[House Hearing, 118 Congress]
[From the U.S. Government Publishing Office]
[H.A.S.C. No. 118-68]
HEARING
ON
NATIONAL DEFENSE AUTHORIZATION ACT
FOR FISCAL YEAR 2025
AND
OVERSIGHT OF PREVIOUSLY AUTHORIZED PROGRAMS
BEFORE THE
COMMITTEE ON ARMED SERVICES
HOUSE OF REPRESENTATIVES
ONE HUNDRED EIGHTEENTH CONGRESS
SECOND SESSION
__________
SUBCOMMITTEE ON CYBER, INFORMATION TECHNOLOGIES, AND INNOVATION
ON
CYBER IN AN ERA
OF PERSISTENT ENGAGEMENT:
THE FISCAL YEAR 2025 BUDGET REQUEST
FOR U.S. CYBER COMMAND AND CYBER OPERATIONS
__________
HEARING HELD
APRIL 10, 2024
______
U.S. GOVERNMENT PUBLISHING OFFICE
56-081 WASHINGTON : 2025
SUBCOMMITTEE ON CYBER, INFORMATION TECHNOLOGIES, AND INNOVATION
MIKE GALLAGHER, Wisconsin, Chairman
MATT GAETZ, Florida RO KHANNA, California
LISA C. McCLAIN, Michigan SETH MOULTON, Massachusetts
PAT FALLON, Texas WILLIAM R. KEATING, Massachusetts
DALE W. STRONG, Alabama ANDY KIM, New Jersey
MORGAN LUTTRELL, Texas ELISSA SLOTKIN, Michigan
JENNIFER A. KIGGANS, Virginia JARED F. GOLDEN, Maine
NICK LaLOTA, New York PATRICK RYAN, New York
RICHARD McCORMICK, Georgia CHRISTOPHER R. DELUZIO,
Pennsylvania
Joshua Stiefel, Professional Staff Member
Michael Hermann, Professional Staff Member
Brooke Alred, Research Assistant
C O N T E N T S
----------
Page
STATEMENTS PRESENTED BY MEMBERS OF CONGRESS
Gallagher, Hon. Mike, a Representative from Wisconsin, Chairman,
Subcommittee on Cyber, Information Technologies, and Innovation 1
WITNESSES
Haugh, Gen Timothy D., USAF, Commander, U.S. Cyber Command;
Director, National Security Agency/Chief, Central Security
Service........................................................ 4
Manning, Ashley, Performing the Duties of the Assistant Secretary
of Defense for Cyber Policy.................................... 3
APPENDIX
Prepared Statements:
Haugh, Gen Timothy D......................................... 45
Khanna, Mr. Ro............................................... 27
Manning, Ashley.............................................. 29
Documents Submitted for the Record:
Gallagher, Hon. Mike......................................... 63
Witness Responses to Questions Asked During the Hearing:
[There were no Questions submitted during the hearing.]
Questions Submitted by Members Post Hearing:
Mrs. McClain................................................. 87
Mr. LaLota................................................... 89
Mr. Wittman.................................................. 92
CYBER IN AN ERA OF PERSISTENT ENGAGEMENT: THE FISCAL YEAR 2025 BUDGET
REQUEST FOR U.S. CYBER COMMAND AND CYBER OPERATIONS
----------
House of Representatives,
Committee on Armed Services,
Subcommittee on Cyber, Information Technologies, and
Innovation,
Washington, DC, Wednesday, April 10, 2024.
The subcommittee met, pursuant to call, at 3:33 p.m., in
room 2212, Rayburn House Office Building, Hon. Mike Gallagher
(chairman of the subcommittee) presiding.
OPENING STATEMENT OF HON. MIKE GALLAGHER, A REPRESENTATIVE FROM
WISCONSIN, CHAIRMAN, SUBCOMMITTEE ON CYBER,
INFORMATIONCHNOLOGIES, AND INNOVATION
Mr. Gallagher. The subcommittee will come to order.
This will likely be my final hearing as chairman of the
subcommittee. And before we get underway, I want to thank--
well, he is not here. I was going to--I had this whole nice
thing prepared to thank Ro Khanna for his partnership. We will
have to save all the sappy stuff for when he actually gets
here. But he is amazing, and we have had a great partnership.
And being on this committee for 8 years has been a
highlight of my time in office, and I want to thank all the
members. And Matt and I have sat next to each other for 8 years
now and had a lot of late-night debates during NDAA [National
Defense Authorization Act] markup, and I have--and often
collaborations when it comes to AUMF [Authorization for Use of
Military Force] issues. And I have sincerely enjoyed that.
So today we are going to--we are going to hear from the
Department on its budget request and plan for cyberspace
operations for the coming fiscal year. From 2013 to 2023,
Congress tried to address force design and readiness through 24
different pieces of legislation, civilian and military
workforce issues via 45 separate provisions of law, and cyber
security at the Defense Industrial Base in 42 provisions of
law. That is a lot of activity.
Through this latest NDAA, we incorporated new requirements,
reports, and mandates into each of those same categories, and
yet here we are. There are still significant issues with our
force design, our civilian and military workforce issues remain
as challenging as they have been in the past 10 years, and
several cyber incidents targeting the Defense Industrial Base
have demonstrated that we are as vulnerable now as we were a
decade ago.
And just as I said when we were here a year ago for this
same cyber posture hearing, insanity is doing the same thing
over and over again and expecting different outcomes. I believe
that almost everyone here today is familiar with a report
published just 2 weeks ago by the Foundation for the Defense of
Democracies on the issue of a cyber force, a proposed new
branch of the armed forces dedicated to the cyber domain.
This new force would be responsible for organizing,
training, and equipping for the cyber domain, no different from
the Navy for combat at sea or the Air Force as the service
responsible for air warfare.
The report is very compelling. And, as I said, in an event
we did a couple of weeks ago, I came in as a skeptic, but I
think they have raised some very important issues that need to
be addressed, and it is a debate that is worth having because I
think the status quo right now is unacceptable.
But the arguments were not--the cogent arguments in the
report are not the only thing that stood out. Included in the
report were personal accounts provided anonymously by more than
75 active and recently separated service members representing
every military branch and rank from E-7 to O-7 as well as
senior civilians. Not a single individual that was approached
declined to respond, nor did any one of them argue in favor of
the current approach in which the operational force is sourced
from four separate military services.
I, therefore, ask unanimous general consent to enter this
report into the record. So ordered.
[The information referred to can be found in the Appendix
on page 63.]
Mr. Gallagher. I will admit, again, I had concerns at the
start of this debate, but over the last 18 months I have been
presented with an astounding array of data and arguments in
favor of a cyber force, as well as a number of convincing
arguments opposing such a force. In my mind, the most logical
way to address this question is a fully independent evaluation
of the notional cyber force to be led by an entity other than
the Department of Defense--other than the Department of Defense
is critical.
If anyone is opposed to a study of this question, I believe
there is only one way to interpret that opposition, which is
that if you are unwilling to ask the question, what you are
really saying is that you are scared of the answer you might
receive and the actions we will have to take to address the
problem. When it comes to national security, that way of
thinking--acceptance of risk because of fear--I think is
unacceptable.
And while I may not be chair of this subcommittee during
this year's NDAA markup, I hope my colleagues will make the
right decision and work collectively to ensure the Department
of Defense is directed to conduct such a study when the time
comes.
With that as context, I am very eager to hear from both of
our witnesses--thank you for being here--each appearing for
their inaugural cyber posture hearing. There is a whole set of
elaborate initiation events that we have to do afterwards. It
is highly top secret. But we are joined by Ms. Ashley Manning,
a career senior executive performing the duties of Assistant
Secretary of Defense for Cyber Policy, and General Tim Haugh,
the Commander of the United States Cyber Command. Thank you
both for appearing today.
At this point, I would turn it over to the ranking member.
He is not yet here. Here is on his way from an oversight
hearing, but I ask that his opening remarks be entered into the
record. I ask unanimous consent for that to happen, and then
something magically happens and it goes into the record.
[The prepared statement of Mr. Khanna to can be found in
the Appendix on page 27.]
Mr. Gallagher. And, with that, we go to Ms. Manning first,
correct, for 5 minutes.
STATEMENT OF ASHLEY MANNING, PERFORMING THE DUTIES OF THE
ASSISTANT SECRETARY OF DEFENSE FOR CYBER POLICY
Ms. Manning. Chairman Gallagher, Ranking Member Khanna, and
distinguished members of the committee, thank you for inviting
me to testify on the Department of Defense's cyber posture and
the advancements we continue to make operationalizing the
Department's priorities in cyberspace. It is an honor to appear
alongside General Haugh.
In my role Performing the Duties of Assistant Secretary of
Defense for Cyber Policy, I am committed to providing overall
supervision of the Department's policy for cyber, advancing the
Department's strategic approach to cyberspace, and ensuring our
readiness to counter emerging cyber threats.
Mr. Chairman, I look forward to working with this committee
through my newly established office to further these
objectives.
I come to this role as a career civilian with almost 20
years of service in the Department of Defense. I have had the
privilege of working across a wide range of regional and
functional issues, serving most recently as the Acting Deputy
Assistant Secretary of Defense for the Middle East and the
Principal Director for Plans and for Posture. And in my
previous positions, I have witnessed the cross-cutting role
cyber plays in the defense of our Nation and our allies and
partners.
The President has nominated Dr. Michael Sulmeyer as the ASD
[Assistant Secretary of Defense] for Cyber Policy. Should he be
confirmed, I look forward to serving as the Principal Deputy
Assistant Secretary of Defense for Cyber Policy.
Our National Defense Strategy makes clear that the People's
Republic of China remains an enduring cyber threat and the
Department's pacing challenge in cyberspace, as the PRC
[People's Republic of China] continues to target U.S. networks
in prolonged campaigns of espionage and to pre-position its
cyber forces for future operations.
Russia remains a persistent threat to the United States and
our allies and partners, as it continues to leverage cyberspace
to target critical infrastructure networks and enable its
malign influence operations. The ongoing, unprovoked, further
invasion of Ukraine serves as a stark reminder of Russia's
willingness to employ cyber capabilities to disrupt defensive
military operations and sow discord.
Following Hamas's attack against Israel on October 7 of
last year, Iran has exploited cyberspace to create additional
disruptions and challenges in Israel. While many of these
malicious cyberspace activities have been relatively limited in
their impact, the ability of both state and non-state actors to
act against Israel in the immediate aftermath of the attack by
Hamas is a reminder of what to expect in future conflicts.
Additionally, the United States continues to face the
still-growing threat posed by for-profit cyber criminals that
target a wide array of vulnerable sectors, conducting
ransomware attacks that impact the daily lives of Americans
across the country.
In response to these evolving challenges, the Department
issued its fourth DOD [Department of Defense] Cyber Strategy
last May. Looking ahead, we are committed to implementing our
strategy and monitoring progress through the forthcoming cyber
posture review in fiscal year 2026.
We understand the Department cannot advance its defense
priorities without a ready, capable, and informed joint force.
To achieve this end, we will invest in our people, in our
capabilities, and in our information needs to support and
enable the full range of cyber activities.
In partnership with USCYBERCOM [U.S. Cyber Command], we are
refining options for the secretary on how to improve the way in
which forces are presented to the command to raise the
readiness level of these forces and to streamline support
mechanisms to other combatant commands. These options will
enable USCYBERCOM to fully exercise authorities in partnership
with my office, including through enhanced budget control.
As part of the fiscal year 2026 budget cycle, DOD released
its first-ever Department-wide Cyber Operations Programming
Guidance. This guidance will shape future cyberspace operations
investments and will serve as a rubric for my office's
certification of the budget's adequacy for fiscal year 2026.
With the authorities granted to us by Congress, the
Department will continue to build on the pathway laid out in
the fiscal year--or, I am sorry, in the 2023 DOD Cyber Strategy
to provide a stronger cyber posture and protect the shared
digital environment for those who intend to subvert our values
and our interests by pursuing integrated deterrence, which
includes our cyber capabilities.
The Department will be ready to fight and win the Nation's
wars with an ability to rapidly respond across the spectrum of
conflict. Thank you for your continued support in this fight,
and I look forward to answering your questions.
[The prepared statement of Ms. Manning can be found in the
Appendix on page 29.]
Mr. Gallagher. Thank you.
General, you are recognized for 5 minutes.
STATEMENT OF GENERAL TIMOTHY D. HAUGH, USAF, COMMANDER, U.S.
CYBER COMMAND, DIRECTOR, NATIONAL SECURITY AGENCY/CHIEF,
CENTRAL SECURITY SERVICE
General Haugh. Chairman Gallagher, Ranking Member Khanna,
and distinguished members of the committee, thank you for the
opportunity to testify before you today. I am honored to
testify beside Ms. Manning. Joining me today is Chief Master
Sergeant Kenneth Bruce, the U.S. Cyber Command and National
Security Agency Senior Enlisted Leader. We are honored to
represent the men and women of U.S. Cyber Command.
In an era defined by rapid technological advancement and
increasing interconnectedness, cyberspace has emerged as a
vital domain for protecting our national security. The People's
Republic of China is our greatest strategic competitor and
poses unique challenges due to its advanced cyber capabilities,
state-sponsored cyber operations around the globe, and a
strategic focus on leveraging cyberspace for military,
economic, and political purposes.
Russia's cyber espionage campaigns prioritize sensitive
U.S. Government and military infrastructure and information and
spread disinformation campaigns to influence public opinion and
undermine our democratic processes. Iran, North Korea,
terrorist organizations, and transnational criminal groups also
challenge U.S. interests in cyberspace. And we are engaged in
ongoing efforts to exploit vulnerabilities--and are engaged in
ongoing efforts to exploit vulnerabilities in U.S. networks,
conduct influence operations, and erode our national security
interests.
With cyber operations becoming more sophisticated and
frequent, it is vital to evolve our capabilities against new
and novel threats. I am confident Cyber Command is well
postured to meet the ever-evolving challenges we face today,
creating advantage for the Department and the Nation.
Our mission is to direct, synchronize, and coordinate
cyberspace planning and operations to defend and advance
national interests in collaboration with domestic and
international partners.
We defend forward by countering cyber threats before they
can reach U.S. networks and critical infrastructure. These
proactive defensive measures ranging from network hardening and
threat hunting to information sharing bolster the resilience of
our systems and foil potential cyber attacks before they can
materialize.
We are aligned with the National Defense Strategy and the
DOD Cyber Strategy to protect Department of Defense information
systems, support Joint Force commanders with cyberspace
operations, and defend the Nation from significant cyber
attacks.
I am excited with what 2024 means for the maturation of
U.S. Cyber Command. This is a year of opportunity for us, and I
would like to thank Congress for the service like enhanced
budget control authorities granted by the 2022 NDAA and enacted
with the fiscal year 2024 appropriation. This authority creates
tighter alignment between requirements and acquisition, which
will result in faster capability and fielding for our cyber
mission force.
Additionally, this committee has been instrumental in
focusing attention on readiness across the cyber mission force.
The studies you have authorized are driving us to do work
needed to ensure we have the force structure and force
generation strategy necessary to field a force of the highest
quality today.
I hope we have an opportunity to unpack several of these
initiatives today. Since Cyber Command's elevation in 2018 to a
unified combatant command, Cyber Command has worked to make
most of its authorities, resources, and support. Of these
authorities, None is as vital to national security and the
command as Section 702 of the Foreign Intelligence Surveillance
Act, which is essential for identifying malicious cyber actors
in protection of the Nation and the Department of Defense.
I am confident we are successful in our mission each and
every day thanks to our people, our innovation, and our
partnerships--my top three priorities that ensure we deliver
outcomes against national priorities in foreign intelligence
and cyber security.
First, our strength lies in our people. Skilled cyber
warriors who are dedicated to protecting the Nation from
threats posed by our rivals and adversaries in cyberspace. We
win because of our people.
Second, Cyber Command remains committed to a relentless
approach in innovation to strengthen our military, now and into
the future. Our investment in technological innovation is key
to maintaining our overmatch against our adversaries.
Lastly, Cyber Command maintains our competitive advantage
through sustained and deliberate partnerships. In addition to
the unique partnership of the National Security Agency, Cyber
Command further embraces a team approach, working with my
fellow combatant commanders and interagency partners while also
collaborating with academic and industry experts, and
cooperating with our allies and partners by establishing
collective security.
I am extremely proud of the efforts Cyber Command has
achieved and the direction we are headed. I look forward to
your questions.
[The prepared statement of General Haugh can be found in
the Appendix on page 45.]
Mr. Gallagher. Thank you, General. You expressed, I
believe, that the Section 15--I am recognizing myself for
questions, in case that was not apparent. The Section 1533
study was looking at all options, to include the establishment
of the separate service and, hence, a separate analysis isn't
necessary.
But we required the Department to do the study in the 2020
NDAA, specifically to study the independent service idea as
part of the cyber posture review. It seems to me that DOD
ignored that requirement and then pointed us to a section in
the posture review that included an assessment. But if you look
at that section, no such assessment existed.
With this as context, I guess we will, one, address that.
But why should we believe that the Department will follow on
with an objective analysis as part of the 1533 study, given
that it was ignored previous to this.
General Haugh. Chairman Gallagher, I have no experience
with the 2020 study. I can tell you what we are doing today. So
we have taken that direction, and we have really--that is an
area for us that is really about the readiness of our force,
and how do we generate our force. So we have looked at that, in
combination with other studies that you have asked us to do
this year.
So there are other studies to look at our headquarters, to
look at our acquisition force, to look at how we examine our
architecture. And each of those we think make up a really good
opportunity for us to evaluate what is the future of this
force. So specific to your question on 1533, and the study that
is underway, the bookends that are required by the law are the
way it was done last year and an evaluation of a cyber service.
We are going to look at both of those bookends, and then look
at options in between that would allow us to generate the force
that we need.
The other things that I think are--that I know we are doing
today is the partnership we have with ASD Cyber, who is the
other portion of the study. So being done with ASD Cyber in OSD
[Office of the Secretary of Defense] and Cyber Command. We owe
that to the secretary in June, and we are required to brief him
in June the results of that study, and we are moving at pace to
ensure that we look at all of the options that you directed.
Mr. Gallagher. Now, I am on record as favoring something
like a zero-based budgeting for congressional studies because
they accumulate over time, and periodically we need to sort of
clear them out. But when they are a matter of U.S. law, they
should be complied with.
Ms. Manning, do you know how many congressional
requirements DOD is currently delinquent on?
Ms. Manning. Thank you for your question, Mr. Chairman.
This is actually one of the first questions I asked when I got
into the seat. And we are tracking 12 reports where our office
is the office of primary responsibility to be able to conduct
and conclude these reports.
I received a status update on all of these reports. There
are a couple that have been delayed because they were
independent studies that were dependent on getting funding, and
because of the continuing resolutions it has gotten delayed a
little bit. But my commitment to you is to make progress on all
of these reports and ensure that we are delivering them as
quickly as possible.
I would note that there are a myriad of other reports
related to cyber that have been directed across the Department,
and we are providing support as a coordinating entity on many
of those reports. And, in the interim, if there are specific
issues where you want to understand a bit more about what the
Department is doing and how we are addressing issues, myself
and my team are always willing to come up and brief you on
those.
Mr. Gallagher. I appreciate that. We are tracking 40, but
that may be a broader aperture than just your office, but we
very much would like to clear the backlog and work with both of
you on clearing the backlog, because, again, wherever those
reports appear it means that we--you know, we voted on it. We
had a debate on it, and it means there is questions we just
need answers to. And so I just would welcome your commitment to
clearing that backlog.
Ms. Manning, your office will also be assuming the
responsibility for certifying the cyberspace operations budget
within DOD. Last year we were informed that the fiscal year
2024 cyber ops budget was 7.4 billion, but then this year the
fiscal year 2025 ops budget, if I am correct, is 6.4 billion.
What we are trying to understand is, does this represent a
net decrease or a confusion about categorizing investments? Can
you share your view of what appears to be a net reduction of
nearly 1 billion or more than 15 percent of the overall budget?
Ms. Manning. Thank you for your question on our budget,
because it is really important that we get this right. So my
understanding is that overall our cyber activities' budget has
increased by almost a billion dollars due to added investment
in cyber security. The teams in both policy and in the Office
of the Chief Information Officer reviewed the various efforts
that are included in the different budgets and decided that
certain portions of the cyber ops budget are actually better
categorized as part of the cyber security budget. So there is
no reduction. It is more of a recategorization of some of the
activities that we are funding between the different budget
categories.
Mr. Gallagher. Thank you. My time has expired.
Mr. Khanna is recognized for 5 minutes.
Mr. Khanna. Thank you, Mr. Chair. Apologies for being a few
minutes late. We had an oversight hearing where I had to vote.
General Haugh, great to see you again. I appreciated our
conversation the other day.
And, Ms. Manning, thank you for your testimony.
General Haugh, one of the things that we had discussed is
the importance of getting young talent into our military
service, particularly young talent in technology. The military
can also be a place where they develop initial skills and
training, something that may be more accessible, frankly, for
people than just starting in Silicon Valley, which often does
not have as, unfortunately, broad-based hiring.
Can you talk about efforts at creating recruiting programs
at community colleges or historically black colleges, Hispanic-
serving institutes, and other public universities across the
country, that would allow us to recruit folks and perhaps even
recruit folks who may not have a 4-year degree?
General Haugh. Certainly, Ranking Member Khanna. This is
our important issue is, how do we grow talent and for--for U.S.
Cyber Command, for the Department, for the Nation. And so when
we look across what Cyber Command and NSA [National Security
Agency] are responsible for, in Cyber Command we have now grown
an academic network to allow us to partner with universities
across the country. So we have right now around 120
universities; in the National Security Agency, around 430. Both
of those provide a really foundational opportunity for us to
participate with our academic institutions on growing cyber
curriculum and also working with a number of research
institutions to be able to allow us to recruit that talent.
So when we think about it internally to our organizations,
that is how we maintain our partnership, growing relationships
with historically black colleges and universities, and also
looking at universities like University of Texas at San
Antonio, that has a large number of first-generation Americans
and Hispanic-Latino population. Drawing talent from across the
country to be able to ensure that we have the highest qualified
workforce.
Mr. Khanna. And do you need more flexibility from Congress?
Because I have heard mixed things in terms of you want someone
to come for 3 years, 4 years, and then they want to go on to
the private sector. Are you able to do that? Are you able to
have flexibility if you want to recruit someone who doesn't
have a college degree and is talented or wants to do a few
years? Or do you need more flexibility in the hiring?
General Haugh. So last year one of the studies that we
executed was under Section 1502, and it was about readiness.
And I am required each year to provide a report on service
readiness. In that report, we identified five provisions that
were all around personnel and administrative policies. So what
we are really looking for is we are seeing good things
happening in each of the services. We would like them all to
adapt each others' best practice.
So as you identified in this NDAA, Section 1535 was to
begin to drive those authorities across the Department. And I
think that would be an example of a step where we want to
continue to provide updates on which types of provisions would
help and then we work together with the services to be able to
enact those provisions.
Mr. Khanna. Ms. Manning, I don't know if you have any
comments or thoughts on how we recruit more talent into our
military.
Ms. Manning. I would say, first of all, I really applaud
the efforts that are underway to tackle this issue. It is a
real challenge across government in terms of how you recruit
and retain top talent to support our ongoing efforts, and
really building out the workforce that is necessary for us to
be able to accomplish our operational missions.
So I think, in addition to what we are dealing with in the
Department, I think looking at sharing best practices across
other departments and agencies will help generate new ideas in
terms of what more we can do as a government to ensure that we
are bringing people in to be able to serve our missions.
Mr. Khanna. One of the things--and you don't have to answer
it now, but I have just been told that there are some
restrictions on people being able to be hired only for a few
years, that that is hard to do because of civil service
protections. I don't know if that is the case or not, but I
just--I didn't know if Congress needs to act in any way to
simplify that.
General Haugh. What I would expect you are referring to is
our ability to have people leave and come back.
Mr. Khanna. Right.
General Haugh. And those are areas that I think we have got
to work internally within the Department in terms of how we
leverage the policies that we already have, but I think that is
an area that we should be continuing to explore, that if
somebody leaves and goes to industry, how do we bring that
expertise back into our force, not as if they are a new hire
but they are returning expert back into the Department.
Mr. Khanna. Thank you.
Mr. Gallagher. Mr. Gaetz.
Mr. Gaetz. Ms. Manning, I think you are totally right when
you say that China is prepositioning capabilities in advance of
some deployment of them. Is one way China does that by having
U.S.-based technology platforms that they own or control in
order to preposition for their cyber capability?
Ms. Manning. Thank you for your question. You know, as I
said, PRC is really our pacing challenge. And, as you note,
they are using malicious cyber activity to counter U.S.
conventional military power and to degrade the combat
capability of the Joint Force. And we need to ensure that we
are employing both defensive and offensive capabilities to
strengthen our deterrence and gain our advantage.
I defer to General Haugh for more of the details when it
comes to how we are operating.
Mr. Gaetz. Yeah. I am really interested in the defensive
part vis-a-vis like what China might be doing with technology
platforms in the United States. Do you have anything to add on
that, General?
General Haugh. So I think the area where we have seen
specific action that has concerned us is hacking activity at
our critical infrastructure and at Guam. I think those are
specific examples. In use of technology within the United
States, having Huawei presence, and things like that, is risk.
We----
Mr. Gaetz. Right. So that is what I want to get into,
because I agree. The hacking is sort of like if they are
breaking into your house, but the Huawei example you give is
more like inviting them in the front door.
Have either of you heard of this company called Tutor.com?
All right. So this is a technology platform that is owned by
Chinese nationals through the Primavera Holdings Limited
company, and it is principally used by DODEA [Department of
Defense Education Activity], by the Department of Defense's
education system, for military connected families.
If you had a technology platform that was being used
specifically by military families owned by Chinese nationals,
would that raise any red flags based on what you are talking
about regarding the need to be well-resilient to that
prepositioning that Ms. Manning discussed?
General Haugh. I think we want to dive deeper and ensure
that we are not bringing risk in, by whomever we partner with
and whatever company.
Mr. Gaetz. Yeah. No, I would just encourage it, because
this one sort of--I mean, I know how much you care about
resilience, particularly with our service members and their
families. We all know that they are targets oftentimes. And so
if we are inviting the Chinese in the front door here, I just
would advise you to look at that.
And I would draw your attention to the fact that Manny
Diaz, the Commissioner of Education in the State of Florida,
has advised superintendents of schools and charter schools to
discontinue the use of this technology. And even after the
State of Florida Secretary of Education made that pronouncement
based on these ties, the Department of Defense education system
continued to offer that platform to students of military
connected families in Florida and elsewhere.
So shifting gears just briefly to this concept of the cyber
force, I want to draw a finer point on what Mr. Khanna was
saying about recruitment. I have noticed anecdotally at our
academy nights that we have in our district that we get a lot
of students that are real interested in going to the academies,
and they are fired up about space force.
And I never really understood how a focused mission set
like that could really ignite a great deal of interest. And do
you think that we could get the same type of positive effect
with the cyber force to recruit specific people for a specific
domain? General?
General Haugh. So I think from our standpoint what we have
done is we have really focused on, what are the services doing?
How are they doing in terms of recruiting? One of the----
Mr. Gaetz. They are not doing great.
General Haugh. So what they have done, Congressman, is in
specific areas, particularly as I look--the area we focused on
has been the Navy, and as we have looked at where the Navy's
readiness has been. This past year, the Navy got 100 percent of
their cyber warfare technicians in terms of their recruiting
numbers. That shows me the services can do it, and that a
focused effort and continue and sustain that they will be able
to meet some of those marks.
Mr. Gaetz. I am open-minded. I think Chairman Gallagher
made some good points.
And, Mr. Chairman, before my time concludes, I wanted to
thank you for your outstanding service as chairman of our
subcommittee, your great work on the House Armed Services
Committee, and in the House more broadly. It has certainly been
to the country's benefit, and it has been to my personal
benefit to sit next to you for 7 years, 8 years, and to learn a
great deal from you along the way.
And I know many of our committee members feel the same,
that the thoughtfulness you brought to the position has
certainly been a great--been a great benefit to all of us. So
greatly appreciate it and yield back.
Mr. Khanna. Mr. Chairman, if I could speak out of order,
because I didn't know this was your last meeting, and I don't
know if there is an objection. But I just want to say from the
Democratic side that it has really been a pleasure working with
you, and you have displayed a patriotism and bipartisanship on
this committee that I think has been a model for what
leadership looks like. Even when we have disagreed, I have
never questioned that you have put the country's interests
first. And I know that this isn't going to be the last of your
public service. And you certainly have someone who is an
admirer on this side, and I think many of my colleagues feel
the same.
Mr. Gallagher. I very much appreciate it.
Mr. Ryan.
Mr. Ryan. All right. Well, I guess I am not allowed to say
nice things, so----
[Laughter.]
Mr. Ryan. Thank you, Mr. Chair. I will leave it at that, on
many levels.
And thank you both for being here. I want to build on some
of the different directions some of my colleagues were taking,
particularly honing in on as we continue to, to everyone's
credit, across the board develop more mature and robust and
sort of broader cyber capability, I want to push and get your
thoughts, General, on kind of that--what is that right
intersection point between CYBERCOM services, COCOMs [combatant
commands]?
I know that is a very broad question, so maybe to hone it a
little bit, can you--let's talk about--let's look actually at
the EUCOM [U.S. European Command] AOR [area of responsibility],
for example, just as--in theory. How is that playing out right
now? Where do you see the future going in terms of, as we build
more capability, how--what is the right handoff point to COCOMs
and services? Does that make sense?
General Haugh. It does. And what I would first start with
is, where are we today, in terms of now the authorities that
you have given us and the Department has given U.S. Cyber
Command? For the real general standup of U.S. Cyber Command,
our goal has been to become SOCOM-like [U.S. Special Operations
Command], to have service-like authorities.
Two weeks ago when the appropriation passed, that is the
first time that we have now had service-like authorities to do
budget, to do acquisition, to set the training standards for
the Department. So now what we really want to be graded on is,
what is our ability to generate new capability?
So, as things emerge, so today our partnership with EUCOM
is really strong, and I was the component to EUCOM as the Air
Force Cyber Commander and the 16th Air Force Commander at the
outset of Russia-Ukraine. And so that partnership is really
about them driving priorities in that theater, and then how we
leverage each of our components to be able to respond to that,
to be able to do defensive activities at their priority, but
also to be able to generate options that give a number of
things to the secretary and to the EUCOM commander that allow
us to consider how we would impose costs based off of their
guidance and direction.
I think it has worked well. I think the area that we need
to be able to accelerate is capability development. And how we
use our budget control and our authorities to generate and
acquisition, we should be able to develop things faster than
anybody else in the Department. The only thing we are
developing is code. How do we do that faster? How do we get it
in the hands of our cyber mission force faster?
Mr. Ryan. And you see that primarily happening or the large
preponderance of it happening at need essentially rather than
out there. Where do you--where do you see that?
General Haugh. We see increasingly that that would be a
balance. We will drive the requirement, we will drive the
overall acquisition oversight, and the dollars, but we will
also partner with the services. It will just look different.
Whereas, before the services would be able to do--were doing
that in support of their own forces they presented, which was
very disconnected from operations.
We are now going to be able to drive that, and we have got
good service partnerships with their program offices and with
their acquisition force. So we need to be able to move faster,
and we need to be able to recast those relationships that are
more responsive.
Mr. Ryan. And last follow up on this thread. So am I
hearing you right that the general direction, though, is more
capability at the CYBERCOM command level to push more, you
know, technical capabilities out there? Do you have the--do you
have enough sort of people and capability at your level to do
that? Like do you see the direction--do we have the pace that
we need? Do you have the resources you need to speed that up?
General Haugh. So from our perspective, the Department has
asked us to be the integrator of the joint cyber warfighting
architecture. That is the--those are the platforms and
capabilities that Cyber Command fights from. So for that now,
we have got to be able to drive that with our authorities.
Our team that we have from an acquisition perspective I am
very confident in. They are small. We have now been given more
resources. We have to hire quickly, and we have to use the
authorities that Congress has given us to be able to hire data
scientists under what we previously knew as the Section 1708
authority. We have now started to hire. We have got the policy
in place. So we have got to use all of those tools to really
accelerate our acquisition team to be able to meet those
objectives.
Mr. Ryan. I only have 40 seconds, but at the--as you look
10 years ahead, or 20 even, in terms of the quality of the
American, essentially, you are getting to show up, what more do
we need to do at the sort of community college level, high
school level? I know that is a big question for 30 seconds,
but----
General Haugh. So I think we have an opportunity. We have
expertise, and we have got partnerships across the--really, the
cadre of higher institutions that are really focused on cyber.
We can help influence that curriculum. How do we accelerate the
curriculum in a way that allows them to adopt and then to be
able to make it more available, particularly as technology
changes? Because I think what we find when we receive somebody
today, they have a good foundation, but they are not
necessarily current today.
Mr. Ryan. Thank you. I yield back, Mr. Chair.
Mr. Gallagher. Dr. McCormick.
Dr. McCormick. Thank you, Mr. Chair. And at the risk of
being gaveled out for being out of order in this--in this era
of politics where people are vilified for agreeing and vilified
for dissenting, Mr. Chair, it has been an honor to serve with
you, my fellow Marine. Let me just summarize by saying you can
be my wingman anytime. I am the Top Gun class, so I can say
that.
Considering we are at war, basically cyber war right now,
and our adversaries are attacking us regularly, almost
momentarily, around the clock, 24 hours a day, and how AI
[artificial intelligence] will affect that into the future and
accelerate that process, a lot of times the perception at least
is that we are always on the defense.
I was hoping, General, you could actually address that over
the last 2 years the new concept, such as persistent
engagement. Hunt forward and defend forward have started to
dominate the conversation, and I was hoping you could elaborate
on how the wider concepts are distinct from each other as we go
forward.
General Haugh. Congressman, thank you for the question. So,
first, as we think about campaigning against any one of those
adversaries that are targeting either our Nation or the
Department, we really think of it through three lenses. First,
how do we generate insights? How do we understand what is
underway? How do we communicate that to the broadest audience
possible? How do we enable defense? That is enabling industry,
it is enabling the Department, it is enabling our foreign
partners. And then, what are our options to impose costs?
Some of those are how we use our defensive force, and then
others are how we partner across the interagency, and then how
we generate options that allow us to contest in cyberspace. So
I think from our perspective we want to be able to bring a full
menu of not only defensive activities but those things that we
can do from both the interagency and from the Department to
impose costs.
Dr. McCormick. Is there anything that we can do to keep you
from being inhibited from doing what you need to do to be
optimized going forward using AI and other weapons that we have
to be not just posturing defensively but also being proactive?
General Haugh. So I think what you have done is you have
empowered us in a number of different ways in terms of how we
have brought together our acquisition force and how we have
brought together our authorities. We will identify areas
throughout this year, as we begin to use those authorities,
that I suspect you will start to see in budget requests for
fiscal year 2026.
We are going to learn a lot with the establishment of our
AI task force. We completed an AI roadmap last year, and that
lays out for us the technologies that we want to begin to
experiment with and pilot and introduce to our force. Those
will be areas that I would expect you are going to see from us
in the future.
Dr. McCormick. That is great. With that said, now that we
looked--this was brought up, interestingly enough, by our
chair, as far as the integrated Cyber Command versus the
individual departments. I have had plenty of people here
testify saying, well, we like--can I keep this in columns,
because each service has its own specific requirements.
But as AI continues to be a problem in integration, whether
it be on weapons systems, information collecting, dissemination
of information, the way it needs to be integrated throughout
purple force, if you will, my concern is that we will have
difficulties integrating even different weapons systems, let
alone the comprehensive battlefield, like when you talk about
purple assets, whether it be electronic jamming or information
gathering.
I am just wondering, is there a compromise in there that we
could come to in information sharing? Which is already the
biggest problem we have in the military anyway. It is just kind
of our Achilles heel, whether it be through COMs [commands] or
just getting the right information to the right people in the
right way. That is my biggest concern. If we don't have a Cyber
Command, how do we do that in an efficient way?
General Haugh. So what I would--the way that I would--the
way that I think the Department looks at it, the deputy
secretary has really empowered the CDAO [Chief Digital and
Artificial Intelligence Office] to set our data standards, and
to do that across the Department. And so when I look at our
teammates that we have in the DOD CIO [Chief Information
Office], in CDAO, how do we enable their ability to go faster
in some of those data standards?
And I think we have a role to play in that, and I think we
can help and assist, not only in how we set some of those
standards but how we think about defense of each of these
activities from a cyber perspective from the outset as we begin
to introduce some of those new technologies.
Dr. McCormick. Okay. I just--for the record, you can see a
lot of Congressmen are concerned about this integration
process. China has a huge advantage in this one area. They have
one command structure, one government. They all agree on each
other because it is kind of a monopolistic government, and it
is going to be a lot easier for them to integrate AI throughout
their weapons systems. The way they do digital technologies, it
is a lot less distractions. They have a lot more focality. And
I think if we get outpaced in the AI arena, we are in big, big
trouble. So I hope we do a good job on that.
Thank you. With that, I yield.
Mr. Gallagher. Mr. Moulton.
Mr. Moulton. Thank you, Mr. Chairman. And thank you very
much for being here.
A couple weeks ago the Foundation for Defense of
Democracies think-tank issued a report calling for a separate
cyber force. And I suspect you have read this. I know this is
not a new topic. It is something that I have discussed myself
over the years.
And I was curious--I mean, basically, the main argument of
the report is that because the individual services each run
their own recruitment, training, and promotion systems for
their cyber operations, those who get sent to U.S. Cyber
Command have inconsistent knowledge and qualifying experience.
So, General, how have these inconsistencies across the
services impacted the effectiveness of U.S. Cyber Command in
executing its mission?
General Haugh. So, Congressman, first, if I could address
the study, one of the areas that I do think that as we go
through this year the 1533 study, and we evaluate all of the
options available for force generation, we certainly are going
to look really closely at, what are the implications of a cyber
service? We will evaluate that.
One of the other responsibilities that is in both our
unified command plan and in the law is that I am responsible to
evaluate the overall health of the DOD cyber workforce. So I am
responsible to do that in plain English both to the Secretary
of Defense and back to Congress.
So I think from our perspective, those reports have allowed
us to identify where are areas that the services could improve.
And in doing so, it has also allowed us to build a partnership
with the services on how do we work together to improve the
readiness? Because I think what areas we had seen in the past
was not necessarily from the recruiting perspective but more so
from the assignment and retention.
And Congress has given us a number of authorities to the
Department that allow for retention incentives. What we were
seeing was the services implement those differently, and so
what we are encouraging, and what we did in our 1502 report
last year was to ask for some specific authorities that
encouraged our ability for assignment policies and personnel
policies to ensure that those trained individuals stay in our
force. And we have seen the services respond to those requests.
So we want to be able to lock those in and then continue to
work on other areas that will improve readiness within the
force.
Mr. Moulton. Do you feel that you are doing enough to use
the authorities that Congress has given you?
General Haugh. So I think now that we have budget control
authority that we received last month, that now gives us a new
series of options that will allow us to drive our priorities in
training, in readiness. We are responsible for the advanced
training of the Department's cyber force. How we use those
dollars in many ways will determine our readiness and our
proficiency.
Mr. Moulton. I would like to ask just a couple of questions
about deterrence. Deterrence is obviously important writ large,
but of course when we look at a China attack on Taiwan, we want
to deter that from happening in the first place. Deterrence is
tough in the cyber world because we worry about giving up our
capabilities when we use them.
How is your thinking about this evolving? And how do you
think--I would love to hear, General, a couple of comments.
And then, Ms. Manning, how do you think about this in the
integrated deterrence environment?
General, perhaps we could start with you. Just how--with
cyber force, how do you think about deterrence?
General Haugh. So from a Cyber Command perspective, what we
really think about in integrated deterrence are, who can we
bring that is a partner that will allow us to be able to have
the outcome we are trying to achieve? And for us, those
partnerships look different than in some of the other domains.
When we think about how--the role that industry plays in
terms of both creating the domain and also being the ones with
our own sensors that are global in nature, how do we partner
with industry? How do we partner with our foreign allies and
partners that either bring capability or have the same common
thread? How do we partner with our fellow combatant commanders
as they think about cyber security and defense? And how do we
integrate capabilities together to be able to have options?
So I think for us we have a unique set of partners, and we
have got to be able to use our authorities in how we defend
forward and do it every single day.
Mr. Moulton. Ms. Manning, how are you thinking about
working with your counterparts in other agencies to fulfill
this goal of integrated deterrence?
Ms. Manning. Thank you for your question, Congressman. We
really do see cyber deterrence, as you mentioned, as part of
overall integrated deterrence, in thinking about integrating
across the Department, across domains, across the interagency,
and also with allies and partners in those private-public
partnerships that General Haugh mentioned.
And it is important that we work together with our
interagency partners, with our partners in industry, and with
our allies and partners to really look at ways that we can deny
adversaries the benefit of cyber attack by, one, being able to
provide indications and warnings of threats to benefit our
interagency partners, and then also by imposing consequences on
our adversaries by disrupting their operations.
Mr. Moulton. Thank you, Mr. Chairman.
Mr. Gallagher. Thank you. I should note the Section 1533
study that I referenced earlier was, I believe, Mr. Moulton's
amendment. So he deserves credit for provoking and stimulating
the debate that led to the report he referenced, and so I thank
him for that.
Mr. Fallon is recognized.
Mr. Fallon. Thank you, Mr. Chairman, and thank you for your
service to the country. I am sorry to see you go. But as--to
quote the immortal words of Dr. Seuss, don't cry because it is
over; smile because it happened.
Last November, the North Texas Municipal Water District got
hacked, and it was a domestic--it was a domestic attack, but,
nonetheless--and they didn't shut it down, but they showed that
they could have. And it reminded me of JBS and Colonial
Pipeline.
And, General, I wanted to ask you, what have we learned?
Because that is the greatest fear we all have is that these
critical areas--water, electricity, energy, fuel. What have we
learned from those attacks that we can employ within the
Defense Department?
General Haugh. So I will give you a couple different
things, Congressman. One is this is an area that we have
clearly identified that the PRC is targeting. So this wasn't in
this case, but we know that it is an area they are targeting.
So from a national readiness perspective, we have to consider
that.
The other thing we think about is, what does it look like
for defense critical infrastructure? Those things that are the
nexus between our private infrastructure and those things the
Department would rely upon if we were mobilizing. So that is a
partnership with NORTHCOM [U.S. Northern Command], and it is a
partnership with Homeland Security.
I think those are areas that within the Department we have
now focused, how do we think about that nexus, and what will it
mean for the Department from a cyber security standpoint? So I
think we have now been applying some of those lessons. We are
going to have to continue to scale as we think about it within
the Department.
Mr. Fallon. And then, you know, with--you mentioned that
CCP [Chinese Communist Party] and, like, Volt Typhoon comes to
mind, there is no doubt that they are actively probing, of
course. Can you talk about the work that you are doing with
industry partners? Because, you know, chain, meet weakest link.
If we have got some of our partners buttoned up and secure as a
uniformed service, or even along the DOD, but a private company
that is working with us isn't, it doesn't get us anywhere.
So can you talk to us about what we are doing to enhance
particularly the cyber security of our partners?
General Haugh. Yes, Congressman. Both Congress and the
Department have given Cyber Command and NSA authorities to work
with our Defense Industrial Base. And that information-sharing
component has now allowed us to establish over 1,000
partnerships, and that allows us to exchange information, it
allows us to do it in real time at an unclassified level, so
that we can make industry aware of those threats.
As we think about those partnerships, now DOD CIO has also
funded additional activities that allow us to provide services
to the Defense Industrial Base--protective DNS [Domain Name
System]--so that they have a service that would make it more
difficult for a redirection attack or a spear phishing attack
informed by NSA's knowledge.
The other things we have been doing are scanning of various
elements of the Defense Industrial Base. We provide them a
scan. We tell them what vulnerabilities we see and allow them
to correct those vulnerabilities themselves. We are going to
continue to look at what other services we can provide, but we
are also looking at how can we extend those partnerships to a
broader number that would ensure that we are covering the
highest priority things that support the Department.
Mr. Fallon. Thank you. And then, you know, when people come
into our offices, they are all dying for labor. It doesn't
matter what industry it is. I ask them, ``Do you have--you
know, do you have job openings?'' and they are all crying for
labor, so--and particularly skilled labor even more so.
So I wanted to ask maybe Ms. Manning as well, what can we
do, if anything, do we need to do? I remember being a junior
officer and the doctors got paid more because, you know, that
is just the market, right? You want to--you want to have those
medical doctors stay on after maybe they owe some time after
getting--going through medical school.
But in particularly this field, it is just a high demand,
and it--they make quite a bit of money. Do we--is there
incentive pay for folks in this service? And does it need to--
do we need to ratchet it up? I just want to kick that to both
of you.
Ms. Manning. You know, I think at this point it is
important that we consider all different ideas of how we can
recruit and retain top talent. I think incentives are one tool
that we have in our toolkit. I think also, though, there is a
sense of mission that comes with doing the work in the
Department.
And so thinking about how we can make people feel really
connected to the mission itself is another thing that we can
think about. But I think really understanding what is it that
is motivating people to come to these jobs, what is allowing
them to sustain careers in government long term, and I think
pay incentives are one of the tools we have at our disposal.
Mr. Fallon. I just don't want the canyon to be this big.
You know, if it is 300-grand in the private market, and it is
100-grand here, that is just too big of a canyon, even if you
are really rewarded, if we can close it. That is kind of my
point.
Thank you. Mr. Chairman, I yield back.
Mr. Gallagher. Mr. Luttrell.
Mr. Luttrell. Thank you, Mr. Chairman.
General, in December 2022, SECDEF [Secretary of Defense]
officially elevated CYBERCOM's offensive arm, the Cyber
National Mission Force, to a sub-unified command. The logic was
that it would provide greater enabling resources for this
critical mission set. With how much adversary activity we have
witnessed against DOD networks, it would appear that your
defensive arm, Joint Forces Headquarters, could similarly
benefit.
Could you share your opinion?
General Haugh. Thank you, Congressman. So when we stood
up--when we elevated the Cyber National Mission Force, it was
at a point, so we now--that is about a third of our force, and
with a very distinct headquarters and assigned forces. That
has--now I think was absolutely the right thing for us to do,
that we are allowing it to create an identity, we are allowing
it to grow its own staff to expand its planning, and then--and
other capability development. I think we are seeing benefit
from that.
This is an area that we are going to look at in the 1533
study, which is, as we start to think about--or, actually, the
1537 study that you have asked us to do looking at our
headquarters. What is the right way to position the Joint Force
Headquarters DODIN [Department of Defense information networks]
in terms of the right resources and authorities to make sure
that it has the capacity to really set the globe? That is the
mission we have given them.
When we have a crisis, we want them to set the globe. So I
think it is an area that we are certainly going to evaluate,
and it does look different as a headquarters, also in terms of
assigned forces, but it is something that we will definitely be
looking at.
Mr. Luttrell. Thank you.
Ms. Manning, I apologize for walking on Mr. Fallon's
questions. To expand or to create an expansiveness of talent,
we wanted to reach out to academics--academia and institutes of
higher performance, correct? Are we doing that, from your--in
your opinion?
I have universities in my district, and then of course, as
I travel the state and the country, I have these discussions
when it comes to cyber risk, cyber threat, cyberspace,
artificial intelligence, machine learning, and how it seems
like we are missing the rising wave, because our brilliant
minds are traveling elsewhere. Are we creating effective
narrative from your position in order to share that with the
youth and say, ``Hey'--and I say ``youth,'' but our next
generation of computational mathematicians.
Ms. Manning. I think there are two aspects to this. I think
one is making folks see a career in government as something
that they want to pursue, and they see building the skills in
cyber and in other fields as something where they can have a
unique role in terms of defending our national security
interests by having jobs you can really only do when you are in
government, so----
Mr. Luttrell. So how do we make working for the government
sound cool?
Ms. Manning. I think that is a really important point, and
I think also beyond just making it sound cool, how do you have
the----
Mr. Luttrell. For lack of a better term, I am sorry, I
should have stated that better.
Ms. Manning. No. I think, you know, it needs to be
relatable, and we also don't need the mechanisms to bring
people into government. So looking at different tools like the
cyber accepted service, looking at the presidential management
tool, fellowship, looking at different scholarships and
opportunities, I think all of this should be on the table, so
that we can give folks the opportunity not only to want to
serve in government but to be able to have the mechanisms to
come in and be able to be a part of our team.
Mr. Luttrell. Are we looking at having them serve in the
various branches of armed services or just government in
general? Because, as we know, we are having trouble recruiting
the bodies for those platforms. Is it both, in between, or is
it just something we are trying to cast that wide net and fill
all of the--all of the silos?
Ms. Manning. I would defer to the team who is responsible
for personnel and readiness in terms of the overall policy.
Mr. Luttrell. Oh, that is a great shift.
Ms. Manning. But I think there are opportunities, both
within the command, within the services, or for individuals to
come in and to serve.
Mr. Luttrell. General, have you got something on that one?
General Haugh. So what I would give you is, what do we see
that are things that are pretty exciting that are really
looking at high schools and middle schools? I just attended the
finals of CyberPatriot, 5,000 schools across the country where
they are doing cyber competitions in middle school and in high
school and in ROTC [Reserve Officers' Training Corps] programs.
Those are the types of things that we want to be able to do
as early--we would like to see being done as early as possible,
so that we are really trying to capture people and what it
looks like to be--that can be both cool and really impactful
things for our Nation. I think----
Mr. Luttrell. They seem like they have a willingness to put
a uniform on?
General Haugh. I think what we have seen is they have done
a really nice job of bringing people towards the technology,
and then it is our job to be able to have opportunities with
the ROTC programs that are in high school and also to be able
to reach out and be able to explain, what would you do if you
came and worked with us, either as a civilian or in the
military? That is our story that we have got to tell. Yes, sir.
Mr. Luttrell. Thank you, Mr. Chairman.
Mr. Gallagher. Thank you. Does any other member have a
follow-up question?
Okay. The FDD [Foundation for Defense of Democracies]-- we
are going to have a classified session after this. But I think
the FDD report that you have heard referenced numerous times
here--again, I think--I mean, I am biased because I worked with
a lot of these people in the Cyberspace Solarium Commission. I
will admit that. But I think what is most compelling in it is
the testimony from active duty, ranging from company grade to
general grade officers.
And I would like to read one statement from a Marine Corps
captain, and all wisdom emanates from Marine Corps captains, as
Mr. Moulton and I know quite well.
``Leading in the cyberspace domain demands technical
competency that cannot be taught in a 12-month schoolhouse
alone. One of my worst professional experiences involved
working underneath a woefully unprepared commander with a
degree in culinary arts. Under no circumstance would a cyber
officer be asked to lead a squadron of aircraft, and that the
opposite is often true.''
That is just one of many quotes in the report that I think
are worth reading. And, again, I am not biasing the outcome of
the study you guys are going to do or an independent study, but
I just think it is fair to say at this point that the status
quo is not getting the job done. So we are asking you to take a
hard look at this problem and work in partnership with us to
come up with a better model.
As was referenced by some of my colleagues, we have given
so many authorities to DOD in the 8 years I have been on this
committee, and it has all been well intentioned. It just seems
like it is not adding up or producing the outcome we want.
And so I know you are both relatively new to your
respective jobs, and they are critically important jobs, and
our commitment is to work with you to get this right, because
the safety of our country and our citizens are quite literally
hanging in the balance. And so we appreciate your time today.
We look forward to the classified session.
And, finally, since he was not here when I said nice things
about him, I just want to reiterate how much of a pleasure it
has been to work with Ranking Member Ro Khanna, not just on
this committee but on many issues. One of my fondest memories
is the op-ed we did on congressional reform together when we
were impetuous freshman members of Congress.
Mr. Khanna. Still no reform.
[Laughter.]
Mr. Gallagher. Still no reform. Yeah. My biggest failure.
Term limits didn't happen. We went to the White House together
to talk about that.
But, Ro, you have always been incredibly, obviously, smart
and independent-minded, but you have a bias for action that I
admire, that I think is rare among people in public service,
and I also appreciate your sense of humor and that you take the
mission, but not yourself, too seriously.
So thank you for your productive partnership. Appreciate
that.
With that, the open hearing is adjourned, and we will move
to a classified session.
[Whereupon, at 4:30 p.m., the subcommittee was adjourned.]
=======================================================================
A P P E N D I X
April 10, 2024
=======================================================================
=======================================================================
PREPARED STATEMENTS SUBMITTED FOR THE RECORD
April 10, 2024
=======================================================================
=======================================================================
DOCUMENTS SUBMITTED FOR THE RECORD
April 10, 2024
=======================================================================
=======================================================================
QUESTIONS SUBMITTED BY MEMBERS POST HEARING
April 10, 2024
=======================================================================
QUESTIONS SUBMITTED BY MRS. MCCLAIN
Mrs. McClain. One of the trends we are seeing in terms of
cyber-attacks is that adversaries have figured out how to phish
many of the legacy tools that we have used in authentication.
Not just passwords, but also some of the tools that we have
used in multi-factor authentication (MFA), such as one-time
passwords and push notifications. Civilian agencies seem to be
making good progress on this front, thanks in large part to a
2022 OMB memo (M-22-09) that required agencies to use only
``phishing-resistant authentication'' that can block phishing
attacks; CISA and NIST have also been highlighting the
importance of phishing-resistant authentication, such as
products that use the FIDO standards, to civilian agencies in
their guidance.
As OMB noted, users can be fooled into providing a one-time
code or responding to a security prompt that grants the
attacker account access, and these attacks can be fully
automated and operate cheaply at significant scale. But there
is no similar policy in DOD to ensure that, in places where the
Common Access Card (CAC) and its PKI authentication can't be
used, the authentication tools that are being used can block
phishing attacks.
Can you explain why DOD seems to be behind civilian
agencies on this critical cybersecurity control (ensuring that
phishable authentication can no longer be used)?
What are your plans to close this security hole across the
Defense Department? Will the DOD create a strategy or policy to
ensure that whenever the CAC can't be used, any alternative
authenticator can block phishing attacks?
Ms. Manning. The cyber threat landscape is evolving at a
pace that requires a coordinated, agile, and defensive
response. I applaud the efforts of CISA and NIST to prioritize
phishing-resistant multi-factor authentication (MFA) within
civilian agencies. Phishing-resistant MFA and Zero Trust
security architectures are critical requirements for all
federal agencies, per Executive Order 14028 on improving the
Nation's cybersecurity. The DoD Chief Information Officer (CIO)
has prioritized implementing Zero Trust through continuous
multi-factor authentication, micro-segmentation, advanced
encryption, endpoint security, analytics, and robust auditing
among other capabilities to fortify data, applications, assets,
and services to deliver cyber resiliency. It is DoD policy that
organizations use the Common Access Card (CAC) as the
authenticator of choice wherever possible, including cloud
environments. In scenarios where a CAC cannot be used or the
user does not have a CAC, DoD has a list of approved phishing-
resistant authenticators for which the user's identity is tied
to a hardware device. The DoD CIO is currently working with the
components to develop a DoD MFA strategy that will guide the
use and approval of anti-phishing MFAs when use of the CAC is
not possible.
Mrs. McClain. Last May, the DOD CIO put out a policy (DOD
Instruction 8520.03, ``Identity Authentication for Information
Systems'' that created a formal approval process for multi-
factor authentication (MFA) technologies to be used as an
alternative to the Common Access Card (CAC) and its PKI-based
authentication, with a focus on ensuring that strong MFA is
being used in applications which cannot easily integrate with
the CAC or where the use of PKI is not practical. For example,
the CAC is not optimized for use in some mobile devices. In
addition, a CAC is not issued to every individual that requires
access to DOD resources.
Can you share how many MFA solutions have been approved
under this new policy? And have any of these approvals been for
phishing-resistant authentication solutions that can block the
increased volume of phishing attacks that have been targeting
legacy MFA technologies such as one-time passwords and push
notifications? What can be done to accelerate this process?
Ms. Manning. Four alternatives to the DoD Common Access
Card (CAC) have been approved under DoD Instruction 8520.03,
``Identity Authentication for Information Systems,'' two of
which are phishing-resistant. The other two multi-factor
authentication (MFA) technologies were approved prior to the
release of the updated DoD Instruction. Another five
alternatives are being evaluated. Of the ones currently being
evaluated, all are intended to be phishing-resistant. DoD is
developing an MFA strategy that will inform an update to DoDI
8520.03 and guide the selection and use of alternative MFAs.
Mrs. McClain. One of the trends we are seeing in terms of
cyber-attacks is that adversaries have figured out how to phish
many of the legacy tools that we have used in authentication.
Not just passwords, but also some of the tools that we have
used in multi-factor authentication (MFA), such as one-time
passwords and push notifications. Civilian agencies seem to be
making good progress on this front, thanks in large part to a
2022 OMB memo (M-22-09) that required agencies to use only
``phishing-resistant authentication'' that can block phishing
attacks; CISA and NIST have also been highlighting the
importance of phishing-resistant authentication, such as
products that use the FIDO standards, to civilian agencies in
their guidance.
As OMB noted, users can be fooled into providing a one-time
code or responding to a security prompt that grants the
attacker account access, and these attacks can be fully
automated and operate cheaply at significant scale. But there
is no similar policy in DOD to ensure that, in places where the
Common Access Card (CAC) and its PKI authentication can't be
used, the authentication tools that are being used can block
phishing attacks.
Can you explain why DOD seems to be behind civilian
agencies on this critical cybersecurity control (ensuring that
phishable authentication can no longer be used)?
What are your plans to close this security hole across the
Defense Department? Will the DOD create a strategy or policy to
ensure that whenever the CAC can't be used, any alternative
authenticator can block phishing attacks?
General Haugh. The DOD CIO, as the author of the DoD
Instruction 8520.03, ``Identity Authentication for Information
Systems,'' published on May 19, 2023 and DoD Instruction
8520.02, ``Public Key Infrastructure (PKI) and Public Key (PK)
Enabling,'' published on May 24, 2011, is best postured to
provide a formal response regarding the perception of an
authentication security hole and any efforts to address them
with strategy or policy. As the policy owner, DOD CIO
``Approves [multi-factor technology] MFA technologies for use
by DOD information systems . . . '' while also addressing
applicable security controls. JFHQ-DODIN, on behalf of
USCYBERCOM, manages cyberspace risk to DoD missions by
executing command and control across all DoD components and
reinforcing or augmenting DoD policy whenever practical through
the release of operational orders. In this role, JFHQ-DODIN is
responsible for synchronizing and coordinating actions in and
through cyberspace so that the Department remains postured
against sustained threats posing risk to the nation's strategic
interests. Operational orders may be proactive or preventative
in nature, may be focused on availability and resiliency of the
DODIN, or may be responsive to suspicious or malicious events.
All orders, regardless of focus, are tracked to completion and
subsequently monitored for compliance.
Mrs. McClain. Last May, the DOD CIO put out a policy (DOD
Instruction 8520.03, ``Identity Authentication for Information
Systems'' that created a formal approval process for multi-
factor authentication (MFA) technologies to be used as an
alternative to the Common Access Card (CAC) and its PKI-based
authentication, with a focus on ensuring that strong MFA is
being used in applications which cannot easily integrate with
the CAC or where the use of PKI is not practical. For example,
the CAC is not optimized for use in some mobile devices. In
addition, a CAC is not issued to every individual that requires
access to DOD resources.
Can you share how many MFA solutions have been approved
under this new policy? And have any of these approvals been for
phishing-resistant authentication solutions that can block the
increased volume of phishing attacks that have been targeting
legacy MFA technologies such as one-time passwords and push
notifications? What can be done to accelerate this process?
General Haugh. The DOD CIO, as the author of the DoD
Instruction 8520.03, ``Identity Authentication for Information
Systems,'' published on May 19, 2023 and DoD Instruction
8520.02, ``Public Key Infrastructure (PKI) and Public Key (PK)
Enabling,'' published on May 24, 2011, is best postured to
provide a formal response. As the policy owner, DOD CIO
``Approves [multi-factor technology] MFA technologies for use
by DOD information systems . . . '' and is therefore the
appropriate source of MFA solution approvals and other process-
related questions.
------
QUESTIONS SUBMITTED BY MR. LALOTA
Mr. LaLota. How is DoD tracking cyber workforce training,
credentials, and job placements?
Ms. Manning. The Department has a robust overarching
governance architecture for managing the training,
credentialing, and assignment of its 230,000-person cyber
workforce. This architecture is defined in DoDD 8140.01
``Cyberspace Workforce Management,'' which established the
Cyberspace Workforce Management Board (CWMB) as the governing
body tri-chaired by the Under Secretary of Defense for
Personnel and Readiness (USD(P&R)), the DoD Chief Information
Officer (CIO), and the Principal Cyber Advisor (PCA). The DoDD
8140.01 specifies the DoD Cyber Workforce Framework (DCWF),
comprising 72 cyber-related work roles, as the basis for cyber
workforce identification (e.g., assigning work roles to
military and civilian positions) and qualification requirements
(e.g., education, training, certifications, job-specific
credentials) tailored to each work role's basic, intermediate,
and advanced proficiency levels.
Work role categorization allows the CWMB to make more
targeted decisions with respect to hiring, retention, and
incentives based on the criticality of various roles. The
Services and DoD agencies maintain their own qualification
tracking systems with unique data constructs. For example,
USCYBERCOM tracks training and credentials of the Cyber Mission
Force in its Joint Cyber Command and Control-Readiness system
(JCC2R). The DoD CIO launched a data maturity initiative in FY
2024 to generate a holistic assessment of cyber workforce
readiness garnering qualification metrics across DoD. During
the first phase of this effort, the DoD CIO conducted an
environmental scan of DoD workforce tracking systems which
identified authoritative sources to harness qualification data.
The second phase underway involves creating data structure and
standardization to enable integration of qualification data
from DoD's disparate systems. The DoD CIO currently employs
Advana, DoD's data analytics platform, for tracking cyber
workforce work role identification through dashboards and other
data visualization and plans to leverage automated tracking and
reporting of cyber qualifications utilizing Advana in FY 2026.
Mr. LaLota. What steps are CYBERCOM and the DOD taking to
cultivate and support the development of cyber talent within
the defense industry?
General Haugh. USCYBERCOM continues to pursue additional
authorities to maximize our ability to recruit and retain high
demand, low-density cyber talent across the global cyber
enterprise to better enable us to fight and WIN the war for
talent. J1 is collaborating with DoD CIO, the Principal Cyber
Advisor, and OSD Policy to execute NDAA 1531 to incentivize our
service members with up to $2500 bonus for their novel action,
invention, or achievement that enables operational outcomes in
cyberspace against threats to National Security. Additionally,
we are advocating for Target Local Market Supplement (TLMS) pay
for our critical work roles with high turnover rates to
increase pay up to 28%.
Lastly, we are partnering with Army to execute the 10
U.S.C. 4092 authorities to hire imminent experts in data
science, computer science, and computer network exploitation
and pay them above the GG pay scale ($181K--246K annually, with
the ability to incentivize up to 25% of base pay). This could
result in an annual pay in upwards of $307K. USCYBERCOM
continues to maximize the use of our Cyber Excepted Service
authorities while pursuing the additional authorities outlined
above, which refine the Command's ability to engage talent
through partnerships and innovation and allow further
competition with industry salaries. Moving forward, we
recognize the Campaign for Talent goes beyond financial
incentives and requires a holistic approach to recruit AND
retain world-class talent we need to support the cyber
enterprise. USCYBERCOM stood up a Civilian Workforce Council,
charged with identifying development and mentorship
opportunities for the military and civilian workforce to set us
apart from the competition and intentionally grow talent to
fill key positions within the broader cyber enterprise. We are
expanding our internship opportunities and collaborating with
our Academic Engagement Network (AEN) of 127 schools, to
inspire the next generation of cyber talent.
Through the AEN, the Command has direct access to the
students and faculty at these schools, establishing a pathway
for students to seek employment at USCYBERCOM or other
government agencies in the cyber field. Finally, our Command
Code is, ``We WIN With People.'' Our new cyber recruiting cell
enables global recruiting in support of the cyber mission and
affords us the opportunity to rapidly identify and recruit the
talent we need to enable our mission in defense of the Nation.
Speed and agility is the key to our success.
Mr. LaLota. Are there particular programs or partnerships
in place to ensure that even small and medium-sized defense
suppliers, like the strong core of defense industrial suppliers
on Long Island, have access to skilled cybersecurity
professionals to meet the strategy's compliance requirements
and enhance their cyber posture against the backdrop of
evolving cyber threats?
General Haugh. NSA's Directorate of Cybersecurity operates
the Cybersecurity Collaboration Center (CCC). The CCC operates
a Defense Industrial Base (DIB) Defense program that supports
enhanced security of the DIB by providing intel-driven
cybersecurity solutions to DoD contractors (to include small
and medium sized defense suppliers). DIB Defense (NSA C53)
provides cybersecurity services that address the top ways
nation-state actors target the DIB, and are infused with NSA's
unique insights and analytics. These services include
Protective Domain Name System (PDNS), Attack Surface Management
(ASM), and Threat Intelligence Collaboration (TIC).
In addition to these core services, DIB Defense also runs
multiple pilot services with DIB partners to include Cloud
Security, Threat Hunting, Phishing Protection, and Autonomous
Penetration Testing. UNDERADVISEMENT (UNAD) is a Cyber National
Mission Force (CNMF)-designated information-sharing activity
designed for partnerships with private sector entities. This
information sharing is overt, voluntary, and reciprocal, with
acknowledgement of the identities of the participants and the
organizations to which they belong. This allows for appropriate
information sharing regarding cybersecurity and cyber threats
related to assigned missions between CNMF and the private
sector. UNAD complements other USG information sharing
programs, complies with existing U.S. law and policy, and
allows for engagement with the private sector on terms with
which the private sector is accustomed.
CNMF information sharing under UNAD facilitates CNMF
operations and timely partner defensive actions. Currently,
UNAD is an unfunded activity but will be designated as the
USCYBERCOM Executive Agent responsible for managing cyber
threat information sharing between USCYBERCOM Components and
the private sector to meet the intent of FY19 NDAA Sec. 1642(b)
and FY22 NDAA Sec. 1508. Outside of USCYBERCOM, the
Cybersecurity and Infrastructure Security Agency (CISA) ensures
members of the Defense Industrial Base (DIB) have access to
skilled cybersecurity professionals to enhance their cyber
posture against the backdrop of evolving cyber threats.
Specifically targeted to supporting the DIB, CISA manages the
DoD's Defense Industrial Base Cyber Program specifically
seeking to enhance and supplement DIB participant's
capabilities to safeguard DoD information that resides on or is
transmitted on unclassified information systems. This program
is free of cost to DIB participants and open to all cleared
defense contractors. For more information, potential DIB
participants should reach out to CISA at OSD.DIBCISA@mail.mil
or visit their website at https://DIBNet.dod.mil.
------
QUESTIONS SUBMITTED BY MR. WITTMAN
Mr. Wittman. The threat of Chinese cyber capabilities
continues to be a persistent and penetrating issue for the
Congress and U.S. Government in general. One of the
vulnerabilities that Congress continues to address is TikTok.
The Congress took action and banned TikTok on all government
devices and devices that access government information. Given
the young age of many service members, it is not presumptuous
to assume that many of them have TikTok accounts and have
downloaded the application on their personal devices. To
protect the data of U.S. service members, personally
identifiable information, and controlled and classified
information, is the Department of Defense currently compliance
with US Code S.1143--No TikTok on Government Devices Act? What
is the Department doing to ensure that the TikTok ban is
enforced, particularly on Government issues cell phones or any
bring your own device solutions. Finally, how does the
Department intend to enforce this Code with the contractors
required and identified under CMMC guidance?
Ms. Manning. TikTok remains a national security concern due
to the sheer volume of user data it collects and potential for
exposure and access of U.S. user data by PRC-based ByteDance.
It is crucial for our Nation to tackle this issue, especially
as similar applications will arise, requiring policies that
strike a balance between information access and protection
against adversarial surveillance and malign influence. On March
3, 2023, the DoD Chief Information Officer (CIO) released the
``Removal and Ban of the Installation of TikTok'' and provided
implementation guidance on May 4, 2023. Both memoranda enforce
the TikTok ban on all government devices. DoD policy required
removal of the TikTok application from all government devices.
Furthermore, the ``DoD Mobile Device Policy'' and ``Use of Non-
Government Owned Mobile Devices'' policy requires government
and contractor issued devices to be enrolled in an Enterprise
Mobility Manager (EMM) for management of DoD information and
applications. Once enrolled, managed devices can only install
mobile applications that have been approved by the EMM and are
available through the managed application store. This
requirement ensures the TikTok ban is enforced on all
government devices.
Moreover, the Cybersecurity Maturity Model Certification
(CMMC) Program will require that DoD contractors manifest
compliance with the cybersecurity safeguards in already
required standards as a condition of receiving awards and
continued business. The purpose of the CMMC Program is to
validate that existing security requirements in NIST Special
Publication (SP) 800-171, ``Protecting Controlled Unclassified
Information in Nonfederal Systems and Organizations'' and
select security requirements from NIST SP 800-172, ``Enhanced
Security Requirements for Protecting Controlled Unclassified
Information'' are properly implemented in accordance with
contractual requirements. The CMMC Program does not directly
prohibit the use of TikTok on contractor devices. However,
several of the NIST control requirements assessed via the CMMC
Program ensure that contractors implement system policies that
prevent personnel or automated processes from installing
software such as TikTok, create and retain system auditing logs
and records needed to monitor unauthorized activities, and
ensure that such auditing logs are traceable to individual
users to hold them accountable.
Mr. Wittman. The Cybersecurity and Infrastructure Security
Agency (CISA) published in March the ``Review of the Summer
2023 Microsoft Exchange Online Intrusion'' that assessed the
security failures of Microsoft which led to successful
cyberattacks from Chinese and Russian hackers (ex: Fancy Bear
and Midnight Blizzard). Additional cyber-attacks against
Microsoft have been reported since the major incidents of 2023,
leading CISA to issue an Emergency Directive 24-02. With regard
to the Department's use of Microsoft software, have you
implemented any policies to mitigate exposure, through
Microsoft capabilities, of the Department to TikTok or
ByteDance applications? Furthermore, in the Midnight Blizzard
attack, source code repositories and internal systems were
compromised. Was the compromised code the sane code of
platforms upon which the Department relies? Does the Department
rely on a single vendor for the majority of its Unclassified
and Classified communications? And does DOD practice vendor
diversity and ``Defense in Depth'' for these types of systems
and software? Finally, it is my understanding the Army, and
potentially other services and agencies, employ the full suite
of Microsoft 365 services. Since the entire suite is closely
integrated, to what extent has DOD been able to meet the CISA
Emergency Directive to take immediate, remediating action for
tokens, passwords, API keys, or other authentication
credentials known or suspected to be compromised?
Ms. Manning. The Department of Defense (DoD) utilizes
multiple cybersecurity tools including Microsoft tools to
mitigate exposure from applications such as TikTok. DoD applies
network content filtering to all DoD networks to block access
to the TikTok website. In addition, the DoD Chief Information
Officer (CIO) memorandum on the ``Use of Unclassified Mobile
Applications in Department of Defense'' dated October 6, 2023,
outlines mitigations for mobile devices by segmenting DoD
information from unmanaged and non-DoD applications such as
TikTok or ByteDance applications. While DoD employs Microsoft
Windows and Office Suite for basic computing and
communications, it also employs a wide variety of non-Microsoft
technologies in support of its various missions. The DoD
emphasizes vendor diversity per the requirements for
competition set out in the Federal Acquisition Regulation
(FAR). The Department is aware of the Midnight Blizzard
compromise, which resulted in the exfiltration of email
correspondence through a compromise of Microsoft corporate
email accounts. These emails contain authentication details,
which Midnight Blizzard is seeking to use to gain access to
Microsoft systems. USCYBERCOM tasked all DoD components to
investigate and mitigate the compromise. The tasking covers the
Cybersecurity and Infrastructure Security Agency (CISA)'s
Emergency Directive actions.
Mr. Wittman. The threat of Chinese cyber capabilities
continues to be a persistent and penetrating issue for the
Congress and U.S. Government in general. One of the
vulnerabilities that Congress continues to address is TikTok.
The Congress took action and banned TikTok on all government
devices and devices that access government information. Given
the young age of many service members, it is not presumptuous
to assume that many of them have TikTok accounts and have
downloaded the application on their personal devices. To
protect the data of U.S. service members, personally
identifiable information, and controlled and classified
information, is the Department of Defense currently compliance
with US Code S.1143--No TikTok on Government Devices Act? What
is the Department doing to ensure that the TikTok ban is
enforced, particularly on Government issues cell phones or any
bring your own device solutions. Finally, how does the
Department intend to enforce this Code with the contractors
required and identified under CMMC guidance?
General Haugh. Regarding the ban of TikTok on government
devices, JFHQ-DODIN directed removal of TikTok ``from all
Government Furnished Equipment (GFE) and prohibit users from
downloading or accessing the application in January 2023.'' As
a result, the Department is compliant and no government desktop
or mobile device may access the TikTok application, as directed
by U.S. Code S. 1143. JFHQ-DODIN leverages Security Information
& Event Management (SIEM) tools to correlate and continually
monitor the effectiveness of the ban across DoD issued devices.
For off-DODIN contractors applying CMMC guidance, DOD CIO is
best postured to provide a formal response, as they maintain
the Department's CMMC website and are involved in the ongoing
rulemaking process that is part of the CMMC 2.0 phase-in
period.
Mr. Wittman. The Cybersecurity and Infrastructure Security
Agency (CISA) published in March the ``Review of the Summer
2023 Microsoft Exchange Online Intrusion'' that assessed the
security failures of Microsoft which led to successful
cyberattacks from Chinese and Russian hackers (ex: Fancy Bear
and Midnight Blizzard). Additional cyber-attacks against
Microsoft have been reported since the major incidents of 2023,
leading CISA to issue an Emergency Directive 24-02. With regard
to the Department's use of Microsoft software, have you
implemented any policies to mitigate exposure, through
Microsoft capabilities, of the Department to TikTok or
ByteDance applications? Furthermore, in the Midnight Blizzard
attack, source code repositories and internal systems were
compromised. Was the compromised code the sane code of
platforms upon which the Department relies? Does the Department
rely on a single vendor for the majority of its Unclassified
and Classified communications? And does DOD practice vendor
diversity and ``Defense in Depth'' for these types of systems
and software? Finally, it is my understanding the Army, and
potentially other services and agencies, employ the full suite
of Microsoft 365 services. Since the entire suite is closely
integrated, to what extent has DOD been able to meet the CISA
Emergency Directive to take immediate, remediating action for
tokens, passwords, API keys, or other authentication
credentials known or suspected to be compromised?
General Haugh. While the Department of Defense (DoD) does
not fall within the purview of the Cybersecurity and
Infrastructure Security Agency's (CISA) authorities, we remain
in close coordination with CISA as it issues guidance to all
federal Agencies under its authority. In concert with the DoD
CIO and the National Manager for National Security Systems (NM-
NSS), JFHQ-DODIN issues specific guidance and direction to the
DoD for significant events such as the Midnight Blizzard
compromise of Microsoft. Based on the information provided by
Microsoft, there was no compromise of source code that would
elevate risk to the department. In response to the events,
JFHQ-DODIN released a Cyber Tasking Order directing hunt,
clearing, and remediation actions based on potentially exposed
DoD credentials immediately following the notification of the
Microsoft Corporate network compromise. JFHQ-DODIN has released
several orders over the last six months in coordination with
DoD CIO to enhance data security measures, visibility, and
detection across the M365 environment. As a result, the orders
align the Department with the directed Zero Trust Framework.
Additionally, the DODIN security concept is built around a
Defense in Depth posture which uses various vendors overlaying
several tiers of security tools/capabilities.