An official website of the United States government
Here's how you know
A .mil website belongs to an official U.S. Department of Defense organization in the United States.
A lock (lock ) or https:// means you’ve safely connected to the .mil website. Share sensitive information only on official, secure websites.

Home : Media : News : News Article View
NEWS | Nov. 29, 2022

DOD Releases Path to Cyber Security Through Zero Trust Architecture

By C. Todd Lopez DOD News

WASHINGTON -- The Defense Department on Tuesday released its Zero Trust Strategy and Roadmap, which spells out how it plans to move beyond traditional network security methods to achieve reduced network attack surfaces, enable risk management and effective data-sharing in partnership environments, and contain and remediate adversary activities over the next five years.

"Zero trust is a framework for moving beyond relying on perimeter-based cybersecurity defense tools alone and basically assuming that breach has occurred within our boundary and responding accordingly," David McKeown, the department's acting chief information officer, said.

McKeown said the department has spent a year now developing the plans to get the department to a zero trust architecture by fiscal year 2027. Included in that effort was development of a Zero Trust Portfolio Management Office, which stood up earlier this year.

"With the publication of this strategy we have articulated the 'how' that can address clear outcomes of how to get to zero trust — and not only accelerated technology adoption, as discussed, but also a culture of zero trust at DOD and an integrated approach at the department and the component levels."

Getting the Defense Department to reach the goals laid out in the Zero Trust Strategy and Roadmap will be an "ambitious undertaking," McKeown said.

Ensuring that work will largely be the responsibility of Randy Resnick, who serves as the director of the Zero Trust Portfolio Management Office.

"With zero trust, we are assuming that a network is already compromised," Resnick said. "And through recurring user authentication and authorization, we will thwart and frustrate an adversary from moving through a network and also quickly identify them and mitigate damage and the vulnerability they may have exploited."

Spotlight: Engineering in the DOD

Resnick explained the difference between a zero trust architecture and security on the network today, which assumes a level of trust for anybody already inside the network.
"If we compare this to our home security, we could say that we traditionally lock our windows and doors and that only those with the key can gain access," he said. "With zero trust, we have identified the items of value within the house and we place guards and locks within each one of those items inside the house. This is the level of security that we need to counter sophisticated cyber adversaries."

The Zero Trust Strategy and Roadmap outlines four high-level and integrated strategic goals that define what the department will do to achieve that level of security. These include:

  • Zero Trust Cultural Adoption — All DOD personnel understand and are aware, trained, and committed to a zero trust mindset and culture to support integration of zero trust.
  • DOD information Systems Secured and Defended — Cybersecurity practices incorporate and operationalize zero trust in new and legacy systems.
  • Technology Acceleration — Technologies deploy at a pace equal to or exceeding industry advancements.
  • Zero Trust Enablement — Department- and component-level processes, policies, and funding are synchronized with zero trust principles and approaches.

Resnick said development of the Zero Trust Strategy and Roadmap was done in collaboration with the National Security Agency, the Defense Information Systems Agency, the Defense Manpower Data Center, U.S. Cyber Command and the military services.

The department and its partners worked together to develop a total of 45 capabilities and more than 100 activities derived from those capabilities, many of which the department and components will be expected to be involved in as part of successfully achieving baseline, or "target level" compliance with zero trust architecture within the five-year timeline, Resnick said.

"Each capability, the 45 capabilities, resides either within what we're calling 'target,' or 'advanced' levels of zero trust," he said. "DOD zero trust target level is deemed to be the required minimum set of zero trust capability outcomes and activities necessary to secure and protect the department's data, applications, assets and services, to manage risks from all cyber threats to the Department of Defense."

Across the department, every agency will be expected to comply with the target level implementation outlined in the Zero Trust Strategy and Roadmap. Only a few might be expected to achieve the more advanced level.

"If you're a national security system, we may require the advanced level for those systems," McKeown said. "But advanced really isn't necessary for literally every system out there. We have an aggressive goal getting to 'targeted' by 2027. And we want to encourage those who have a greater need to secure their data to adopt this advanced level."

Resnick said achieving the target level of zero trust isn't equivalent to a lower standard for network security.

"We defined target as that level of ability where we're actually containing, slowing down or stopping the adversary from exploiting our networks," he said. "Compared to today, where an adversary could do an attack and then go laterally through the network, frequently under the noise floor of detection, with zero trust that's not going to be possible."

By 2027, Resnick said, the department will be better poised to prevent adversaries from attacking the DOD network and minimize damage if it does occur.

"The target level of zero trust is going to be that ability to contain the adversary, prevent their freedom of movement, from not only going laterally but being able to even see the network, to enumerate the network, and to even try to exploit the network," he said.

If later on more is needed, he said, the requirements for meeting the target level of compliance can be adjusted.

"Target will always remain that level to which we're seeing and stopping the adversary," he said. "And for the majority of the DOD, that's really our goal."

CONNECT WITH USINDOPACOM

ENGAGE & CONNECT MORE WITH PACOM

                                                 

IN THE USINDOPACOM NEWS
U.S. Indo-Pacific Command Honors Last USS Arizona Survivor
A memorial poster recognizes the service of the last survivor from battleship USS Arizona (BB-39), Louis Al. (Lou) Conter, during a ceremony on the USS Arizona memorial on April 23, 2024. Retired Lt. Cmdr. Conter first enlisted in 1939, and he served more than 27 years in the U.S. Navy, including as a pilot during the Korean War. Conter passed away April 1 at the age of 102, and he devoted much of his life to preserving the memory of the 2,403 Americans killed and 1,178 wounded during the attack on Pearl Harbor. (U.S. Navy photo by Chief Mass Communication Specialist Shannon M. Smith)
April 24, 2024 - HONOLULU — U.S. Indo-Pacific Command service members and Pearl Harbor National Park Service employees attended the memorial ceremony in honor of the last survivor from USS Arizona, Louis Al. (Lou) Conter, on April 23, 2024...

Statement by Secretary of Defense Lloyd J. Austin III on the House Passage of the National Security Supplemental
Graphic intended for use as a placeholder for Statements and Press Releases without accompanying imagery.
April 23, 2024 - "I welcome the passage of the critical national security supplemental, which will help the Department of Defense support Ukraine and Israel, bolster security in the Indo-Pacific, and stand firm with our Allies and partners...

U.S. Coast Guard partners conduct Multi-Agency Strike Force Operation at the Port of Guam
U.S. Coast Guard Forces Micronesia/Sector Guam personnel spearhead a comprehensive Multi-Agency Strike Force Operation (MASFO), meticulously inspecting 172 containers at the Port of Guam, on April 18, 2024. This operation is part of ongoing efforts to ensure the safety and security of containerized cargo, which is crucial for the island's economy and environmental protection. The MASFO brought together various agencies, including the Guam Customs and Quarantine Agency, Port Authority Police, the U.S. Food and Drug Administration, and other law enforcement and regulatory bodies. (U.S. Coast Guard photo by Josiah Moss)
April 23, 2024 - On April 18, 2024, U.S. Coast Guard Forces Micronesia/Sector Guam spearheaded a comprehensive Multi-Agency Strike Force Operation (MASFO), meticulously inspecting 172 containers at the Port of Guam...

U.S. Indo-Pacific Commander Travels to Japan
Adm. John C. Aquilino, right, commander of U.S. Indo-Pacific Command, inspects the Japan ground self defense force special honor guard with Japanese Chief of Staff, Japan Joint Staff, Gen. Yoshihide Yoshida during a visit to Tokyo, April 22, 2024. The visit included exchanges on regional security and mutual partnership, further developing the strategic partnership with Japan codified in the 1960 U.S.-Japan Treaty of Mutual Cooperation and Security. USINDOPACOM is committed to enhancing stability in the Indo-Pacific region by promoting security cooperation, encouraging peaceful development, responding to contingencies, deterring aggression and, when necessary, fighting to win. (U.S. Navy photo by Mass Communication Specialist 1st Class John D. Bellino)
April 23, 2024 - TOKYO — Adm. John C. Aquilino, commander of U.S. Indo-Pacific Command, visited Japan from April 21-23, 2024. This was Aquilino’s final overseas engagement with partners and Allies as commander of USINDOPACOM. Aquilino will be...

South Korea’s largest air exercise proves ‘Accept Follow-on Forces’ mission
Republic of Korea Air Force F-15K Slam Eagles and FA-50 Golden Eagles parked on the airfield at Kunsan Air Base, ROK, April 12, 2024. ROKAF follow-on forces arrived from across the country to participate in Korea Flying Training 2024. (U.S. Air Force photo by Staff Sgt. Nicholas Ross)
April 22, 2024 - A crucial aspect of any exercise for the 8th Fighter Wing is the reception of forces, and that was no different as the Wolf Pack hosts the largest air exercise in the Republic of Korea...