the command to raise the 
readiness level of these forces and to streamline support 
mechanisms to other combatant commands. These options will 
enable USCYBERCOM to fully exercise authorities in partnership 
with my office, including through enhanced budget control.
    As part of the fiscal year 2026 budget cycle, DOD released 
its first-ever Department-wide Cyber Operations Programming 
Guidance. This guidance will shape future cyberspace operations 
investments and will serve as a rubric for my office's 
certification of the budget's adequacy for fiscal year 2026.
    With the authorities granted to us by Congress, the 
Department will continue to build on the pathway laid out in 
the fiscal year--or, I am sorry, in the 2023 DOD Cyber Strategy 
to provide a stronger cyber posture and protect the shared 
digital environment for those who intend to subvert our values 
and our interests by pursuing integrated deterrence, which 
includes our cyber capabilities.
    The Department will be ready to fight and win the Nation's 
wars with an ability to rapidly respond across the spectrum of 
conflict. Thank you for your continued support in this fight, 
and I look forward to answering your questions.
    [The prepared statement of Ms. Manning can be found in the 
Appendix on page 29.]
    Mr. Gallagher. Thank you.
    General, you are recognized for 5 minutes.

 STATEMENT OF GENERAL TIMOTHY D. HAUGH, USAF, COMMANDER, U.S. 
   CYBER COMMAND, DIRECTOR, NATIONAL SECURITY AGENCY/CHIEF, 
                    CENTRAL SECURITY SERVICE

    General Haugh. Chairman Gallagher, Ranking Member Khanna, 
and distinguished members of the committee, thank you for the 
opportunity to testify before you today. I am honored to 
testify beside Ms. Manning. Joining me today is Chief Master 
Sergeant Kenneth Bruce, the U.S. Cyber Command and National 
Security Agency Senior Enlisted Leader. We are honored to 
represent the men and women of U.S. Cyber Command.
    In an era defined by rapid technological advancement and 
increasing interconnectedness, cyberspace has emerged as a 
vital domain for protecting our national security. The People's 
Republic of China is our greatest strategic competitor and 
poses unique challenges due to its advanced cyber capabilities, 
state-sponsored cyber operations around the globe, and a 
strategic focus on leveraging cyberspace for military, 
economic, and political purposes.
    Russia's cyber espionage campaigns prioritize sensitive 
U.S. Government and military infrastructure and information and 
spread disinformation campaigns to influence public opinion and 
undermine our democratic processes. Iran, North Korea, 
terrorist organizations, and transnational criminal groups also 
challenge U.S. interests in cyberspace. And we are engaged in 
ongoing efforts to exploit vulnerabilities--and are engaged in 
ongoing efforts to exploit vulnerabilities in U.S. networks, 
conduct influence operations, and erode our national security 
interests.
    With cyber operations becoming more sophisticated and 
frequent, it is vital to evolve our capabilities against new 
and novel threats. I am confident Cyber Command is well 
postured to meet the ever-evolving challenges we face today, 
creating advantage for the Department and the Nation.
    Our mission is to direct, synchronize, and coordinate 
cyberspace planning and operations to defend and advance 
national interests in collaboration with domestic and 
international partners.
    We defend forward by countering cyber threats before they 
can reach U.S. networks and critical infrastructure. These 
proactive defensive measures ranging from network hardening and 
threat hunting to information sharing bolster the resilience of 
our systems and foil potential cyber attacks before they can 
materialize.
    We are aligned with the National Defense Strategy and the 
DOD Cyber Strategy to protect Department of Defense information 
systems, support Joint Force commanders with cyberspace 
operations, and defend the Nation from significant cyber 
attacks.
    I am excited with what 2024 means for the maturation of 
U.S. Cyber Command. This is a year of opportunity for us, and I 
would like to thank Congress for the service like enhanced 
budget control authorities granted by the 2022 NDAA and enacted 
with the fiscal year 2024 appropriation. This authority creates 
tighter alignment between requirements and acquisition, which 
will result in faster capability and fielding for our cyber 
mission force.
    Additionally, this committee has been instrumental in 
focusing attention on readiness across the cyber mission force. 
The studies you have authorized are driving us to do work 
needed to ensure we have the force structure and force 
generation strategy necessary to field a force of the highest 
quality today.
    I hope we have an opportunity to unpack several of these 
initiatives today. Since Cyber Command's elevation in 2018 to a 
unified combatant command, Cyber Command has worked to make 
most of its authorities, resources, and support. Of these 
authorities, None is as vital to national security and the 
command as Section 702 of the Foreign Intelligence Surveillance 
Act, which is essential for identifying malicious cyber actors 
in protection of the Nation and the Department of Defense.
    I am confident we are successful in our mission each and 
every day thanks to our people, our innovation, and our 
partnerships--my top three priorities that ensure we deliver 
outcomes against national priorities in foreign intelligence 
and cyber security.
    First, our strength lies in our people. Skilled cyber 
warriors who are dedicated to protecting the Nation from 
threats posed by our rivals and adversaries in cyberspace. We 
win because of our people.
    Second, Cyber Command remains committed to a relentless 
approach in innovation to strengthen our military, now and into 
the future. Our investment in technological innovation is key 
to maintaining our overmatch against our adversaries.
    Lastly, Cyber Command maintains our competitive advantage 
through sustained and deliberate partnerships. In addition to 
the unique partnership of the National Security Agency, Cyber 
Command further embraces a team approach, working with my 
fellow combatant commanders and interagency partners while also 
collaborating with academic and industry experts, and 
cooperating with our allies and partners by establishing 
collective security.
    I am extremely proud of the efforts Cyber Command has 
achieved and the direction we are headed. I look forward to 
your questions.
    [The prepared statement of General Haugh can be found in 
the Appendix on page 45.]
    Mr. Gallagher. Thank you, General. You expressed, I 
believe, that the Section 15--I am recognizing myself for 
questions, in case that was not apparent. The Section 1533 
study was looking at all options, to include the establishment 
of the separate service and, hence, a separate analysis isn't 
necessary.
    But we required the Department to do the study in the 2020 
NDAA, specifically to study the independent service idea as 
part of the cyber posture review. It seems to me that DOD 
ignored that requirement and then pointed us to a section in 
the posture review that included an assessment. But if you look 
at that section, no such assessment existed.
    With this as context, I guess we will, one, address that. 
But why should we believe that the Department will follow on 
with an objective analysis as part of the 1533 study, given 
that it was ignored previous to this.
    General Haugh. Chairman Gallagher, I have no experience 
with the 2020 study. I can tell you what we are doing today. So 
we have taken that direction, and we have really--that is an 
area for us that is really about the readiness of our force, 
and how do we generate our force. So we have looked at that, in 
combination with other studies that you have asked us to do 
this year.
    So there are other studies to look at our headquarters, to 
look at our acquisition force, to look at how we examine our 
architecture. And each of those we think make up a really good 
opportunity for us to evaluate what is the future of this 
force. So specific to your question on 1533, and the study that 
is underway, the bookends that are required by the law are the 
way it was done last year and an evaluation of a cyber service. 
We are going to look at both of those bookends, and then look 
at options in between that would allow us to generate the force 
that we need.
    The other things that I think are--that I know we are doing 
today is the partnership we have with ASD Cyber, who is the 
other portion of the study. So being done with ASD Cyber in OSD 
[Office of the Secretary of Defense] and Cyber Command. We owe 
that to the secretary in June, and we are required to brief him 
in June the results of that study, and we are moving at pace to 
ensure that we look at all of the options that you directed.
    Mr. Gallagher. Now, I am on record as favoring something 
like a zero-based budgeting for congressional studies because 
they accumulate over time, and periodically we need to sort of 
clear them out. But when they are a matter of U.S. law, they 
should be complied with.
    Ms. Manning, do you know how many congressional 
requirements DOD is currently delinquent on?
    Ms. Manning. Thank you for your question, Mr. Chairman. 
This is actually one of the first questions I asked when I got 
into the seat. And we are tracking 12 reports where our office 
is the office of primary responsibility to be able to conduct 
and conclude these reports.
    I received a status update on all of these reports. There 
are a couple that have been delayed because they were 
independent studies that were dependent on getting funding, and 
because of the continuing resolutions it has gotten delayed a 
little bit. But my commitment to you is to make progress on all 
of these reports and ensure that we are delivering them as 
quickly as possible.
    I would note that there are a myriad of other reports 
related to cyber that have been directed across the Department, 
and we are providing support as a coordinating entity on many 
of those reports. And, in the interim, if there are specific 
issues where you want to understand a bit more about what the 
Department is doing and how we are addressing issues, myself 
and my team are always willing to come up and brief you on 
those.
    Mr. Gallagher. I appreciate that. We are tracking 40, but 
that may be a broader aperture than just your office, but we 
very much would like to clear the backlog and work with both of 
you on clearing the backlog, because, again, wherever those 
reports appear it means that we--you know, we voted on it. We 
had a debate on it, and it means there is questions we just 
need answers to. And so I just would welcome your commitment to 
clearing that backlog.
    Ms. Manning, your office will also be assuming the 
responsibility for certifying the cyberspace operations budget 
within DOD. Last year we were informed that the fiscal year 
2024 cyber ops budget was 7.4 billion, but then this year the 
fiscal year 2025 ops budget, if I am correct, is 6.4 billion.
    What we are trying to understand is, does this represent a 
net decrease or a confusion about categorizing investments? Can 
you share your view of what appears to be a net reduction of 
nearly 1 billion or more than 15 percent of the overall budget?
    Ms. Manning. Thank you for your question on our budget, 
because it is really important that we get this right. So my 
understanding is that overall our cyber activities' budget has 
increased by almost a billion dollars due to added investment 
in cyber security. The teams in both policy and in the Office 
of the Chief Information Officer reviewed the various efforts 
that are included in the different budgets and decided that 
certain portions of the cyber ops budget are actually better 
categorized as part of the cyber security budget. So there is 
no reduction. It is more of a recategorization of some of the 
activities that we are funding between the different budget 
categories.
    Mr. Gallagher. Thank you. My time has expired.
    Mr. Khanna is recognized for 5 minutes.
    Mr. Khanna. Thank you, Mr. Chair. Apologies for being a few 
minutes late. We had an oversight hearing where I had to vote.
    General Haugh, great to see you again. I appreciated our 
conversation the other day.
    And, Ms. Manning, thank you for your testimony.
    General Haugh, one of the things that we had discussed is 
the importance of getting young talent into our military 
service, particularly young talent in technology. The military 
can also be a place where they develop initial skills and 
training, something that may be more accessible, frankly, for 
people than just starting in Silicon Valley, which often does 
not have as, unfortunately, broad-based hiring.
    Can you talk about efforts at creating recruiting programs 
at community colleges or historically black colleges, Hispanic-
serving institutes, and other public universities across the 
country, that would allow us to recruit folks and perhaps even 
recruit folks who may not have a 4-year degree?
    General Haugh. Certainly, Ranking Member Khanna. This is 
our important issue is, how do we grow talent and for--for U.S. 
Cyber Command, for the Department, for the Nation. And so when 
we look across what Cyber Command and NSA [National Security 
Agency] are responsible for, in Cyber Command we have now grown 
an academic network to allow us to partner with universities 
across the country. So we have right now around 120 
universities; in the National Security Agency, around 430. Both 
of those provide a really foundational opportunity for us to 
participate with our academic institutions on growing cyber 
curriculum and also working with a number of research 
institutions to be able to allow us to recruit that talent.
    So when we think about it internally to our organizations, 
that is how we maintain our partnership, growing relationships 
with historically black colleges and universities, and also 
looking at universities like University of Texas at San 
Antonio, that has a large number of first-generation Americans 
and Hispanic-Latino population. Drawing talent from across the 
country to be able to ensure that we have the highest qualified 
workforce.
    Mr. Khanna. And do you need more flexibility from Congress? 
Because I have heard mixed things in terms of you want someone 
to come for 3 years, 4 years, and then they want to go on to 
the private sector. Are you able to do that? Are you able to 
have flexibility if you want to recruit someone who doesn't 
have a college degree and is talented or wants to do a few 
years? Or do you need more flexibility in the hiring?
    General Haugh. So last year one of the studies that we 
executed was under Section 1502, and it was about readiness. 
And I am required each year to provide a report on service 
readiness. In that report, we identified five provisions that 
were all around personnel and administrative policies. So what 
we are really looking for is we are seeing good things 
happening in each of the services. We would like them all to 
adapt each others' best practice.
    So as you identified in this NDAA, Section 1535 was to 
begin to drive those authorities across the Department. And I 
think that would be an example of a step where we want to 
continue to provide updates on which types of provisions would 
help and then we work together with the services to be able to 
enact those provisions.
    Mr. Khanna. Ms. Manning, I don't know if you have any 
comments or thoughts on how we recruit more talent into our 
military.
    Ms. Manning. I would say, first of all, I really applaud 
the efforts that are underway to tackle this issue. It is a 
real challenge across government in terms of how you recruit 
and retain top talent to support our ongoing efforts, and 
really building out the workforce that is necessary for us to 
be able to accomplish our operational missions.
    So I think, in addition to what we are dealing with in the 
Department, I think looking at sharing best practices across 
other departments and agencies will help generate new ideas in 
terms of what more we can do as a government to ensure that we 
are bringing people in to be able to serve our missions.
    Mr. Khanna. One of the things--and you don't have to answer 
it now, but I have just been told that there are some 
restrictions on people being able to be hired only for a few 
years, that that is hard to do because of civil service 
protections. I don't know if that is the case or not, but I 
just--I didn't know if Congress needs to act in any way to 
simplify that.
    General Haugh. What I would expect you are referring to is 
our ability to have people leave and come back.
    Mr. Khanna. Right.
    General Haugh. And those are areas that I think we have got 
to work internally within the Department in terms of how we 
leverage the policies that we already have, but I think that is 
an area that we should be continuing to explore, that if 
somebody leaves and goes to industry, how do we bring that 
expertise back into our force, not as if they are a new hire 
but they are returning expert back into the Department.
    Mr. Khanna. Thank you.
    Mr. Gallagher. Mr. Gaetz.
    Mr. Gaetz. Ms. Manning, I think you are totally right when 
you say that China is prepositioning capabilities in advance of 
some deployment of them. Is one way China does that by having 
U.S.-based technology platforms that they own or control in 
order to preposition for their cyber capability?
    Ms. Manning. Thank you for your question. You know, as I 
said, PRC is really our pacing challenge. And, as you note, 
they are using malicious cyber activity to counter U.S. 
conventional military power and to degrade the combat 
capability of the Joint Force. And we need to ensure that we 
are employing both defensive and offensive capabilities to 
strengthen our deterrence and gain our advantage.
    I defer to General Haugh for more of the details when it 
comes to how we are operating.
    Mr. Gaetz. Yeah. I am really interested in the defensive 
part vis-a-vis like what China might be doing with technology 
platforms in the United States. Do you have anything to add on 
that, General?
    General Haugh. So I think the area where we have seen 
specific action that has concerned us is hacking activity at 
our critical infrastructure and at Guam. I think those are 
specific examples. In use of technology within the United 
States, having Huawei presence, and things like that, is risk. 
We----
    Mr. Gaetz. Right. So that is what I want to get into, 
because I agree. The hacking is sort of like if they are 
breaking into your house, but the Huawei example you give is 
more like inviting them in the front door.
    Have either of you heard of this company called Tutor.com? 
All right. So this is a technology platform that is owned by 
Chinese nationals through the Primavera Holdings Limited 
company, and it is principally used by DODEA [Department of 
Defense Education Activity], by the Department of Defense's 
education system, for military connected families.
    If you had a technology platform that was being used 
specifically by military families owned by Chinese nationals, 
would that raise any red flags based on what you are talking 
about regarding the need to be well-resilient to that 
prepositioning that Ms. Manning discussed?
    General Haugh. I think we want to dive deeper and ensure 
that we are not bringing risk in, by whomever we partner with 
and whatever company.
    Mr. Gaetz. Yeah. No, I would just encourage it, because 
this one sort of--I mean, I know how much you care about 
resilience, particularly with our service members and their 
families. We all know that they are targets oftentimes. And so 
if we are inviting the Chinese in the front door here, I just 
would advise you to look at that.
    And I would draw your attention to the fact that Manny 
Diaz, the Commissioner of Education in the State of Florida, 
has advised superintendents of schools and charter schools to 
discontinue the use of this technology. And even after the 
State of Florida Secretary of Education made that pronouncement 
based on these ties, the Department of Defense education system 
continued to offer that platform to students of military 
connected families in Florida and elsewhere.
    So shifting gears just briefly to this concept of the cyber 
force, I want to draw a finer point on what Mr. Khanna was 
saying about recruitment. I have noticed anecdotally at our 
academy nights that we have in our district that we get a lot 
of students that are real interested in going to the academies, 
and they are fired up about space force.
    And I never really understood how a focused mission set 
like that could really ignite a great deal of interest. And do 
you think that we could get the same type of positive effect 
with the cyber force to recruit specific people for a specific 
domain? General?
    General Haugh. So I think from our standpoint what we have 
done is we have really focused on, what are the services doing? 
How are they doing in terms of recruiting? One of the----
    Mr. Gaetz. They are not doing great.
    General Haugh. So what they have done, Congressman, is in 
specific areas, particularly as I look--the area we focused on 
has been the Navy, and as we have looked at where the Navy's 
readiness has been. This past year, the Navy got 100 percent of 
their cyber warfare technicians in terms of their recruiting 
numbers. That shows me the services can do it, and that a 
focused effort and continue and sustain that they will be able 
to meet some of those marks.
    Mr. Gaetz. I am open-minded. I think Chairman Gallagher 
made some good points.
    And, Mr. Chairman, before my time concludes, I wanted to 
thank you for your outstanding service as chairman of our 
subcommittee, your great work on the House Armed Services 
Committee, and in the House more broadly. It has certainly been 
to the country's benefit, and it has been to my personal 
benefit to sit next to you for 7 years, 8 years, and to learn a 
great deal from you along the way.
    And I know many of our committee members feel the same, 
that the thoughtfulness you brought to the position has 
certainly been a great--been a great benefit to all of us. So 
greatly appreciate it and yield back.
    Mr. Khanna. Mr. Chairman, if I could speak out of order, 
because I didn't know this was your last meeting, and I don't 
know if there is an objection. But I just want to say from the 
Democratic side that it has really been a pleasure working with 
you, and you have displayed a patriotism and bipartisanship on 
this committee that I think has been a model for what 
leadership looks like. Even when we have disagreed, I have 
never questioned that you have put the country's interests 
first. And I know that this isn't going to be the last of your 
public service. And you certainly have someone who is an 
admirer on this side, and I think many of my colleagues feel 
the same.
    Mr. Gallagher. I very much appreciate it.
    Mr. Ryan.
    Mr. Ryan. All right. Well, I guess I am not allowed to say 
nice things, so----
    [Laughter.]
    Mr. Ryan. Thank you, Mr. Chair. I will leave it at that, on 
many levels.
    And thank you both for being here. I want to build on some 
of the different directions some of my colleagues were taking, 
particularly honing in on as we continue to, to everyone's 
credit, across the board develop more mature and robust and 
sort of broader cyber capability, I want to push and get your 
thoughts, General, on kind of that--what is that right 
intersection point between CYBERCOM services, COCOMs [combatant 
commands]?
    I know that is a very broad question, so maybe to hone it a 
little bit, can you--let's talk about--let's look actually at 
the EUCOM [U.S. European Command] AOR [area of responsibility], 
for example, just as--in theory. How is that playing out right 
now? Where do you see the future going in terms of, as we build 
more capability, how--what is the right handoff point to COCOMs 
and services? Does that make sense?
    General Haugh. It does. And what I would first start with 
is, where are we today, in terms of now the authorities that 
you have given us and the Department has given U.S. Cyber 
Command? For the real general standup of U.S. Cyber Command, 
our goal has been to become SOCOM-like [U.S. Special Operations 
Command], to have service-like authorities.
    Two weeks ago when the appropriation passed, that is the 
first time that we have now had service-like authorities to do 
budget, to do acquisition, to set the training standards for 
the Department. So now what we really want to be graded on is, 
what is our ability to generate new capability?
    So, as things emerge, so today our partnership with EUCOM 
is really strong, and I was the component to EUCOM as the Air 
Force Cyber Commander and the 16th Air Force Commander at the 
outset of Russia-Ukraine. And so that partnership is really 
about them driving priorities in that theater, and then how we 
leverage each of our components to be able to respond to that, 
to be able to do defensive activities at their priority, but 
also to be able to generate options that give a number of 
things to the secretary and to the EUCOM commander that allow 
us to consider how we would impose costs based off of their 
guidance and direction.
    I think it has worked well. I think the area that we need 
to be able to accelerate is capability development. And how we 
use our budget control and our authorities to generate and 
acquisition, we should be able to develop things faster than 
anybody else in the Department. The only thing we are 
developing is code. How do we do that faster? How do we get it 
in the hands of our cyber mission force faster?
    Mr. Ryan. And you see that primarily happening or the large 
preponderance of it happening at need essentially rather than 
out there. Where do you--where do you see that?
    General Haugh. We see increasingly that that would be a 
balance. We will drive the requirement, we will drive the 
overall acquisition oversight, and the dollars, but we will 
also partner with the services. It will just look different. 
Whereas, before the services would be able to do--were doing 
that in support of their own forces they presented, which was 
very disconnected from operations.
    We are now going to be able to drive that, and we have got 
good service partnerships with their program offices and with 
their acquisition force. So we need to be able to move faster, 
and we need to be able to recast those relationships that are 
more responsive.
    Mr. Ryan. And last follow up on this thread. So am I 
hearing you right that the general direction, though, is more 
capability at the CYBERCOM command level to push more, you 
know, technical capabilities out there? Do you have the--do you 
have enough sort of people and capability at your level to do 
that? Like do you see the direction--do we have the pace that 
we need? Do you have the resources you need to speed that up?
    General Haugh. So from our perspective, the Department has 
asked us to be the integrator of the joint cyber warfighting 
architecture. That is the--those are the platforms and 
capabilities that Cyber Command fights from. So for that now, 
we have got to be able to drive that with our authorities.
    Our team that we have from an acquisition perspective I am 
very confident in. They are small. We have now been given more 
resources. We have to hire quickly, and we have to use the 
authorities that Congress has given us to be able to hire data 
scientists under what we previously knew as the Section 1708 
authority. We have now started to hire. We have got the policy 
in place. So we have got to use all of those tools to really 
accelerate our acquisition team to be able to meet those 
objectives.
    Mr. Ryan. I only have 40 seconds, but at the--as you look 
10 years ahead, or 20 even, in terms of the quality of the 
American, essentially, you are getting to show up, what more do 
we need to do at the sort of community college level, high 
school level? I know that is a big question for 30 seconds, 
but----
    General Haugh. So I think we have an opportunity. We have 
expertise, and we have got partnerships across the--really, the 
cadre of higher institutions that are really focused on cyber. 
We can help influence that curriculum. How do we accelerate the 
curriculum in a way that allows them to adopt and then to be 
able to make it more available, particularly as technology 
changes? Because I think what we find when we receive somebody 
today, they have a good foundation, but they are not 
necessarily current today.
    Mr. Ryan. Thank you. I yield back, Mr. Chair.
    Mr. Gallagher. Dr. McCormick.
    Dr. McCormick. Thank you, Mr. Chair. And at the risk of 
being gaveled out for being out of order in this--in this era 
of politics where people are vilified for agreeing and vilified 
for dissenting, Mr. Chair, it has been an honor to serve with 
you, my fellow Marine. Let me just summarize by saying you can 
be my wingman anytime. I am the Top Gun class, so I can say 
that.
    Considering we are at war, basically cyber war right now, 
and our adversaries are attacking us regularly, almost 
momentarily, around the clock, 24 hours a day, and how AI 
[artificial intelligence] will affect that into the future and 
accelerate that process, a lot of times the perception at least 
is that we are always on the defense.
    I was hoping, General, you could actually address that over 
the last 2 years the new concept, such as persistent 
engagement. Hunt forward and defend forward have started to 
dominate the conversation, and I was hoping you could elaborate 
on how the wider concepts are distinct from each other as we go 
forward.
    General Haugh. Congressman, thank you for the question. So, 
first, as we think about campaigning against any one of those 
adversaries that are targeting either our Nation or the 
Department, we really think of it through three lenses. First, 
how do we generate insights? How do we understand what is 
underway? How do we communicate that to the broadest audience 
possible? How do we enable defense? That is enabling industry, 
it is enabling the Department, it is enabling our foreign 
partners. And then, what are our options to impose costs?
    Some of those are how we use our defensive force, and then 
others are how we partner across the interagency, and then how 
we generate options that allow us to contest in cyberspace. So 
I think from our perspective we want to be able to bring a full 
menu of not only defensive activities but those things that we 
can do from both the interagency and from the Department to 
impose costs.
    Dr. McCormick. Is there anything that we can do to keep you 
from being inhibited from doing what you need to do to be 
optimized going forward using AI and other weapons that we have 
to be not just posturing defensively but also being proactive?
    General Haugh. So I think what you have done is you have 
empowered us in a number of different ways in terms of how we 
have brought together our acquisition force and how we have 
brought together our authorities. We will identify areas 
throughout this year, as we begin to use those authorities, 
that I suspect you will start to see in budget requests for 
fiscal year 2026.
    We are going to learn a lot with the establishment of our 
AI task force. We completed an AI roadmap last year, and that 
lays out for us the technologies that we want to begin to 
experiment with and pilot and introduce to our force. Those 
will be areas that I would expect you are going to see from us 
in the future.
    Dr. McCormick. That is great. With that said, now that we 
looked--this was brought up, interestingly enough, by our 
chair, as far as the integrated Cyber Command versus the 
individual departments. I have had plenty of people here 
testify saying, well, we like--can I keep this in columns, 
because each service has its own specific requirements.
    But as AI continues to be a problem in integration, whether 
it be on weapons systems, information collecting, dissemination 
of information, the way it needs to be integrated throughout 
purple force, if you will, my concern is that we will have 
difficulties integrating even different weapons systems, let 
alone the comprehensive battlefield, like when you talk about 
purple assets, whether it be electronic jamming or information 
gathering.
    I am just wondering, is there a compromise in there that we 
could come to in information sharing? Which is already the 
biggest problem we have in the military anyway. It is just kind 
of our Achilles heel, whether it be through COMs [commands] or 
just getting the right information to the right people in the 
right way. That is my biggest concern. If we don't have a Cyber 
Command, how do we do that in an efficient way?
    General Haugh. So what I would--the way that I would--the 
way that I think the Department looks at it, the deputy 
secretary has really empowered the CDAO [Chief Digital and 
Artificial Intelligence Office] to set our data standards, and 
to do that across the Department. And so when I look at our 
teammates that we have in the DOD CIO [Chief Information 
Office], in CDAO, how do we enable their ability to go faster 
in some of those data standards?
    And I think we have a role to play in that, and I think we 
can help and assist, not only in how we set some of those 
standards but how we think about defense of each of these 
activities from a cyber perspective from the outset as we begin 
to introduce some of those new technologies.
    Dr. McCormick. Okay. I just--for the record, you can see a 
lot of Congressmen are concerned about this integration 
process. China has a huge advantage in this one area. They have 
one command structure, one government. They all agree on each 
other because it is kind of a monopolistic government, and it 
is going to be a lot easier for them to integrate AI throughout 
their weapons systems. The way they do digital technologies, it 
is a lot less distractions. They have a lot more focality. And 
I think if we get outpaced in the AI arena, we are in big, big 
trouble. So I hope we do a good job on that.
    Thank you. With that, I yield.
    Mr. Gallagher. Mr. Moulton.
    Mr. Moulton. Thank you, Mr. Chairman. And thank you very 
much for being here.
    A couple weeks ago the Foundation for Defense of 
Democracies think-tank issued a report calling for a separate 
cyber force. And I suspect you have read this. I know this is 
not a new topic. It is something that I have discussed myself 
over the years.
    And I was curious--I mean, basically, the main argument of 
the report is that because the individual services each run 
their own recruitment, training, and promotion systems for 
their cyber operations, those who get sent to U.S. Cyber 
Command have inconsistent knowledge and qualifying experience.
    So, General, how have these inconsistencies across the 
services impacted the effectiveness of U.S. Cyber Command in 
executing its mission?
    General Haugh. So, Congressman, first, if I could address 
the study, one of the areas that I do think that as we go 
through this year the 1533 study, and we evaluate all of the 
options available for force generation, we certainly are going 
to look really closely at, what are the implications of a cyber 
service? We will evaluate that.
    One of the other responsibilities that is in both our 
unified command plan and in the law is that I am responsible to 
evaluate the overall health of the DOD cyber workforce. So I am 
responsible to do that in plain English both to the Secretary 
of Defense and back to Congress.
    So I think from our perspective, those reports have allowed 
us to identify where are areas that the services could improve. 
And in doing so, it has also allowed us to build a partnership 
with the services on how do we work together to improve the 
readiness? Because I think what areas we had seen in the past 
was not necessarily from the recruiting perspective but more so 
from the assignment and retention.
    And Congress has given us a number of authorities to the 
Department that allow for retention incentives. What we were 
seeing was the services implement those differently, and so 
what we are encouraging, and what we did in our 1502 report 
last year was to ask for some specific authorities that 
encouraged our ability for assignment policies and personnel 
policies to ensure that those trained individuals stay in our 
force. And we have seen the services respond to those requests.
    So we want to be able to lock those in and then continue to 
work on other areas that will improve readiness within the 
force.
    Mr. Moulton. Do you feel that you are doing enough to use 
the authorities that Congress has given you?
    General Haugh. So I think now that we have budget control 
authority that we received last month, that now gives us a new 
series of options that will allow us to drive our priorities in 
training, in readiness. We are responsible for the advanced 
training of the Department's cyber force. How we use those 
dollars in many ways will determine our readiness and our 
proficiency.
    Mr. Moulton. I would like to ask just a couple of questions 
about deterrence. Deterrence is obviously important writ large, 
but of course when we look at a China attack on Taiwan, we want 
to deter that from happening in the first place. Deterrence is 
tough in the cyber world because we worry about giving up our 
capabilities when we use them.
    How is your thinking about this evolving? And how do you 
think--I would love to hear, General, a couple of comments.
    And then, Ms. Manning, how do you think about this in the 
integrated deterrence environment?
    General, perhaps we could start with you. Just how--with 
cyber force, how do you think about deterrence?
    General Haugh. So from a Cyber Command perspective, what we 
really think about in integrated deterrence are, who can we 
bring that is a partner that will allow us to be able to have 
the outcome we are trying to achieve? And for us, those 
partnerships look different than in some of the other domains.
    When we think about how--the role that industry plays in 
terms of both creating the domain and also being the ones with 
our own sensors that are global in nature, how do we partner 
with industry? How do we partner with our foreign allies and 
partners that either bring capability or have the same common 
thread? How do we partner with our fellow combatant commanders 
as they think about cyber security and defense? And how do we 
integrate capabilities together to be able to have options?
    So I think for us we have a unique set of partners, and we 
have got to be able to use our authorities in how we defend 
forward and do it every single day.
    Mr. Moulton. Ms. Manning, how are you thinking about 
working with your counterparts in other agencies to fulfill 
this goal of integrated deterrence?
    Ms. Manning. Thank you for your question, Congressman. We 
really do see cyber deterrence, as you mentioned, as part of 
overall integrated deterrence, in thinking about integrating 
across the Department, across domains, across the interagency, 
and also with allies and partners in those private-public 
partnerships that General Haugh mentioned.
    And it is important that we work together with our 
interagency partners, with our partners in industry, and with 
our allies and partners to really look at ways that we can deny 
adversaries the benefit of cyber attack by, one, being able to 
provide indications and warnings of threats to benefit our 
interagency partners, and then also by imposing consequences on 
our adversaries by disrupting their operations.
    Mr. Moulton. Thank you, Mr. Chairman.
    Mr. Gallagher. Thank you. I should note the Section 1533 
study that I referenced earlier was, I believe, Mr. Moulton's 
amendment. So he deserves credit for provoking and stimulating 
the debate that led to the report he referenced, and so I thank 
him for that.
    Mr. Fallon is recognized.
    Mr. Fallon. Thank you, Mr. Chairman, and thank you for your 
service to the country. I am sorry to see you go. But as--to 
quote the immortal words of Dr. Seuss, don't cry because it is 
over; smile because it happened.
    Last November, the North Texas Municipal Water District got 
hacked, and it was a domestic--it was a domestic attack, but, 
nonetheless--and they didn't shut it down, but they showed that 
they could have. And it reminded me of JBS and Colonial 
Pipeline.
    And, General, I wanted to ask you, what have we learned? 
Because that is the greatest fear we all have is that these 
critical areas--water, electricity, energy, fuel. What have we 
learned from those attacks that we can employ within the 
Defense Department?
    General Haugh. So I will give you a couple different 
things, Congressman. One is this is an area that we have 
clearly identified that the PRC is targeting. So this wasn't in 
this case, but we know that it is an area they are targeting. 
So from a national readiness perspective, we have to consider 
that.
    The other thing we think about is, what does it look like 
for defense critical infrastructure? Those things that are the 
nexus between our private infrastructure and those things the 
Department would rely upon if we were mobilizing. So that is a 
partnership with NORTHCOM [U.S. Northern Command], and it is a 
partnership with Homeland Security.
    I think those are areas that within the Department we have 
now focused, how do we think about that nexus, and what will it 
mean for the Department from a cyber security standpoint? So I 
think we have now been applying some of those lessons. We are 
going to have to continue to scale as we think about it within 
the Department.
    Mr. Fallon. And then, you know, with--you mentioned that 
CCP [Chinese Communist Party] and, like, Volt Typhoon comes to 
mind, there is no doubt that they are actively probing, of 
course. Can you talk about the work that you are doing with 
industry partners? Because, you know, chain, meet weakest link. 
If we have got some of our partners buttoned up and secure as a 
uniformed service, or even along the DOD, but a private company 
that is working with us isn't, it doesn't get us anywhere.
    So can you talk to us about what we are doing to enhance 
particularly the cyber security of our partners?
    General Haugh. Yes, Congressman. Both Congress and the 
Department have given Cyber Command and NSA authorities to work 
with our Defense Industrial Base. And that information-sharing 
component has now allowed us to establish over 1,000 
partnerships, and that allows us to exchange information, it 
allows us to do it in real time at an unclassified level, so 
that we can make industry aware of those threats.
    As we think about those partnerships, now DOD CIO has also 
funded additional activities that allow us to provide services 
to the Defense Industrial Base--protective DNS [Domain Name 
System]--so that they have a service that would make it more 
difficult for a redirection attack or a spear phishing attack 
informed by NSA's knowledge.
    The other things we have been doing are scanning of various 
elements of the Defense Industrial Base. We provide them a 
scan. We tell them what vulnerabilities we see and allow them 
to correct those vulnerabilities themselves. We are going to 
continue to look at what other services we can provide, but we 
are also looking at how can we extend those partnerships to a 
broader number that would ensure that we are covering the 
highest priority things that support the Department.
    Mr. Fallon. Thank you. And then, you know, when people come 
into our offices, they are all dying for labor. It doesn't 
matter what industry it is. I ask them, ``Do you have--you 
know, do you have job openings?'' and they are all crying for 
labor, so--and particularly skilled labor even more so.
    So I wanted to ask maybe Ms. Manning as well, what can we 
do, if anything, do we need to do? I remember being a junior 
officer and the doctors got paid more because, you know, that 
is just the market, right? You want to--you want to have those 
medical doctors stay on after maybe they owe some time after 
getting--going through medical school.
    But in particularly this field, it is just a high demand, 
and it--they make quite a bit of money. Do we--is there 
incentive pay for folks in this service? And does it need to--
do we need to ratchet it up? I just want to kick that to both 
of you.
    Ms. Manning. You know, I think at this point it is 
important that we consider all different ideas of how we can 
recruit and retain top talent. I think incentives are one tool 
that we have in our toolkit. I think also, though, there is a 
sense of mission that comes with doing the work in the 
Department.
    And so thinking about how we can make people feel really 
connected to the mission itself is another thing that we can 
think about. But I think really understanding what is it that 
is motivating people to come to these jobs, what is allowing 
them to sustain careers in government long term, and I think 
pay incentives are one of the tools we have at our disposal.
    Mr. Fallon. I just don't want the canyon to be this big. 
You know, if it is 300-grand in the private market, and it is 
100-grand here, that is just too big of a canyon, even if you 
are really rewarded, if we can close it. That is kind of my 
point.
    Thank you. Mr. Chairman, I yield back.
    Mr. Gallagher. Mr. Luttrell.
    Mr. Luttrell. Thank you, Mr. Chairman.
    General, in December 2022, SECDEF [Secretary of Defense] 
officially elevated CYBERCOM's offensive arm, the Cyber 
National Mission Force, to a sub-unified command. The logic was 
that it would provide greater enabling resources for this 
critical mission set. With how much adversary activity we have 
witnessed against DOD networks, it would appear that your 
defensive arm, Joint Forces Headquarters, could similarly 
benefit.
    Could you share your opinion?
    General Haugh. Thank you, Congressman. So when we stood 
up--when we elevated the Cyber National Mission Force, it was 
at a point, so we now--that is about a third of our force, and 
with a very distinct headquarters and assigned forces. That 
has--now I think was absolutely the right thing for us to do, 
that we are allowing it to create an identity, we are allowing 
it to grow its own staff to expand its planning, and then--and 
other capability development. I think we are seeing benefit 
from that.
    This is an area that we are going to look at in the 1533 
study, which is, as we start to think about--or, actually, the 
1537 study that you have asked us to do looking at our 
headquarters. What is the right way to position the Joint Force 
Headquarters DODIN [Department of Defense information networks] 
in terms of the right resources and authorities to make sure 
that it has the capacity to really set the globe? That is the 
mission we have given them.
    When we have a crisis, we want them to set the globe. So I 
think it is an area that we are certainly going to evaluate, 
and it does look different as a headquarters, also in terms of 
assigned forces, but it is something that we will definitely be 
looking at.
    Mr. Luttrell. Thank you.
    Ms. Manning, I apologize for walking on Mr. Fallon's 
questions. To expand or to create an expansiveness of talent, 
we wanted to reach out to academics--academia and institutes of 
higher performance, correct? Are we doing that, from your--in 
your opinion?
    I have universities in my district, and then of course, as 
I travel the state and the country, I have these discussions 
when it comes to cyber risk, cyber threat, cyberspace, 
artificial intelligence, machine learning, and how it seems 
like we are missing the rising wave, because our brilliant 
minds are traveling elsewhere. Are we creating effective 
narrative from your position in order to share that with the 
youth and say, ``Hey'--and I say ``youth,'' but our next 
generation of computational mathematicians.
    Ms. Manning. I think there are two aspects to this. I think 
one is making folks see a career in government as something 
that they want to pursue, and they see building the skills in 
cyber and in other fields as something where they can have a 
unique role in terms of defending our national security 
interests by having jobs you can really only do when you are in 
government, so----
    Mr. Luttrell. So how do we make working for the government 
sound cool?
    Ms. Manning. I think that is a really important point, and 
I think also beyond just making it sound cool, how do you have 
the----
    Mr. Luttrell. For lack of a better term, I am sorry, I 
should have stated that better.
    Ms. Manning. No. I think, you know, it needs to be 
relatable, and we also don't need the mechanisms to bring 
people into government. So looking at different tools like the 
cyber accepted service, looking at the presidential management 
tool, fellowship, looking at different scholarships and 
opportunities, I think all of this should be on the table, so 
that we can give folks the opportunity not only to want to 
serve in government but to be able to have the mechanisms to 
come in and be able to be a part of our team.
    Mr. Luttrell. Are we looking at having them serve in the 
various branches of armed services or just government in 
general? Because, as we know, we are having trouble recruiting 
the bodies for those platforms. Is it both, in between, or is 
it just something we are trying to cast that wide net and fill 
all of the--all of the silos?
    Ms. Manning. I would defer to the team who is responsible 
for personnel and readiness in terms of the overall policy.
    Mr. Luttrell. Oh, that is a great shift.
    Ms. Manning. But I think there are opportunities, both 
within the command, within the services, or for individuals to 
come in and to serve.
    Mr. Luttrell. General, have you got something on that one?
    General Haugh. So what I would give you is, what do we see 
that are things that are pretty exciting that are really 
looking at high schools and middle schools? I just attended the 
finals of CyberPatriot, 5,000 schools across the country where 
they are doing cyber competitions in middle school and in high 
school and in ROTC [Reserve Officers' Training Corps] programs.
    Those are the types of things that we want to be able to do 
as early--we would like to see being done as early as possible, 
so that we are really trying to capture people and what it 
looks like to be--that can be both cool and really impactful 
things for our Nation. I think----
    Mr. Luttrell. They seem like they have a willingness to put 
a uniform on?
    General Haugh. I think what we have seen is they have done 
a really nice job of bringing people towards the technology, 
and then it is our job to be able to have opportunities with 
the ROTC programs that are in high school and also to be able 
to reach out and be able to explain, what would you do if you 
came and worked with us, either as a civilian or in the 
military? That is our story that we have got to tell. Yes, sir.
    Mr. Luttrell. Thank you, Mr. Chairman.
    Mr. Gallagher. Thank you. Does any other member have a 
follow-up question?
    Okay. The FDD [Foundation for Defense of Democracies]-- we 
are going to have a classified session after this. But I think 
the FDD report that you have heard referenced numerous times 
here--again, I think--I mean, I am biased because I worked with 
a lot of these people in the Cyberspace Solarium Commission. I 
will admit that. But I think what is most compelling in it is 
the testimony from active duty, ranging from company grade to 
general grade officers.
    And I would like to read one statement from a Marine Corps 
captain, and all wisdom emanates from Marine Corps captains, as 
Mr. Moulton and I know quite well.
    ``Leading in the cyberspace domain demands technical 
competency that cannot be taught in a 12-month schoolhouse 
alone. One of my worst professional experiences involved 
working underneath a woefully unprepared commander with a 
degree in culinary arts. Under no circumstance would a cyber 
officer be asked to lead a squadron of aircraft, and that the 
opposite is often true.''
    That is just one of many quotes in the report that I think 
are worth reading. And, again, I am not biasing the outcome of 
the study you guys are going to do or an independent study, but 
I just think it is fair to say at this point that the status 
quo is not getting the job done. So we are asking you to take a 
hard look at this problem and work in partnership with us to 
come up with a better model.
    As was referenced by some of my colleagues, we have given 
so many authorities to DOD in the 8 years I have been on this 
committee, and it has all been well intentioned. It just seems 
like it is not adding up or producing the outcome we want.
    And so I know you are both relatively new to your 
respective jobs, and they are critically important jobs, and 
our commitment is to work with you to get this right, because 
the safety of our country and our citizens are quite literally 
hanging in the balance. And so we appreciate your time today. 
We look forward to the classified session.
    And, finally, since he was not here when I said nice things 
about him, I just want to reiterate how much of a pleasure it 
has been to work with Ranking Member Ro Khanna, not just on 
this committee but on many issues. One of my fondest memories 
is the op-ed we did on congressional reform together when we 
were impetuous freshman members of Congress.
    Mr. Khanna. Still no reform.
    [Laughter.]
    Mr. Gallagher. Still no reform. Yeah. My biggest failure. 
Term limits didn't happen. We went to the White House together 
to talk about that.
    But, Ro, you have always been incredibly, obviously, smart 
and independent-minded, but you have a bias for action that I 
admire, that I think is rare among people in public service, 
and I also appreciate your sense of humor and that you take the 
mission, but not yourself, too seriously.
    So thank you for your productive partnership. Appreciate 
that.
    With that, the open hearing is adjourned, and we will move 
to a classified session.
    [Whereupon, at 4:30 p.m., the subcommittee was adjourned.]



      
=======================================================================




                            A P P E N D I X

                             April 10, 2024

=======================================================================

      



      
=======================================================================


              PREPARED STATEMENTS SUBMITTED FOR THE RECORD

                             April 10, 2024

=======================================================================

      


    
    

      
=======================================================================


                   DOCUMENTS SUBMITTED FOR THE RECORD

                             April 10, 2024

=======================================================================

      

      
    

    
    
    



      
=======================================================================


              QUESTIONS SUBMITTED BY MEMBERS POST HEARING

                             April 10, 2024

=======================================================================

      

                  QUESTIONS SUBMITTED BY MRS. MCCLAIN

    Mrs. McClain. One of the trends we are seeing in terms of 
cyber-attacks is that adversaries have figured out how to phish 
many of the legacy tools that we have used in authentication. 
Not just passwords, but also some of the tools that we have 
used in multi-factor authentication (MFA), such as one-time 
passwords and push notifications. Civilian agencies seem to be 
making good progress on this front, thanks in large part to a 
2022 OMB memo (M-22-09) that required agencies to use only 
``phishing-resistant authentication'' that can block phishing 
attacks; CISA and NIST have also been highlighting the 
importance of phishing-resistant authentication, such as 
products that use the FIDO standards, to civilian agencies in 
their guidance.
    As OMB noted, users can be fooled into providing a one-time 
code or responding to a security prompt that grants the 
attacker account access, and these attacks can be fully 
automated and operate cheaply at significant scale. But there 
is no similar policy in DOD to ensure that, in places where the 
Common Access Card (CAC) and its PKI authentication can't be 
used, the authentication tools that are being used can block 
phishing attacks.
    Can you explain why DOD seems to be behind civilian 
agencies on this critical cybersecurity control (ensuring that 
phishable authentication can no longer be used)?
    What are your plans to close this security hole across the 
Defense Department? Will the DOD create a strategy or policy to 
ensure that whenever the CAC can't be used, any alternative 
authenticator can block phishing attacks?
    Ms. Manning. The cyber threat landscape is evolving at a 
pace that requires a coordinated, agile, and defensive 
response. I applaud the efforts of CISA and NIST to prioritize 
phishing-resistant multi-factor authentication (MFA) within 
civilian agencies. Phishing-resistant MFA and Zero Trust 
security architectures are critical requirements for all 
federal agencies, per Executive Order 14028 on improving the 
Nation's cybersecurity. The DoD Chief Information Officer (CIO) 
has prioritized implementing Zero Trust through continuous 
multi-factor authentication, micro-segmentation, advanced 
encryption, endpoint security, analytics, and robust auditing 
among other capabilities to fortify data, applications, assets, 
and services to deliver cyber resiliency. It is DoD policy that 
organizations use the Common Access Card (CAC) as the 
authenticator of choice wherever possible, including cloud 
environments. In scenarios where a CAC cannot be used or the 
user does not have a CAC, DoD has a list of approved phishing-
resistant authenticators for which the user's identity is tied 
to a hardware device. The DoD CIO is currently working with the 
components to develop a DoD MFA strategy that will guide the 
use and approval of anti-phishing MFAs when use of the CAC is 
not possible.
    Mrs. McClain. Last May, the DOD CIO put out a policy (DOD 
Instruction 8520.03, ``Identity Authentication for Information 
Systems'' that created a formal approval process for multi-
factor authentication (MFA) technologies to be used as an 
alternative to the Common Access Card (CAC) and its PKI-based 
authentication, with a focus on ensuring that strong MFA is 
being used in applications which cannot easily integrate with 
the CAC or where the use of PKI is not practical. For example, 
the CAC is not optimized for use in some mobile devices. In 
addition, a CAC is not issued to every individual that requires 
access to DOD resources.
    Can you share how many MFA solutions have been approved 
under this new policy? And have any of these approvals been for 
phishing-resistant authentication solutions that can block the 
increased volume of phishing attacks that have been targeting 
legacy MFA technologies such as one-time passwords and push 
notifications? What can be done to accelerate this process?
    Ms. Manning. Four alternatives to the DoD Common Access 
Card (CAC) have been approved under DoD Instruction 8520.03, 
``Identity Authentication for Information Systems,'' two of 
which are phishing-resistant. The other two multi-factor 
authentication (MFA) technologies were approved prior to the 
release of the updated DoD Instruction. Another five 
alternatives are being evaluated. Of the ones currently being 
evaluated, all are intended to be phishing-resistant. DoD is 
developing an MFA strategy that will inform an update to DoDI 
8520.03 and guide the selection and use of alternative MFAs.
    Mrs. McClain. One of the trends we are seeing in terms of 
cyber-attacks is that adversaries have figured out how to phish 
many of the legacy tools that we have used in authentication. 
Not just passwords, but also some of the tools that we have 
used in multi-factor authentication (MFA), such as one-time 
passwords and push notifications. Civilian agencies seem to be 
making good progress on this front, thanks in large part to a 
2022 OMB memo (M-22-09) that required agencies to use only 
``phishing-resistant authentication'' that can block phishing 
attacks; CISA and NIST have also been highlighting the 
importance of phishing-resistant authentication, such as 
products that use the FIDO standards, to civilian agencies in 
their guidance.
    As OMB noted, users can be fooled into providing a one-time 
code or responding to a security prompt that grants the 
attacker account access, and these attacks can be fully 
automated and operate cheaply at significant scale. But there 
is no similar policy in DOD to ensure that, in places where the 
Common Access Card (CAC) and its PKI authentication can't be 
used, the authentication tools that are being used can block 
phishing attacks.
    Can you explain why DOD seems to be behind civilian 
agencies on this critical cybersecurity control (ensuring that 
phishable authentication can no longer be used)?
    What are your plans to close this security hole across the 
Defense Department? Will the DOD create a strategy or policy to 
ensure that whenever the CAC can't be used, any alternative 
authenticator can block phishing attacks?
    General Haugh. The DOD CIO, as the author of the DoD 
Instruction 8520.03, ``Identity Authentication for Information 
Systems,'' published on May 19, 2023 and DoD Instruction 
8520.02, ``Public Key Infrastructure (PKI) and Public Key (PK) 
Enabling,'' published on May 24, 2011, is best postured to 
provide a formal response regarding the perception of an 
authentication security hole and any efforts to address them 
with strategy or policy. As the policy owner, DOD CIO 
``Approves [multi-factor technology] MFA technologies for use 
by DOD information systems . . . '' while also addressing 
applicable security controls. JFHQ-DODIN, on behalf of 
USCYBERCOM, manages cyberspace risk to DoD missions by 
executing command and control across all DoD components and 
reinforcing or augmenting DoD policy whenever practical through 
the release of operational orders. In this role, JFHQ-DODIN is 
responsible for synchronizing and coordinating actions in and 
through cyberspace so that the Department remains postured 
against sustained threats posing risk to the nation's strategic 
interests. Operational orders may be proactive or preventative 
in nature, may be focused on availability and resiliency of the 
DODIN, or may be responsive to suspicious or malicious events. 
All orders, regardless of focus, are tracked to completion and 
subsequently monitored for compliance.
    Mrs. McClain. Last May, the DOD CIO put out a policy (DOD 
Instruction 8520.03, ``Identity Authentication for Information 
Systems'' that created a formal approval process for multi-
factor authentication (MFA) technologies to be used as an 
alternative to the Common Access Card (CAC) and its PKI-based 
authentication, with a focus on ensuring that strong MFA is 
being used in applications which cannot easily integrate with 
the CAC or where the use of PKI is not practical. For example, 
the CAC is not optimized for use in some mobile devices. In 
addition, a CAC is not issued to every individual that requires 
access to DOD resources.
    Can you share how many MFA solutions have been approved 
under this new policy? And have any of these approvals been for 
phishing-resistant authentication solutions that can block the 
increased volume of phishing attacks that have been targeting 
legacy MFA technologies such as one-time passwords and push 
notifications? What can be done to accelerate this process?
    General Haugh. The DOD CIO, as the author of the DoD 
Instruction 8520.03, ``Identity Authentication for Information 
Systems,'' published on May 19, 2023 and DoD Instruction 
8520.02, ``Public Key Infrastructure (PKI) and Public Key (PK) 
Enabling,'' published on May 24, 2011, is best postured to 
provide a formal response. As the policy owner, DOD CIO 
``Approves [multi-factor technology] MFA technologies for use 
by DOD information systems . . . '' and is therefore the 
appropriate source of MFA solution approvals and other process-
related questions.
                                ------                                


                   QUESTIONS SUBMITTED BY MR. LALOTA

    Mr. LaLota. How is DoD tracking cyber workforce training, 
credentials, and job placements?
    Ms. Manning. The Department has a robust overarching 
governance architecture for managing the training, 
credentialing, and assignment of its 230,000-person cyber 
workforce. This architecture is defined in DoDD 8140.01 
``Cyberspace Workforce Management,'' which established the 
Cyberspace Workforce Management Board (CWMB) as the governing 
body tri-chaired by the Under Secretary of Defense for 
Personnel and Readiness (USD(P&R)), the DoD Chief Information 
Officer (CIO), and the Principal Cyber Advisor (PCA). The DoDD 
8140.01 specifies the DoD Cyber Workforce Framework (DCWF), 
comprising 72 cyber-related work roles, as the basis for cyber 
workforce identification (e.g., assigning work roles to 
military and civilian positions) and qualification requirements 
(e.g., education, training, certifications, job-specific 
credentials) tailored to each work role's basic, intermediate, 
and advanced proficiency levels.
    Work role categorization allows the CWMB to make more 
targeted decisions with respect to hiring, retention, and 
incentives based on the criticality of various roles. The 
Services and DoD agencies maintain their own qualification 
tracking systems with unique data constructs. For example, 
USCYBERCOM tracks training and credentials of the Cyber Mission 
Force in its Joint Cyber Command and Control-Readiness system 
(JCC2R). The DoD CIO launched a data maturity initiative in FY 
2024 to generate a holistic assessment of cyber workforce 
readiness garnering qualification metrics across DoD. During 
the first phase of this effort, the DoD CIO conducted an 
environmental scan of DoD workforce tracking systems which 
identified authoritative sources to harness qualification data. 
The second phase underway involves creating data structure and 
standardization to enable integration of qualification data 
from DoD's disparate systems. The DoD CIO currently employs 
Advana, DoD's data analytics platform, for tracking cyber 
workforce work role identification through dashboards and other 
data visualization and plans to leverage automated tracking and 
reporting of cyber qualifications utilizing Advana in FY 2026.
    Mr. LaLota. What steps are CYBERCOM and the DOD taking to 
cultivate and support the development of cyber talent within 
the defense industry?
    General Haugh. USCYBERCOM continues to pursue additional 
authorities to maximize our ability to recruit and retain high 
demand, low-density cyber talent across the global cyber 
enterprise to better enable us to fight and WIN the war for 
talent. J1 is collaborating with DoD CIO, the Principal Cyber 
Advisor, and OSD Policy to execute NDAA 1531 to incentivize our 
service members with up to $2500 bonus for their novel action, 
invention, or achievement that enables operational outcomes in 
cyberspace against threats to National Security. Additionally, 
we are advocating for Target Local Market Supplement (TLMS) pay 
for our critical work roles with high turnover rates to 
increase pay up to 28%.
    Lastly, we are partnering with Army to execute the 10 
U.S.C. 4092 authorities to hire imminent experts in data 
science, computer science, and computer network exploitation 
and pay them above the GG pay scale ($181K--246K annually, with 
the ability to incentivize up to 25% of base pay). This could 
result in an annual pay in upwards of $307K. USCYBERCOM 
continues to maximize the use of our Cyber Excepted Service 
authorities while pursuing the additional authorities outlined 
above, which refine the Command's ability to engage talent 
through partnerships and innovation and allow further 
competition with industry salaries. Moving forward, we 
recognize the Campaign for Talent goes beyond financial 
incentives and requires a holistic approach to recruit AND 
retain world-class talent we need to support the cyber 
enterprise. USCYBERCOM stood up a Civilian Workforce Council, 
charged with identifying development and mentorship 
opportunities for the military and civilian workforce to set us 
apart from the competition and intentionally grow talent to 
fill key positions within the broader cyber enterprise. We are 
expanding our internship opportunities and collaborating with 
our Academic Engagement Network (AEN) of 127 schools, to 
inspire the next generation of cyber talent.
    Through the AEN, the Command has direct access to the 
students and faculty at these schools, establishing a pathway 
for students to seek employment at USCYBERCOM or other 
government agencies in the cyber field. Finally, our Command 
Code is, ``We WIN With People.'' Our new cyber recruiting cell 
enables global recruiting in support of the cyber mission and 
affords us the opportunity to rapidly identify and recruit the 
talent we need to enable our mission in defense of the Nation. 
Speed and agility is the key to our success.
    Mr. LaLota. Are there particular programs or partnerships 
in place to ensure that even small and medium-sized defense 
suppliers, like the strong core of defense industrial suppliers 
on Long Island, have access to skilled cybersecurity 
professionals to meet the strategy's compliance requirements 
and enhance their cyber posture against the backdrop of 
evolving cyber threats?
    General Haugh. NSA's Directorate of Cybersecurity operates 
the Cybersecurity Collaboration Center (CCC). The CCC operates 
a Defense Industrial Base (DIB) Defense program that supports 
enhanced security of the DIB by providing intel-driven 
cybersecurity solutions to DoD contractors (to include small 
and medium sized defense suppliers). DIB Defense (NSA C53) 
provides cybersecurity services that address the top ways 
nation-state actors target the DIB, and are infused with NSA's 
unique insights and analytics. These services include 
Protective Domain Name System (PDNS), Attack Surface Management 
(ASM), and Threat Intelligence Collaboration (TIC).
    In addition to these core services, DIB Defense also runs 
multiple pilot services with DIB partners to include Cloud 
Security, Threat Hunting, Phishing Protection, and Autonomous 
Penetration Testing. UNDERADVISEMENT (UNAD) is a Cyber National 
Mission Force (CNMF)-designated information-sharing activity 
designed for partnerships with private sector entities. This 
information sharing is overt, voluntary, and reciprocal, with 
acknowledgement of the identities of the participants and the 
organizations to which they belong. This allows for appropriate 
information sharing regarding cybersecurity and cyber threats 
related to assigned missions between CNMF and the private 
sector. UNAD complements other USG information sharing 
programs, complies with existing U.S. law and policy, and 
allows for engagement with the private sector on terms with 
which the private sector is accustomed.
    CNMF information sharing under UNAD facilitates CNMF 
operations and timely partner defensive actions. Currently, 
UNAD is an unfunded activity but will be designated as the 
USCYBERCOM Executive Agent responsible for managing cyber 
threat information sharing between USCYBERCOM Components and 
the private sector to meet the intent of FY19 NDAA Sec. 1642(b) 
and FY22 NDAA Sec. 1508. Outside of USCYBERCOM, the 
Cybersecurity and Infrastructure Security Agency (CISA) ensures 
members of the Defense Industrial Base (DIB) have access to 
skilled cybersecurity professionals to enhance their cyber 
posture against the backdrop of evolving cyber threats. 
Specifically targeted to supporting the DIB, CISA manages the 
DoD's Defense Industrial Base Cyber Program specifically 
seeking to enhance and supplement DIB participant's 
capabilities to safeguard DoD information that resides on or is 
transmitted on unclassified information systems. This program 
is free of cost to DIB participants and open to all cleared 
defense contractors. For more information, potential DIB 
participants should reach out to CISA at OSD.DIBCISA@mail.mil 
or visit their website at https://DIBNet.dod.mil.
                                ------                                


                   QUESTIONS SUBMITTED BY MR. WITTMAN

    Mr. Wittman. The threat of Chinese cyber capabilities 
continues to be a persistent and penetrating issue for the 
Congress and U.S. Government in general. One of the 
vulnerabilities that Congress continues to address is TikTok. 
The Congress took action and banned TikTok on all government 
devices and devices that access government information. Given 
the young age of many service members, it is not presumptuous 
to assume that many of them have TikTok accounts and have 
downloaded the application on their personal devices. To 
protect the data of U.S. service members, personally 
identifiable information, and controlled and classified 
information, is the Department of Defense currently compliance 
with US Code S.1143--No TikTok on Government Devices Act? What 
is the Department doing to ensure that the TikTok ban is 
enforced, particularly on Government issues cell phones or any 
bring your own device solutions. Finally, how does the 
Department intend to enforce this Code with the contractors 
required and identified under CMMC guidance?
    Ms. Manning. TikTok remains a national security concern due 
to the sheer volume of user data it collects and potential for 
exposure and access of U.S. user data by PRC-based ByteDance. 
It is crucial for our Nation to tackle this issue, especially 
as similar applications will arise, requiring policies that 
strike a balance between information access and protection 
against adversarial surveillance and malign influence. On March 
3, 2023, the DoD Chief Information Officer (CIO) released the 
``Removal and Ban of the Installation of TikTok'' and provided 
implementation guidance on May 4, 2023. Both memoranda enforce 
the TikTok ban on all government devices. DoD policy required 
removal of the TikTok application from all government devices. 
Furthermore, the ``DoD Mobile Device Policy'' and ``Use of Non-
Government Owned Mobile Devices'' policy requires government 
and contractor issued devices to be enrolled in an Enterprise 
Mobility Manager (EMM) for management of DoD information and 
applications. Once enrolled, managed devices can only install 
mobile applications that have been approved by the EMM and are 
available through the managed application store. This 
requirement ensures the TikTok ban is enforced on all 
government devices.
    Moreover, the Cybersecurity Maturity Model Certification 
(CMMC) Program will require that DoD contractors manifest 
compliance with the cybersecurity safeguards in already 
required standards as a condition of receiving awards and 
continued business. The purpose of the CMMC Program is to 
validate that existing security requirements in NIST Special 
Publication (SP) 800-171, ``Protecting Controlled Unclassified 
Information in Nonfederal Systems and Organizations'' and 
select security requirements from NIST SP 800-172, ``Enhanced 
Security Requirements for Protecting Controlled Unclassified 
Information'' are properly implemented in accordance with 
contractual requirements. The CMMC Program does not directly 
prohibit the use of TikTok on contractor devices. However, 
several of the NIST control requirements assessed via the CMMC 
Program ensure that contractors implement system policies that 
prevent personnel or automated processes from installing 
software such as TikTok, create and retain system auditing logs 
and records needed to monitor unauthorized activities, and 
ensure that such auditing logs are traceable to individual 
users to hold them accountable.
    Mr. Wittman. The Cybersecurity and Infrastructure Security 
Agency (CISA) published in March the ``Review of the Summer 
2023 Microsoft Exchange Online Intrusion'' that assessed the 
security failures of Microsoft which led to successful 
cyberattacks from Chinese and Russian hackers (ex: Fancy Bear 
and Midnight Blizzard). Additional cyber-attacks against 
Microsoft have been reported since the major incidents of 2023, 
leading CISA to issue an Emergency Directive 24-02. With regard 
to the Department's use of Microsoft software, have you 
implemented any policies to mitigate exposure, through 
Microsoft capabilities, of the Department to TikTok or 
ByteDance applications? Furthermore, in the Midnight Blizzard 
attack, source code repositories and internal systems were 
compromised. Was the compromised code the sane code of 
platforms upon which the Department relies? Does the Department 
rely on a single vendor for the majority of its Unclassified 
and Classified communications? And does DOD practice vendor 
diversity and ``Defense in Depth'' for these types of systems 
and software? Finally, it is my understanding the Army, and 
potentially other services and agencies, employ the full suite 
of Microsoft 365 services. Since the entire suite is closely 
integrated, to what extent has DOD been able to meet the CISA 
Emergency Directive to take immediate, remediating action for 
tokens, passwords, API keys, or other authentication 
credentials known or suspected to be compromised?
    Ms. Manning. The Department of Defense (DoD) utilizes 
multiple cybersecurity tools including Microsoft tools to 
mitigate exposure from applications such as TikTok. DoD applies 
network content filtering to all DoD networks to block access 
to the TikTok website. In addition, the DoD Chief Information 
Officer (CIO) memorandum on the ``Use of Unclassified Mobile 
Applications in Department of Defense'' dated October 6, 2023, 
outlines mitigations for mobile devices by segmenting DoD 
information from unmanaged and non-DoD applications such as 
TikTok or ByteDance applications. While DoD employs Microsoft 
Windows and Office Suite for basic computing and 
communications, it also employs a wide variety of non-Microsoft 
technologies in support of its various missions. The DoD 
emphasizes vendor diversity per the requirements for 
competition set out in the Federal Acquisition Regulation 
(FAR). The Department is aware of the Midnight Blizzard 
compromise, which resulted in the exfiltration of email 
correspondence through a compromise of Microsoft corporate 
email accounts. These emails contain authentication details, 
which Midnight Blizzard is seeking to use to gain access to 
Microsoft systems. USCYBERCOM tasked all DoD components to 
investigate and mitigate the compromise. The tasking covers the 
Cybersecurity and Infrastructure Security Agency (CISA)'s 
Emergency Directive actions.
    Mr. Wittman. The threat of Chinese cyber capabilities 
continues to be a persistent and penetrating issue for the 
Congress and U.S. Government in general. One of the 
vulnerabilities that Congress continues to address is TikTok. 
The Congress took action and banned TikTok on all government 
devices and devices that access government information. Given 
the young age of many service members, it is not presumptuous 
to assume that many of them have TikTok accounts and have 
downloaded the application on their personal devices. To 
protect the data of U.S. service members, personally 
identifiable information, and controlled and classified 
information, is the Department of Defense currently compliance 
with US Code S.1143--No TikTok on Government Devices Act? What 
is the Department doing to ensure that the TikTok ban is 
enforced, particularly on Government issues cell phones or any 
bring your own device solutions. Finally, how does the 
Department intend to enforce this Code with the contractors 
required and identified under CMMC guidance?
    General Haugh. Regarding the ban of TikTok on government 
devices, JFHQ-DODIN directed removal of TikTok ``from all 
Government Furnished Equipment (GFE) and prohibit users from 
downloading or accessing the application in January 2023.'' As 
a result, the Department is compliant and no government desktop 
or mobile device may access the TikTok application, as directed 
by U.S. Code S. 1143. JFHQ-DODIN leverages Security Information 
& Event Management (SIEM) tools to correlate and continually 
monitor the effectiveness of the ban across DoD issued devices. 
For off-DODIN contractors applying CMMC guidance, DOD CIO is 
best postured to provide a formal response, as they maintain 
the Department's CMMC website and are involved in the ongoing 
rulemaking process that is part of the CMMC 2.0 phase-in 
period.
    Mr. Wittman. The Cybersecurity and Infrastructure Security 
Agency (CISA) published in March the ``Review of the Summer 
2023 Microsoft Exchange Online Intrusion'' that assessed the 
security failures of Microsoft which led to successful 
cyberattacks from Chinese and Russian hackers (ex: Fancy Bear 
and Midnight Blizzard). Additional cyber-attacks against 
Microsoft have been reported since the major incidents of 2023, 
leading CISA to issue an Emergency Directive 24-02. With regard 
to the Department's use of Microsoft software, have you 
implemented any policies to mitigate exposure, through 
Microsoft capabilities, of the Department to TikTok or 
ByteDance applications? Furthermore, in the Midnight Blizzard 
attack, source code repositories and internal systems were 
compromised. Was the compromised code the sane code of 
platforms upon which the Department relies? Does the Department 
rely on a single vendor for the majority of its Unclassified 
and Classified communications? And does DOD practice vendor 
diversity and ``Defense in Depth'' for these types of systems 
and software? Finally, it is my understanding the Army, and 
potentially other services and agencies, employ the full suite 
of Microsoft 365 services. Since the entire suite is closely 
integrated, to what extent has DOD been able to meet the CISA 
Emergency Directive to take immediate, remediating action for 
tokens, passwords, API keys, or other authentication 
credentials known or suspected to be compromised?
    General Haugh. While the Department of Defense (DoD) does 
not fall within the purview of the Cybersecurity and 
Infrastructure Security Agency's (CISA) authorities, we remain 
in close coordination with CISA as it issues guidance to all 
federal Agencies under its authority. In concert with the DoD 
CIO and the National Manager for National Security Systems (NM-
NSS), JFHQ-DODIN issues specific guidance and direction to the 
DoD for significant events such as the Midnight Blizzard 
compromise of Microsoft. Based on the information provided by 
Microsoft, there was no compromise of source code that would 
elevate risk to the department. In response to the events, 
JFHQ-DODIN released a Cyber Tasking Order directing hunt, 
clearing, and remediation actions based on potentially exposed 
DoD credentials immediately following the notification of the 
Microsoft Corporate network compromise. JFHQ-DODIN has released 
several orders over the last six months in coordination with 
DoD CIO to enhance data security measures, visibility, and 
detection across the M365 environment. As a result, the orders 
align the Department with the directed Zero Trust Framework. 
Additionally, the DODIN security concept is built around a 
Defense in Depth posture which uses various vendors overlaying 
several tiers of security tools/capabilities.