DoD:加强国防部的安全协议(2025) 2页

VIP文档

ID:74149

阅读量:0

大小:0.62 MB

页数:2页

时间:2025-07-23

金币:1

上传者:PASHU
SECRETARY
OF
DEFENSE
1000
DEFENSE
PENTAGON
WASHINGTON
,
DC
20301-1000
JUL
1 8
2025
MEMORANDUM
FOR
SENIOR PENTAGON LEADERSHIP
COMMANDERS OF THE COMBATANT COMMANDS
DEFENSE AGENCY AND
DOD
FIELD ACTIVITY DIRECTORS
SUBJ: Enhancing Security Protocols for the Depa1tmP.nt
of
Defense
I direct the Department
of
Defense (DoD)
Chieflnformation
Officer (CIO), in
coordination with the Under Secretaries
of
Defense for Acquisition and Sustainment, Intelligence
and Security, and Research and Engineering,
to
take immediate actions to ensure
to
the
maximum extent possible that all information technology capabilities, including cloud services,
developed and procured for
DoD
are reviewed and validated
as
secure against supply chain
attacks by adversaries such as China and Russia.
The DoD will not procure any hardware or software susceptible to adversarial foreign
influence that presents ri
sk
to mission accomp
li
shment and must prevent such adversaries from
introducing malicious capabilities into the products and services that are utilized by the
Department.
To
that end, the Department will
fo
rti
fy
existing programs and processes utilized
within the Defense Industrial Base (DIB)
to
ensure that adversarial foreign influence is
appropriately eliminated
or
mitigated and determine what,
if
any, additional actions may be
required to address these risks. ·Specifically, the DoD CIO will leverage efforts such as the
Cybersecurity Maturity Model Certification, the Software Fast Track Program, the Authority to
Operate process, the Federal Risk and Authorization Management Program, and initiatives such
as the Secure Software Development Framework. Moreover, the Under Secretary
of
Defense for
Intelligence and Security will review and validate personnel security practices and insider threat
programs
of
the DIB and cloud service providers to the maximum extent possible.
I direct the DoD CIO to issue additional implementing guidance within
15
days
of
the
date
of
this memorandum
to
achieve and maintain a secure environment for our warfighters. My
point
of
contact in this matter is David McKeown, david.w.mckeown.civ@mail.mil, 703-695-
8705.
资源描述:

美国国防部部长于2025年7月1日发布备忘录,要求国防部首席信息官与负责采购与保障、情报与安全、研究与工程的国防部副部长协调,立即采取行动,确保国防部开发和采购的所有信息技术能力,包括云服务,都经过审查和验证,以防受中国、俄罗斯等对手的供应链攻击。国防部不会采购易受外国对手影响且危及任务完成的硬件或软件,要防止对手将恶意能力引入其使用的产品和服务。为此将强化国防工业基地现有项目和流程,消除或减轻外国对手影响,并确定是否需采取额外行动应对风险。国防部首席信息官将利用网络安全成熟度模型认证等举措,负责情报与安全的副部长将审查和验证人员安全做法及内部威胁项目。国防部首席信息官需在备忘录发布15天内发布更多实施指导,以保障作战人员的安全环境。

当前文档最多预览五页,下载文档查看全文

此文档下载收益归作者所有

当前文档最多预览五页,下载文档查看全文
温馨提示:
1. 部分包含数学公式或PPT动画的文件,查看预览时可能会显示错乱或异常,文件下载后无此问题,请放心下载。
2. 本文档由用户上传,版权归属用户,天天文库负责整理代发布。如果您对本文档版权有争议请及时联系客服。
3. 下载前请仔细阅读文档内容,确认文档内容符合您的需求后进行下载,若出现内容与标题不符可向本站投诉处理。
4. 下载文档时可能由于网络波动等原因无法下载或下载错误,付费完成后未能成功下载的用户请联系客服处理。
关闭