<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet media="screen" type="text/xsl" href="/wp-content/themes/smg/assets/xslt/rss-xslt.xml"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:media="http://search.yahoo.com/mrss/"
xmlns:news="http://www.pugpig.com/news"
>

<channel>
	<title>Robert Metzger, Author at Federal Times</title>
	<atom:link href="https://www.federaltimes.com/author/robert-metzger/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.federaltimes.com</link>
	<description>Covering the federal workforce, acquisition, IT adoption and management issues for a new era of public service.</description>
	<lastBuildDate>Sat, 08 Aug 2026 04:56:45 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1</generator>

<image>
	<url>https://one.sightlinemg.com/wp-content/uploads/2026/06/favicon-fed.png?w=32</url>
	<title>Robert Metzger, Author at Federal Times</title>
	<link>https://www.federaltimes.com</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">255331619</site><atom:link rel="next" type="application/rss+xml" href="https://www.federaltimes.com/feed/?paged=2" />
	<item>
		<title>Why supply chain threats require a whole-of-government response</title>
		<link>https://www.federaltimes.com/opinions/2018/09/07/why-supply-chain-threats-require-a-whole-of-government-response/</link>
					<comments>https://www.federaltimes.com/opinions/2018/09/07/why-supply-chain-threats-require-a-whole-of-government-response/#respond</comments>
		
		<dc:creator><![CDATA[Robert Metzger]]></dc:creator>
		<pubDate>Fri, 07 Sep 2018 20:17:10 +0000</pubDate>
				<category><![CDATA[Daily Brief]]></category>
		<category><![CDATA[Home]]></category>
		<category><![CDATA[Newsletters]]></category>
		<category><![CDATA[Opinion]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2018/09/07/why-supply-chain-threats-require-a-whole-of-government-response/</guid>

					<description><![CDATA[As supply chain threats evolve across sectors, a cohesive and collaborative defense is needed.]]></description>
		
					<wfw:commentRss>https://www.federaltimes.com/opinions/2018/09/07/why-supply-chain-threats-require-a-whole-of-government-response/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">21155</post-id><media:thumbnail url="https://one.sightlinemg.com/wp-content/uploads/2026/08/AP17179497344211.jpg.jpg" width="3647" height="2304" type="image/jpeg" />
<media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/AP17179497344211.jpg.jpg" width="3647" height="2304" type="image/jpeg" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">This is the final part in a multipart series on supply chain security. Click here for <a href="https://www.federaltimes.com/opinions/2018/08/13/federal-supply-chain-threats-quietly-growing/">part one</a>, <a href="https://www.federaltimes.com/opinions/2018/08/16/when-fisma-isnt-enough/">part two</a>, <a href="https://www.federaltimes.com/opinions/2018/08/24/voluntary-doesnt-secure-the-supply-chain/">part three</a> and <a href="https://www.federaltimes.com/opinions/2018/08/31/why-supply-chain-threats-call-for-urgent-cooperative-action/" target=_blank>part four</a>.</p>



<p class="wp-block-paragraph">Supply chain security is a problem that crosses traditional boundaries. One sector can be exposed to or impacted by an attack upon another, or even be used as a vehicle. Lines between cyber effects and physical results are blurred by the nature of cyber-physical attacks that use software to deny, damage or destroy physical assets. </p>



<p class="wp-block-paragraph">Hostile nations can conduct asymmetric warfare by use of supply chain-directed attacks as surrogates or alternates for conventional military power. In this context, defense of the homeland requires actions coordinated among the civilian agencies, the Department of Defense and the intelligence community.</p>



<p class="wp-block-paragraph">Cross-agency action on threat information is needed. Adversaries’ tactics, techniques and procedures in supply chain attacks are known or knowable to the IC and other specialized assets of the U.S. government. Methods to deter or respond to such attacks may reside in the DoD and its components. The National Protection and Programs Directorate (NPPD) of DHS has many responsibilities and resources for protection of domestic infrastructure and industry. </p>



<p class="wp-block-paragraph">Understanding how an adversary may attack, its methods, and where attacks have been attempted (globally) is key to informing deflection of threats, detection of events, protection and recovery. An effective national response to supply chain threats utilizes all-source intelligence and coordinated collection and analysis. Both DHS and DoD now are moving in this direction.</p>



<p class="wp-block-paragraph"><b>Reforming, empowering, evaluating</b></p>



<p class="wp-block-paragraph">There is widespread enthusiasm for measures that will “reform” federal procurement to reduce barriers to commercial sources, encourage innovation, speed purchase and delivery, and eliminate the regulatory cost premium. </p>



<p class="wp-block-paragraph">In the 2016 National Defense Authorization Act, Congress authorized an independent advisory panel on streamlining and codifying acquisition regulations (the “section 809 panel”). Improved security was not in the charter of the section 809 panel, but there is potential tension between security objectives. That can add time, expense and federal-specific demands to acquisitions, and the objectives of section 809 and similar reform efforts. </p>



<p class="wp-block-paragraph">The solution may be to establish risk-informed categories for DoD procurement such that greater security obligations are imposed upon the “higher” tiers but minimized for commodity, commercial-off-the-shelf and other low-risk items.</p>



<p class="wp-block-paragraph">Congress allows DoD to exclude “high risk” supply chain sources, and now DoD is working to better utilize that authority. The Kaspersky Labs example is one where national interest led to the exclusion of a suspect source. </p>



<p class="wp-block-paragraph">Reportedly, DoD is now working on a software “do not buy” list. Congress is looking at extending this authority to other departments and agencies, and at other measures to prevent contracting with the enemy on a whole-of-government basis. </p>



<p class="wp-block-paragraph">Such initiatives will have significant effect upon thousands of private-sector enterprises. Agencies need to improve coordination to produce consistent goals, uniform measures and fair process. NIST can play an especially important role here, given the widespread private sector use of the cybersecurity framework.</p>



<p class="wp-block-paragraph"><b>Agencies should wield the power</b></p>



<p class="wp-block-paragraph">As the threat environment worsens, regulatory agencies should be ready to use their authority on a coordinated basis to improve supply chain defenses, promote resiliency and enable recovery. While regulatory agencies have limited purchasing leverage, they have sweeping authority over enterprises subject to their oversight. </p>



<p class="wp-block-paragraph">In some cases, regulatory agencies can condition market access upon or otherwise mandate security measures. They have authority over market entry, licensing, approvals, qualification, eligibility and more. They should use that authority to inform, instruct, enable, and assess self-improvement. But they should hold in reserve the authority to require improved security.</p>



<p class="wp-block-paragraph">International measures require multi-agency coordination. There are distinct U.S. interests in protecting supply chain security for our Government, and for our national economy. But supply chain security also affects our allies and other trading partners; truly, it is an international problem. </p>



<p class="wp-block-paragraph">Ultimately, the U.S. cannot “go it alone” or separate itself from a global supply chain. </p>



<p class="wp-block-paragraph">For this among many other reasons, solutions to supply chain risks will involve international cooperation. Important measures may be achieved through international agreement, and international organizations will play a critical role in setting standards and best practices. It may be advantageous to U.S. interests to promote a council of allied countries to exchange information about supply chain vulnerabilities and responses. </p>



<p class="wp-block-paragraph">Past doctrines, historical methods and legacy techniques have limited value today. Conventional thinking needs to change to confront the contemporary threat environment. New actions are necessary to challenge orthodoxy and adroitly secure the supply chain.</p>
]]></content:encoded>
	</item>
		<item>
		<title>Why supply-chain threats call for urgent, cooperative action</title>
		<link>https://www.federaltimes.com/opinions/2018/08/31/why-supply-chain-threats-call-for-urgent-cooperative-action/</link>
					<comments>https://www.federaltimes.com/opinions/2018/08/31/why-supply-chain-threats-call-for-urgent-cooperative-action/#respond</comments>
		
		<dc:creator><![CDATA[Robert Metzger]]></dc:creator>
		<pubDate>Fri, 31 Aug 2018 16:46:09 +0000</pubDate>
				<category><![CDATA[Daily Brief]]></category>
		<category><![CDATA[Home]]></category>
		<category><![CDATA[IT & Cloud Report]]></category>
		<category><![CDATA[Newsletters]]></category>
		<category><![CDATA[Opinion]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2018/08/31/why-supply-chain-threats-call-for-urgent-cooperative-action/</guid>

					<description><![CDATA[Supply-chain threats don't target only government or only industry. Confronting those threats requires a partnership — and soon.]]></description>
		
					<wfw:commentRss>https://www.federaltimes.com/opinions/2018/08/31/why-supply-chain-threats-call-for-urgent-cooperative-action/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">20743</post-id><media:thumbnail url="https://one.sightlinemg.com/wp-content/uploads/2026/08/CoverFeature_1.jpg_73e279.jpg" width="4928" height="3280" type="image/jpeg" />
<media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/CoverFeature_1.jpg_73e279.jpg" width="4928" height="3280" type="image/jpeg" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph"><i>This is part four in a multipart series on supply chain security. Click here for </i><a href="https://www.federaltimes.com/opinions/2018/08/13/federal-supply-chain-threats-quietly-growing/"><i>part one</i></a><i>, </i><a href="https://www.federaltimes.com/opinions/2018/08/16/when-fisma-isnt-enough/"><i>part two</i></a><i> and </i><a href="https://www.federaltimes.com/opinions/2018/08/24/voluntary-doesnt-secure-the-supply-chain/"><i>part three</i></a><i>.</i></p>



<p class="wp-block-paragraph">The potential consequences of supply chain attack are severe. Recent attention has focused on hacks resulting in exposure of private information — Sony in 2014, the Office of Personnel Management in 2015 or Equifax in 2017. The loss of confidentiality of millions of personal records, and the resultant impacts upon individual privacy, are matters of great national concern.</p>



<p class="wp-block-paragraph">A successful cyber-physical attack upon national infrastructure could have even worse consequences. Such attacks already have been attempted (and publicly reported) by Russia as well as Iran. Should such attacks succeed, they will produce widespread physical effects — destruction of equipment or facilities, and crippling or loss of key public assets — affecting the functioning of government, the strength of our economy, and the daily lives of millions of U.S. citizens.</p>



<p class="wp-block-paragraph">The national interest is to defend against and recover from supply chain attacks. A supply chain-directed attack need not be confined to one server, one information system, one agency or enterprise, or one type of private record. Adversaries may mount simultaneous or sequential attacks on diverse industry and government sectors, related or not, with objectives that may include confusion, public frustration and leadership doubt.</p>



<p class="wp-block-paragraph">Defense against such attacks and remediation requires stronger action than contract requirements and voluntary measures. Sectoral initiatives can be helpful, but they may not scale to cover the threat’s complexity or severity. Nor do they address cross- or multi-sectoral impacts.</p>



<p class="wp-block-paragraph">The time to improve defenses, plan for attack, and prepare to recover is now. Waiting to act until after the event(s) is a recipe that adversaries can exploit now to their advantage. The situation today is what was predicted — and feared — just a few years ago. Restraint on the part of adversaries is unlikely, and certainly cannot be assumed. Deterrence has a role, but its operation is complicated by the “gray” nature of asymmetric conflict in cyber domains and the continuing difficulty of attribution to attackers.</p>



<p class="wp-block-paragraph"><b>Resolving tensions between government and industry</b></p>



<p class="wp-block-paragraph">Congress has been reluctant to impose security upon the commercial sector by law or regulation. Industry has concerns about the costs and burdens of federal intervention and prefers to be free to use its superior abilities, agility and technology to deal on its own with supply chain and cyber threats.</p>



<p class="wp-block-paragraph">Government and industry must work together to defend against and defeat these threats. But the stakes are too high, and the risks too great, for government to defer to industry and hope that market forces alone will produce sufficient results.</p>



<p class="wp-block-paragraph">At the very least, Congress should require measures now that anticipate attack and enable prompt, effective response in the event of emergency. Threats are not directed at the government distinctly from industry. Government and industry share interests in finding common grounds and shared methods for cooperative, mutual defense.</p>



<p class="wp-block-paragraph">o There is no reason other than optimism uninformed by experience to trust that only voluntary measures in the private sector will provide the needed protection to critical infrastructure. Even if some companies do it “right,” or even “better” or “best,” adversaries will attack the weaker links – and there are many enterprises indifferent to security.</p>



<p class="wp-block-paragraph">o Leaders in industry will assert that they can do it better, smarter, with more agility, and with better results. That may well be true — but only for the leaders. Even then, the security of the enterprise at the end point of the supply chain does not mean that assurance extends to connected systems or to all participants in regulated industry. Incentives are needed to promote best practices in supply chain security in the private sector.</p>



<p class="wp-block-paragraph">o As industry and government share exposure and will suffer similar or the same consequences of supply chain attacks, it is critical to promote means for partnership so that the private and public sectors cooperate in mutual defense and remediation when attacks occur.</p>



<p class="wp-block-paragraph"><i>Robert Metzger is a shareholder of the law firm of Rogers, Joseph O’Donnell, PC and head of the firm’s office in Washington, D.C. As a special government employee of the Department of Defense, he was a member of the Defense Science Board (DSB) Task Force that produced the Cyber Supply Chain Report in 2017. He is active in other public-private initiatives, including cyber and supply chain security work for the MITRE Corporation.</i></p>
]]></content:encoded>
	</item>
		<item>
		<title>‘Voluntary’ doesn’t secure the supply chain</title>
		<link>https://www.federaltimes.com/opinions/2018/08/24/voluntary-doesnt-secure-the-supply-chain/</link>
					<comments>https://www.federaltimes.com/opinions/2018/08/24/voluntary-doesnt-secure-the-supply-chain/#respond</comments>
		
		<dc:creator><![CDATA[Robert Metzger]]></dc:creator>
		<pubDate>Fri, 24 Aug 2018 19:37:56 +0000</pubDate>
				<category><![CDATA[Daily Brief]]></category>
		<category><![CDATA[Home]]></category>
		<category><![CDATA[Newsletters]]></category>
		<category><![CDATA[Opinion]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2018/08/24/voluntary-doesnt-secure-the-supply-chain/</guid>

					<description><![CDATA[Government contracting poses inherent supply chain threats. One agency can make a difference, but it's not who you think.]]></description>
		
					<wfw:commentRss>https://www.federaltimes.com/opinions/2018/08/24/voluntary-doesnt-secure-the-supply-chain/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">20993</post-id><media:thumbnail url="https://one.sightlinemg.com/wp-content/uploads/2026/08/635924283160512126-computer-hardwarejpg.jpg" width="4753" height="3169" type="image/jpeg" />
<media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/635924283160512126-computer-hardwarejpg.jpg" width="4753" height="3169" type="image/jpeg" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph"><i>This is part three in a multipart series on supply chain security. Click here for </i><a href="https://www.federaltimes.com/opinions/2018/08/13/federal-supply-chain-threats-quietly-growing/"><i>part one</i></a><i> and </i><a href="https://www.federaltimes.com/opinions/2018/08/16/when-fisma-isnt-enough/"><i>part two</i></a><i>.</i></p>



<p class="wp-block-paragraph">The federal government encourages many forms of voluntary security measures. The National Institute of Standards and Technology has produced a voluntary cybersecurity framework that is a useful way to organize, achieve and measure security progress. But voluntary measures are insufficient when not everyone is adopting the measures.</p>



<p class="wp-block-paragraph">Adversaries can and will exploit resulting gaps and wreak widespread injury through supply chain attacks directed against weak links, such as market participants indifferent to security. This exposure, unfortunately, also is present in the Department of Defense’s efforts to improve the cybersecurity of defense industrial base contractors. There, NIST Special Publication 800-171 safeguards are specified — but there is no method of assurance or assessment beyond “trust” in contractors to comply with contract terms. </p>



<p class="wp-block-paragraph">An unfortunate truth about supply chain vulnerability — and especially software supply chain exposure — is the enormous attack surface and the virtually limitless number of points where an attack can be executed. Adversaries can avoid the best defended resources and most secure products (or components) and instead find weak actors and exploit insecure entry points. </p>



<p class="wp-block-paragraph"><b>Procurement measures are significant. but not sufficient</b> </p>



<p class="wp-block-paragraph">DoD has been the leader in efforts to defend against supply chain exposure. Even so, experience shows that procurement methods may not achieve effective supply chain security across the entire range of exposure. </p>



<p class="wp-block-paragraph">By definition, procurement measures, such as federal acquisition regulations or contract clauses, affect only those in the chain-of-contract with the federal agency customer. While the universe of companies affected by DoD procurement measures is significant, it nonetheless represents a very small fraction of U.S. enterprises at risk. </p>



<p class="wp-block-paragraph">Even where procurement methods matter, such as in DoD procurements and those of other federal agencies, today’s emphasis is on price, schedule and performance. Security requirements may be tacked on to new solicitations for supplies and services, but federal purchasers, at present, evaluate the cyber and supply chain security of contractors only in limited instances. </p>



<p class="wp-block-paragraph">Federal leaders should elevate security to the point that it becomes the “fourth pillar” of the acquisition process – equal in priority to cost, schedule and performance. </p>



<p class="wp-block-paragraph"><b>Software supply chain attacks: discrete targets, broad effects</b>. </p>



<p class="wp-block-paragraph">Conventional thinking has been that adversaries seek high “return on investment” by targeting supply chain attacks in ways that achieve precise, impactful effects. The publicly reported experience with Kaspersky Labs software, however, suggests an alternative paradigm that is very dangerous: infiltration through widely installed, publicly accessible software. </p>



<p class="wp-block-paragraph">Measures confined to government contractors, or which are voluntary for commercial enterprises, do little to mitigate and certainly do not defeat such threats. Commercial sources of supplies or services for government use can be unwittingly exposed to tainted, commercial-origin, widely marketed software and, conceivably, firmware in widely utilized devices.</p>



<p class="wp-block-paragraph">No part of the “system development life cycle” is unexposed to software-delivered supply chain attack. Contemporary systems typically depend upon a global supply chain for parts and for software, including open-source components from sources both known and unknown. There is exposure at all points along the life cycle spectrum, from inception to end-of-life disposition. </p>



<p class="wp-block-paragraph">Even industrial base issues come into play here, as the U.S. becomes increasingly dependent upon foreign sources for critical, high-performance microelectronics. </p>



<p class="wp-block-paragraph"><b>IoT: Internet of Threats</b> </p>



<p class="wp-block-paragraph">The Internet of Things is producing massive interconnection of sensors, devices and systems – and massive interdependencies among systems. Literally billions of connected devices are in our near-term future. With this connectivity, paths for attack, malware propagation and distribution grow exponentially. Detection and response to such attacks implicates many federal agencies, notably the FCC.</p>



<p class="wp-block-paragraph">The FCC has a pivotal role in security of our increasingly interconnected national economy. It is the “gatekeeper” for the communications instrumentalities upon which connected systems rely in private sector and for much of the public sector. </p>



<p class="wp-block-paragraph">Apart from authority to hold regulated communications service providers to higher security standards, the FCC can play an important role in shaping future network architecture so that transport layer attacks are rapidly identified and isolated — helping to mitigate the risk of “cascading” impacts across connected systems. The FCC will also have a key role in protecting U.S. interests in the development of the 5G mobile networks standard, where other nation-states may seek outcomes adverse to the U.S.</p>



<p class="wp-block-paragraph"><i>Robert Metzger is a shareholder of the law firm of Rogers, Joseph O’Donnell, PC and head of the firm’s office in Washington, D.C. As a special government employee of the Department of Defense, he was a member of the Defense Science Board (DSB) Task Force that produced the Cyber Supply Chain Report in 2017. He is active in other public-private initiatives, including cyber and supply chain security work for the MITRE Corporation.</i></p>
]]></content:encoded>
	</item>
		<item>
		<title>When FISMA isn’t enough</title>
		<link>https://www.federaltimes.com/opinions/2018/08/16/when-fisma-isnt-enough/</link>
					<comments>https://www.federaltimes.com/opinions/2018/08/16/when-fisma-isnt-enough/#respond</comments>
		
		<dc:creator><![CDATA[Robert Metzger]]></dc:creator>
		<pubDate>Thu, 16 Aug 2018 01:31:46 +0000</pubDate>
				<category><![CDATA[Daily Brief]]></category>
		<category><![CDATA[Home]]></category>
		<category><![CDATA[IT & Cloud Report]]></category>
		<category><![CDATA[Newsletters]]></category>
		<category><![CDATA[Opinion]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2018/08/16/when-fisma-isnt-enough/</guid>

					<description><![CDATA[Federal agencies, especially civilian organizations, aren't going far enough to secure against cyber-physical threats to the supply chain.]]></description>
		
					<wfw:commentRss>https://www.federaltimes.com/opinions/2018/08/16/when-fisma-isnt-enough/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">20967</post-id><news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph"><i>This is part two in a multipart commentary on supply chain security. For part one, </i><a href="https://www.federaltimes.com/opinions/2018/08/13/federal-supply-chain-threats-quietly-growing/" target=_blank><i>click here</i></a><i>.</i></p>



<p class="wp-block-paragraph">Federal departments and agencies are obligated by the Federal Information Security Modernization Act to protect the confidentiality, integrity and availability of defined categories of federal information (“controlled unclassified information,” or CUI) and information systems that host, process or transmit that information. But it’s often not enough to secure the federal supply chain against software threats and cyber-physical dangers.</p>



<p class="wp-block-paragraph">FISMA is directed to protect against network and information system attacks that can compromise federal CUI. Present federal efforts give comparatively little attention to cyber-physical threats, such as corruption of firmware or other types of software that produce unwanted and adverse effects on connected equipment. Measures intended to protect IT, even where successful, may do little to secure operational technology.</p>



<p class="wp-block-paragraph">Spurred by Congress, DoD requires its larger contractors to implement systems and procedures to detect and avoid counterfeit electronic parts. On its own initiative, DoD has implemented DFARS procurement regulations and contract requirements to make all DoD suppliers safeguard controlled technical information of military or space significance and other CUI types, using NIST security principles.</p>



<p class="wp-block-paragraph">DoD’s acts concern the risk that the supply chain might deliver counterfeit parts and the cyber threat to the confidentiality of information and information systems that host CTI and other forms of CUI. To protect contractor information systems against network-delivered attacks, DoD requires contractors to employ the 110 safeguards of NIST Special Publication 800-171.</p>



<p class="wp-block-paragraph">The present challenge is to identify, detect, defend against, respond to or recover from software-delivered cyber-physical attacks on operational technology – for example, industrial control systems, supervisory control and data acquisition, programmable logic controllers and other systems that operate manufacturing facilities and infrastructure. SP 800-171 is not intended to protect these systems.</p>



<p class="wp-block-paragraph">Civilian departments have done less than DoD against supply chain threats. For years, civilian agencies have considered a counterpart to the DoD “cyber DFARS” to require protection of CUI when shared with non-federal entities. There currently is no such regulation or requirement, but an inter-agency effort is proceeding that may produce a regulation, like the “cyber DFARS,” requiring use of NIST SP 800-171 safeguards by non-federal entities to protect all CUI they receive it from a federal agency.</p>



<p class="wp-block-paragraph">DoD presently has special authorities, to avoid counterfeit electronics and exclude high risk sources, not available to all federal departments and agencies. Generally, civilian agencies take no regular and direct measures, beyond ordinary quality and conformance requirements, to require suppliers or service providers to secure their supply chains or to report and remedy supply-chain attacks. But adversaries will not limit hostile activities to the defense sector.</p>



<p class="wp-block-paragraph">The president’s executive order from May 11, 2017, holds heads of executive departments accountable for managing cybersecurity risk to their enterprises and calls on the executive branch to support the cybersecurity efforts of the owners and operators of critical infrastructure. It further requires a report on the cybersecurity risks facing the defense industrial base, including its supply chain. These are commendable in intent, but more policies, efforts and reports do not produce objective improvements in security, nor do they necessarily change the security practices of commercial enterprises.</p>



<p class="wp-block-paragraph">It’s critical to recognize threats to private industry affect government interests. Federal action on cyber and supply chain threats focus upon federal information systems and contractors for supplies, systems or services. Attacks upon utilities or transportation facilities, or other aspects of critical infrastructure can produce discomfort, inconvenience, economic loss, property damage or even personal injury or death. Attacks upon civil logistics providers, even where facilities are located in the continental United States, can inflict damage on defense business and erode the ability of commanders to deploy forces and execute missions on foreign soil.</p>



<p class="wp-block-paragraph"><i>Robert Metzger is a shareholder of the law firm of Rogers, Joseph O’Donnell, PC and head of the firm’s office in Washington, D.C. As a special government employee of the Department of Defense, he was a member of the Defense Science Board (DSB) Task Force that produced the Cyber Supply Chain Report in 2017. He is active in other public-private initiatives, including cyber and supply chain security work for the MITRE Corporation.</i></p>
]]></content:encoded>
	</item>
		<item>
		<title>Federal supply-chain threats quietly growing</title>
		<link>https://www.federaltimes.com/opinions/2018/08/13/federal-supply-chain-threats-quietly-growing/</link>
					<comments>https://www.federaltimes.com/opinions/2018/08/13/federal-supply-chain-threats-quietly-growing/#respond</comments>
		
		<dc:creator><![CDATA[Robert Metzger]]></dc:creator>
		<pubDate>Mon, 13 Aug 2018 19:51:24 +0000</pubDate>
				<category><![CDATA[Daily Brief]]></category>
		<category><![CDATA[Home]]></category>
		<category><![CDATA[Newsletters]]></category>
		<category><![CDATA[Opinion]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2018/08/13/federal-supply-chain-threats-quietly-growing/</guid>

					<description><![CDATA[There's a lot of emphasis on cyber threats, but the government is increasingly vulnerable to gaps in supply-chain security.]]></description>
		
					<wfw:commentRss>https://www.federaltimes.com/opinions/2018/08/13/federal-supply-chain-threats-quietly-growing/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">10545</post-id><media:thumbnail url="https://one.sightlinemg.com/wp-content/uploads/2026/08/supply-chain.jpg.jpg" width="1199" height="740" type="image/jpeg" />
<media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/supply-chain.jpg.jpg" width="1199" height="740" type="image/jpeg" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph"><i>This is the first piece in a multi-part commentary series.</i></p>



<p class="wp-block-paragraph">Nation-state adversaries have exploited supply chain vulnerabilities for various hostile purposes, including theft of IP and technical data, attacks upon control systems used for electrical utilities, and manipulation of software to achieve unauthorized access to connected systems. Not enough is done to protect against the range of supply chain threats. This presents grave exposure to federal interests.</p>



<p class="wp-block-paragraph">A 2013 Defense Science Board report, “Resilient Military Systems and the Advanced Cyber Threat,” observed that the “challenge to supply chain management in a cyber-contested environment is significant.” Since that report, the challenge has only grown, and with increased dependency on “smart” devices, vulnerabilities and potential consequences have magnified. In February 2017, the DSB released a Cyber Supply Chain Task Force report, which focused on security of weapons systems against forms of supply chain attacks. This DSB report found that attack surfaces are found in the global commercial supply chain, the DoD acquisition supply chain, and the sustainment supply chain, and concluded that present capabilities to mitigate supply chain risk are limited.</p>



<p class="wp-block-paragraph">Today’s picture is changed because what were forecast as possibilities now are reality. Adversaries seek ways to avoid areas of U.S. dominance and to challenge U.S. interests in cyber-enabled domains upon which our government, industry and populace rely. In contested cyberspace, traditional boundaries are blurred. Threats to the whole of government affect the whole of American society.</p>



<p class="wp-block-paragraph"><b>The Changing Nature of Supply Chain Threats</b></p>



<p class="wp-block-paragraph">Just a few years ago, Congress enacted Section 818 of the 2012 National Defense Authorization Act to protect DoD against counterfeit electronic parts. The principal concern was the purchase and use of electronic parts that were non-authentic and would fail when installed or used in the intended environment. Supply chain threats are now understood as broader than the example of counterfeit electronics. As shown by the well-publicized experience with Kaspersky Labs anti-virus software, the “software supply chain” is at risk, raising the possibility of millions of infected computers and networks.</p>



<p class="wp-block-paragraph">Software increasingly defines the boundaries, operation, and security of systems relied upon by all facets of civil society – consumer-facing, industrial, transportation, energy, healthcare, communications – as well as defense missions and management. The functionality of electronic systems increasingly is achieved through software. A modern airliner may have more than 10 million lines of code. A premium automobile may have 100 million lines of code operating 50 or more computerized engine control units. Electronic systems are increasingly command-driven through connections to remote sensors and cloud-based applications.</p>



<p class="wp-block-paragraph">The co-dependency of so many varieties of software-dependent systems is accompanied by enlarged exposure to harm should adversaries choose to make supply chain or cyber-physical attacks. As software has become more complex, many developers rely upon open sources for part of the code. In some cases, these sources are not trustworthy or no established means exist to establish trust. Should open-source code be the target of malicious software insertion, great damage can be done to connected systems – and to the people and enterprises who depend upon them.</p>



<p class="wp-block-paragraph">The federal government, pursuant to the Federal Information Systems Modernization Act (FISMA), has focused upon cyber threats to information and information systems. Supply chain risks extend further, to include attacks where non-conforming or counterfeit parts infiltrate the supply chain, as well as cyber-physical threats, by which adversaries introduce malware or exploit latent vulnerabilities in firmware or software to produce physical effects on connected or controlled systems.</p>



<p class="wp-block-paragraph">These supply chain threats reach beyond public sector boundaries to include core industrial capabilities and every infrastructure component. Such threats are real and present – as evidenced by recent headlines.</p>



<p class="wp-block-paragraph">The <i>New York Times</i> reported on March 15, 2018, that the Trump Administration accused Russia of cyberattacks that targeted and could have shut off nuclear power plants and water and electric systems. Another <i>Times</i> story, also dated March 15, 2018, described a “new kind of cyberassault’” on petrochemical facilities in Saudi Arabia. The story described the attack as “not designed to simply destroy data or shut down the plant.” Instead, the attack was “meant to sabotage the firm’s operations and trigger an explosion.”</p>



<p class="wp-block-paragraph"><i>Robert Metzger is a shareholder of the law firm of Rogers, Joseph O’Donnell, PC and head of the firm’s office in Washington, D.C. As a special government employee of the Department of Defense, he was a member of the Defense Science Board (DSB) Task Force that produced the Cyber Supply Chain Report in 2017. He is active in other public-private initiatives, including cyber and supply chain security work for the MITRE Corporation.</i></p>
]]></content:encoded>
	</item>
		<item>
		<title>A federal response to cyber/physical threats</title>
		<link>https://www.federaltimes.com/opinions/2016/08/19/a-federal-response-to-cyber-physical-threats/</link>
					<comments>https://www.federaltimes.com/opinions/2016/08/19/a-federal-response-to-cyber-physical-threats/#respond</comments>
		
		<dc:creator><![CDATA[Robert Metzger]]></dc:creator>
		<pubDate>Fri, 19 Aug 2016 18:37:26 +0000</pubDate>
				<category><![CDATA[Inside the Agencies]]></category>
		<category><![CDATA[Opinion]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2016/08/19/a-federal-response-to-cyber-physical-threats/</guid>

					<description><![CDATA[Security professionals must address the functionality and safety of crucial systems.]]></description>
		
					<wfw:commentRss>https://www.federaltimes.com/opinions/2016/08/19/a-federal-response-to-cyber-physical-threats/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">12008</post-id><media:thumbnail url="https://one.sightlinemg.com/wp-content/uploads/2026/08/635854350849568071-metzgerjpg.jpg.jpg" width="3603" height="2027" type="image/jpeg" />
<media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/635854350849568071-metzgerjpg.jpg.jpg" width="3603" height="2027" type="image/jpeg" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">Supply chain threats to cyber/physical systems are the next great challenge. Adversaries can use cyber tools to manipulate physical functions of connected devices and systems. Hostile actors can include nation-states, terror groups or commercial rivals. In a crisis, a nation-state may seek to disable facilities on which U.S. national logistics capabilities depend. Terrorists could attack the infrastructure of our public utilities. An unscrupulous competitor could disrupt the factory of an American manufacturer.   <br/></p>



<p class="wp-block-paragraph">Such attacks may exploit vulnerabilities in networks and be directed through information systems. There are different threat vectors, however. Cyber/physical attacks are made through malicious code that subverts the command logic of cyber-active devices. Firmware may harbor corrupt elements. Hardware can be compromised in fabrication. Malicious code insertion can occur at any phase of product life cycle. Risks are present at many junctures of the supply chain. Even after microelectronic devices are shipped from their manufacturer, software updates, as routinely occur during sustainment, are a potential attack channel.</p>



<p class="wp-block-paragraph">These risks, however, are not the cyber threats that now dominate the attention of federal government agencies.</p>



<p class="wp-block-paragraph">The dominant consequence of cyber/physical attacks is not compromise to the confidentiality, integrity or availability of federal information or federal information systems. Rather, the impact is to the functionality of physical systems and to safety of equipment operations. The results differ from the injury of a breach of network security that results in extraction of sensitive information. Cyber/physical attacks may be directed to Supervisorial Control and Data Acquisition (SCADA) systems, industrial control systems (ICS) and factory automation systems. Critical infrastructure or defense manufacturing, for example, may be disabled immediately, require costly repairs, and take a very long time to remediate.</p>



<p class="wp-block-paragraph">The cornerstone of federal cybersecurity efforts is FISMA – the Federal Information Systems Management (now Modernization) Act. FISMA requires agencies to provide information security &#8220;commensurate with the risk and the magnitude of the harm resulting from the unauthorized access, use, disclosure, disruption, modification or destruction of (i) information collected by or on behalf of an agency; or (ii) information systems used or operated by an agency or by a contractor of an agency or other organization on behalf of an agency.&#8221;</p>



<p class="wp-block-paragraph">FISMA&#8217;s purpose is to protect agency information and information systems. NIST has developed an elaborate security regime to fulfill FISMA&#8217;s requirements, e.g., FIPS 199, FIPS 200, and Special Publication 800-53. These articulate process, procedures, controls and enhancements – to protect federal information, and federal information systems. FISMA and its &#8220;progeny&#8221; are not directed to cyber/physical threats or to the impacts to functionality and safety that could degrade or deny the ability of federal agencies and their contractors to perform missions and deliver supplies and services.</p>



<p class="wp-block-paragraph">The security emphasis of much of the federal government, where driven by FISMA, has been to protect information and information systems. Cyber/physical threats change the paradigm. With the internet of things (IoT), both the scale and urgency of the problem increase. The IoT implies massive interconnectivity and constant interdependence among devices, communications and control, proliferation of sensors in quantity and functions, cognitive machine processing without human intervention, and relocation of much command functionality to the periphery. The IoT expands the vulnerable surfaces for cyber/physical attacks and could multiply the consequences of attacks.</p>





<p class="wp-block-paragraph">Security professionals must address the functionality and safety of physical systems crucial to the economy, to homeland security and to national defense. New measures are needed, across multiple domains. The federal government needs to find the right balance between restraint and intervention. The IoT offers enormous commercial opportunity and benefits to consumers, to industry and to governments at all levels. These positive attributes weigh in favor of regulatory restraint. Further, there is wide variation in the deployments and purposes of cyber/physical systems, indicating that the federal response should be discriminating, sector-specific and risk-driven. Federal policy should motivate and leverage private sector initiatives and encourage use of industry-developed standards and best practices.</p>



<p class="wp-block-paragraph">Yet, the national interest requires protection of certain infrastructure, critical facilities, vulnerable control systems and key factories against emerging cyber/physical threats. Trust in the good intentions or sufficient accomplishments of industry will not be enough. Some in the supply chain will act of their own accord to address cyber/physical risks and respond effectively. Some will promise but not take effective actions. Many will act only if required.  For critical systems, even a few &#8220;gaps&#8221; could be disastrous.  <br/> <br/></p>





<p class="wp-block-paragraph">The federal government is using its acquisition authority to require contractors to protect sensitive federal information used in the performance of government contracts. DoD is leading this effort, with the &#8220;Network Penetration&#8221; DFARS that requires &#8220;adequate security&#8221; to protect four categories of &#8220;Covered Defense Information.&#8221; Policy makers should consider similar initiatives to address the distinct domain of cyber/physical risks. NIST is working to expand the tool set it provides to help agencies and companies assess and respond these risks. <br/> <br/>It is timely for DoD, DHS and other federal agencies to further develop policies and practices that contractors can adopt to reduce vulnerability to these threats, enhance detection and response to exploits, and mitigate consequence. Elaborate exercises in documentation should be avoided, in favor of policies that emphasize active and continuing response to the dynamic threat universe. Each agency of the federal government may benefit from risk assessment of the infrastructure and industrial capabilities essential to fulfillment of their priority missions. For such critical systems, it could prove appropriate, even necessary, to require contractors to assess for cyber/physical risks and to document system security plans. <br/> <br/> <em>Robert Metzger is a shareholder at law firm Rogers Joseph O&#8217;Donnell PC, where he&#8217;s a member of the Government Contracts Practice Group and head of the Washington, D.C., office.</em> <br/></p>
]]></content:encoded>
	</item>
		<item>
		<title>At long last: The final rule on safeguarding of contractor information systems</title>
		<link>https://www.federaltimes.com/opinions/2016/06/13/at-long-last-the-final-rule-on-safeguarding-of-contractor-information-systems/</link>
					<comments>https://www.federaltimes.com/opinions/2016/06/13/at-long-last-the-final-rule-on-safeguarding-of-contractor-information-systems/#respond</comments>
		
		<dc:creator><![CDATA[Robert Metzger]]></dc:creator>
		<pubDate>Mon, 13 Jun 2016 15:55:00 +0000</pubDate>
				<category><![CDATA[Inside the Agencies]]></category>
		<category><![CDATA[Opinion]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2016/06/13/at-long-last-the-final-rule-on-safeguarding-of-contractor-information-systems/</guid>

					<description><![CDATA[Using this new FAR provision, every federal agency now will require minimum cyber protection for federal contract information.]]></description>
		
					<wfw:commentRss>https://www.federaltimes.com/opinions/2016/06/13/at-long-last-the-final-rule-on-safeguarding-of-contractor-information-systems/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">15592</post-id><media:thumbnail url="https://one.sightlinemg.com/wp-content/uploads/2026/08/635854350849568071-metzgerjpg.jpg.jpg" width="3603" height="2027" type="image/jpeg" />
<media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/635854350849568071-metzgerjpg.jpg.jpg" width="3603" height="2027" type="image/jpeg" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">After years of gestation, a final rule was promulgated May 16 to mandate minimum cyber defenses for companies that do government business. This Federal Acquisition Regulations rule – &#8220;Basic Safeguarding of Contractor Information Systems&#8221; 81 Fed. Reg. 30439 – seeks to protect the confidentiality and integrity of federal contract information (FCI) that resides in or transits through any contractor information system.  <br/><br/><strong>Why this rule? </strong><br/><br/>Agencies are required by the Federal Information Security Modernization Act to protect federal information. The obligation extends to nonpublic information provided by the federal government to its contractors. Unauthorized cyber extraction of federal information has caused genuine injury to national interests. Using this new FAR provision, every federal agency now will require minimum cyber protection for FCI. <br/><br/><strong>What is federal contract information? </strong><br/><br/>FCI is defined as nonpublic information that is &#8220;provided by or generated for the government&#8221; under a contract to &#8220;develop or deliver a product or service to the government,&#8221; but not including information provided to the public or simple transactional information. The new rule protects &#8220;information systems&#8221; rather than carefully defined information types, however. If a contractor processes stores or transmits any FCI, its information system becomes subject to 15 basic safeguards. Where a contractor information system hosts FCI and other, non-federal information, the rule applies to the whole system.<br/><br/></p>





<p class="wp-block-paragraph"><strong>Why now?</strong></p>



<p class="wp-block-paragraph">The new FAR has been in the works since March 2010 – but the subject is complex. Even &#8220;basic&#8221; protection of federal information involves many variables and requires resolution of tough questions. This FAR rule of general application will affect thousands of companies, and must align with other federal cyber initiatives.</p>



<p class="wp-block-paragraph"><strong>Who is affected?</strong></p>



<p class="wp-block-paragraph">The new &#8220;Basic Safeguarding&#8221; contract clause, at FAR 52.204-21, is to be included in every solicitation and resulting contract. It applies below the simplified acquisition threshold, to subcontractors for commercial items, and to services (if there is FCI) – but not to the acquisition of commercial-off-the-shelf items. Flowdown is required: The clause applies to any contract or subcontract that involves receipt, use or generation of FCI, where a contractor information system figures into these functions.</p>



<p class="wp-block-paragraph"><strong>How is protection achieved?</strong></p>



<p class="wp-block-paragraph">The federal government has a surfeit of cyber controls. Those designed for federal information systems, e.g., NIST SP 800-53, are too costly and burdensome to impose on contractors to protect FCI. Instead, the new rule calls out 15 safeguards, each derived from the 2015 NIST Special Publication, SP 800-171.</p>



<p class="wp-block-paragraph">(Created for commercial organizations, SP 800-171 states 109 safeguards and applies to federal information that is more sensitive than FCI.)</p>





<p class="wp-block-paragraph"><strong>How will industry respond?</strong></p>



<p class="wp-block-paragraph">Last summer, the Department of Defense issued the ‘Network Penetration’ Defense Federal Acquisition Regulation Supplement that requires defense suppliers to apply the SP 800-171 safeguards to protect what DoD calls covered defense information. The DFARS met with strong industry resistance because of uncertainty over costs and how to comply. Similarly, many companies likely will object to the new FAR, even though it invokes only 15 cyber safeguards and these are performance standards – goals – rather than prescriptive design standards. The new rule presumes that the required safeguards are consistent with &#8220;prudent business practices.&#8221; Even so, this FAR has been issued because trust in market forces and customary business practices only goes so far.</p>



<p class="wp-block-paragraph"><strong>Are there problems in the final rule?</strong></p>



<p class="wp-block-paragraph">Predictably, as this rule addresses a highly complex area and applies so broadly, there are drafting issues. One issue is whether companies must apply the minimum safeguards to federal information received before the rule. Companies may be uncertain how to reconcile varying federal cyber controls for different types of protected federal information. Some may ask if it the government’s responsibility, in every case, to designate FCI, or whether contractors are to make their own decisions.</p>



<p class="wp-block-paragraph">Although expressed at a high level, the rule identifies the 15 safeguards as requirements. The rule provides no method to establish compliance. In the absence of stated process, is self-assessment and good faith sufficient? Some companies will have questions as to how much to do, when, with what test, or what validation, and so forth. The regulation concerns contractor information systems and the intent is minimally sufficient security. The government should assure contractors that they can satisfy the new rule without having to embrace the various, often exacting NIST standards developed for federal information systems or for more sensitive federal information types. For FCI, contractors should be encouraged to use sound commercial practices and methods.</p>



<p class="wp-block-paragraph">This new rule is a major development. While self-described as &#8220;just one step in a series of coordinated regulatory actions being taken or planned&#8221; to strengthen federal protections of contractor information systems, it reflects a government decision to use its regulatory power and acquisition authority to mandate minimum cyber defenses for all private companies that do government business.</p>



<p class="wp-block-paragraph"><em>Robert Metzger is a shareholder at law firm Rogers Joseph O&#8217;Donnell PC, where he&#8217;s a member of the Government Contracts Practice Group and head of the Washington, D.C., office.</em></p>
]]></content:encoded>
	</item>
		<item>
		<title>Secure networks critical to maintaining DoD tech edge</title>
		<link>https://www.federaltimes.com/opinions/2016/04/26/secure-networks-critical-to-maintaining-dod-tech-edge/</link>
					<comments>https://www.federaltimes.com/opinions/2016/04/26/secure-networks-critical-to-maintaining-dod-tech-edge/#respond</comments>
		
		<dc:creator><![CDATA[Robert Metzger]]></dc:creator>
		<pubDate>Tue, 26 Apr 2016 15:28:50 +0000</pubDate>
				<category><![CDATA[Inside the Agencies]]></category>
		<category><![CDATA[Opinion]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2016/04/26/secure-networks-critical-to-maintaining-dod-tech-edge/</guid>

					<description><![CDATA[The Defense Department must work with the industrial base to protect technical information from cyberattacks.]]></description>
		
					<wfw:commentRss>https://www.federaltimes.com/opinions/2016/04/26/secure-networks-critical-to-maintaining-dod-tech-edge/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">22009</post-id><media:thumbnail url="https://one.sightlinemg.com/wp-content/uploads/2026/08/635854350849568071-metzgerjpg.jpg.jpg" width="3603" height="2027" type="image/jpeg" />
<media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/635854350849568071-metzgerjpg.jpg.jpg" width="3603" height="2027" type="image/jpeg" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">Many in U.S. industry — even some among key defense suppliers — do not grasp the extent to which our defense posture has suffered from unauthorized extraction of technical information. This is a persistent and evolving threat — and one where there is ample evidence that nation-state rivals and commercial competitors have &#8220;feasted&#8221; at our expense by employing network-directed cyberattacks to steal and then exploit valuable information.</p>



<p>The Department of Defense&#8217;s <span class="rte rte-comment">DoD’s &#8220;</span>Better Buying Power 3.0<span class="rte rte-comment">&#8220;</span> states plainly that compromise of unclassified, controlled, technical information &#8220;can significantly degrade U.S. technological superiority by saving an adversary time and effort in developing similar capabilities or countermeasures.&#8221; Where contractor information systems host sensitive DoD technical information that is vulnerable to extraction, it is likely that company proprietary information and trade secrets are similarly exposed. </p>



<p>DoD has wielded its acquisition authority to obligate contractors to improve protection of technical information through the &#8220;Unclassified Controlled Technical Information&#8221; <span class="rte rte-comment">(UCTI) </span>Defense Federal Acquisition Regulation Supplement, and more recently, by the &#8220;Network Penetration&#8221; DFARS, which includes National Institute of Standards and Technology&#8217;s SP 800-171 — new safeguards specifically intended for commercial organizations. <span class="rte rte-comment">First in 2013, through the &#8220;Unclassified Controlled Technical Information&#8221; (UCTI) Defense Federal Acquisition Regulation Supplement, and more recently, in 2015, by the &#8220;Network Penetration&#8221; DFARS, DoD has wielded its acquisition authority to obligate contractors to improve protection of technical information. On Dec. 30, 2015, by an amendment to the &#8220;Network Penetration&#8221; Interim Rule, DoD decided to postpone, until Dec. 31, 2017, obligations to fully comply with the National Institute of Standards and Technology SP 800-171 — the new safeguards specifically intended for commercial organizations. This decision was regrettable, because the extraction threat is immediate and continuing, but necessary for practical reasons. Some in the defense industrial base were uncertain how to comply and many companies were surprised by and unprepared for the new DFARS requirements. They needed the time to assess the state of existing cyber measures and to implement improvements, as necessary to fill gaps and to satisfy the 109 controls stated in SP 800-171.</span></p>



<p>Under the &#8220;Network Penetration&#8221; DFARS, new DoD contracts are subject to DFARS 252.204–7012 (&#8220;Safeguarding Covered Defense Information and Cyber Incident Reporting&#8221;). This <span class="rte rte-comment">‘S</span>safeguarding<span class="rte rte-comment">&#8220;</span> clause imposes a direct and immediate security obligation on defense contractors. It states: </p>



<p class="wp-block-paragraph"><p>&#8220;The Contractor shall provide adequate security for all covered defense information [CDI] on all covered contractor information systems that support the performance of work under this contract.&#8221;</p></p>



<p>For contractor information systems, the <span class="rte rte-comment">&#8220;S</span>safeguarding<span class="rte rte-comment">&#8220;</span> clause requires implementation, &#8220;at a minimum,&#8221; the security requirements of SP 800-171, and this must be done &#8220;as soon as practical, but not later than Dec.<span class="rte rte-comment">ember</span> 31, 2017.&#8221; Some in the defense industrial base were uncertain how to comply with<span class="rte rte-comment"> and many companies were surprised by and unprepared for</span> the new DFARS requirements. They also needed time to assess the state of existing cyber measures and to implement improvements<span class="rte rte-comment">, as necessary to fill gaps and</span> to satisfy the 109 controls stated in SP 800-171. </p>



<p>Flowdown of the <span class="rte rte-comment">&#8220;S</span>safeguarding<span class="rte rte-comment">&#8220;</span> clause is required — &#8220;without alteration&#8221; — to subcontractors who receive or host CDI.</p>



<p>DoD’s largest contractors are likely to have in place already systems to protect CDI that meet or exceed the requirements of SP 800-171. As to medium-sized and smaller businesses, the risks increase. Adversaries recognize that valuable, technical information is accessible not just through <span class="rte rte-comment">at the </span>&#8220;tier 1&#8221; contractors, where we can expect relatively good cyber measures, but also <span class="rte rte-comment">&#8220;</span>down<span class="rte rte-comment">&#8220;</span> the supply chain<span class="rte rte-comment">, where protection is less assured</span>.</p>



<p class="wp-block-paragraph">There is some anecdotal evidence that medium-sized companies are approaching the cyber obligations of the &#8220;Network Penetration&#8221; rules cautiously, and that smaller companies are doing little while they wait to see how compliance can be achieved affordably and without business disruption. Some companies may contemplate leaving the defense supply chain out of concern over the burdens and costs of the new cyber requirements. This is not in DoD&#8217;s interest — and could deprive higher tier contractors of essential and trusted specialty suppliers.</p>



<p>DoD needs to help solve this problem and should do so with the active cooperation of the larger primes. DoD may need to make funding available to assist its industrial base in compliance with new cyber protection demands. Added protection comes at a cost to those who implement it and thus at a price to DoD. At a more technical level, DoD needs to work with NIST to develop ways that authorize smaller businesses to employ third-party, cloud-based resources to handle the access, authentication and security requirements imposed when these companies receive CDI. And these developments <span class="rte rte-comment">Ways </span>need to be promoted to protect this information without costly obligations to reconfigure enterprise<span class="rte rte-comment">&#8211;</span>wide information systems.</p>



<p>The approach of NIST SP 800-171 focuses upon protecting<span class="rte rte-comment">ion</span><span class="rte rte-comment"> of</span> information systems, but <span class="rte rte-comment">as the means </span><span class="rte rte-comment">to protect the information hosted on those systems</span><span class="rte rte-comment">. </span><span class="rte rte-comment">W</span>we might take a lesson from several of the notorious security breaches of recent years. Protection of the information system<span class="rte rte-comment">,</span> as if it were <span class="rte rte-comment">a &#8220;citadel,&#8221; or </span>a <span class="rte rte-comment">&#8220;</span>castle<span class="rte rte-comment">&#8220;</span> with barriers (e.g., firewalls) <span class="rte rte-comment">constituting a veritable &#8220;moat,&#8221; </span>has not worked well when <span class="rte rte-comment">where </span>massive amounts of information, once extracted<span class="rte rte-comment"> from the information system</span>, are unprotected and freely transferable. Technical measures are available to encrypt and otherwise control or<span class="rte rte-comment">, even</span> deny<span class="rte rte-comment">,</span> access and rights to sensitive but unclassified information. Digital rights management<span class="rte rte-comment">, as can be cloud-enabled or premises-based,</span> provides a means to retain control over <span class="rte rte-comment">access to and use rights in </span>sensitive information even after initial transfer to an<span class="rte rte-comment"> intended and</span> authorized recipient or <span class="rte rte-comment">and even </span>in the event of a successful but unauthorized extraction. Future governmental cyber initiatives should encourage and, where necessary, enable the use of these methods.</p>



<p class="wp-block-paragraph">(I&#8217;ll return to the Internet of Things and cyber/physical threats in future <em>Federal Times</em> blogs.)</p>



<p class="wp-block-paragraph"><em>Robert Metzger is a shareholder at law firm Rogers Joseph O&#8217;Donnell PC, where he&#8217;s a member of the Government Contracts Practice Group and head of the Washington, D.C., office.</em></p>
]]></content:encoded>
	</item>
		<item>
		<title>Internet of Things: When cyberattacks have physical effects</title>
		<link>https://www.federaltimes.com/opinions/2016/04/08/internet-of-things-when-cyberattacks-have-physical-effects/</link>
					<comments>https://www.federaltimes.com/opinions/2016/04/08/internet-of-things-when-cyberattacks-have-physical-effects/#respond</comments>
		
		<dc:creator><![CDATA[Robert Metzger]]></dc:creator>
		<pubDate>Fri, 08 Apr 2016 15:01:07 +0000</pubDate>
				<category><![CDATA[Inside the Agencies]]></category>
		<category><![CDATA[Opinion]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2016/04/08/internet-of-things-when-cyberattacks-have-physical-effects/</guid>

					<description><![CDATA[The Internet of Things comes with new risks, such as vulnerabilities in SCADA systems that control critical infrastructure.]]></description>
		
					<wfw:commentRss>https://www.federaltimes.com/opinions/2016/04/08/internet-of-things-when-cyberattacks-have-physical-effects/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">12511</post-id><media:thumbnail url="https://one.sightlinemg.com/wp-content/uploads/2026/08/635854350849568071-metzgerjpg.jpg.jpg" width="3603" height="2027" type="image/jpeg" />
<media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/635854350849568071-metzgerjpg.jpg.jpg" width="3603" height="2027" type="image/jpeg" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">New risks accompany the Internet of Things (IoT). Software attacks that produce physical effects are especially troubling.</p>



<p>Take the Bowman Avenue Dam attack, as an example. On March 24, 2016, the Department of Justice announced charges against an Iranian hacker who mounted a cyber-physical attack upon the supervisory control and data acquisition (SCADA) systems of the Bowman Dam, in Rye, New York. The charges are that the hacker repeatedly obtained information regarding the status and operation of the dam, including information about the water levels and temperature, and the status of the sluice gate, which <span class="rte rte-comment">is responsible for controlling </span>controls water levels and flow rates. The hacker obtained access that, ordinarily, would have enabled him to remotely operate and manipulate the dam’s sluice gate. Fortuitously, the gate had been manually disconnected at the time of his intrusion.</p>



<p>This is a real-time example of exactly the kind of IoT risks that I’ve discussed in my two previous blogs for Federal Times. In the <a href="http://www.federaltimes.com/story/government/solutions-ideas/2015/12/11/how-iot-poses-security-risk-our-critical-infrastructure/77152806/">first blog</a>, <span class="rte rte-comment"><a href="http://www.federaltimes.com/story/government/solutions-ideas/2015/12/11/how-iot-poses-security-risk-our-critical-infrastructure/77152806/">http://www.federaltimes.com/story/government/solutions-ideas/2015/12/11/how-iot-poses-security-risk-our-critical-infrastructure/77152806/</a>, Dec. 11, 2015,</span> I observed that &#8220;cyberattacks upon the IoT can produce adverse consequence upon physical systems that are IoT endpoints.&#8221;  Had the Bowman Dam sluice gate not been down for maintenance, the Iranian attacker could have opened the gate and produced flooding. </p>



<p class="wp-block-paragraph">Federal officials, especially those at the Department of Homeland Security, are alert to cyber-physical threats to SCADA systems that control critical infrastructure. With the proliferation of IoT instrumentalities, we can expect greater interconnectivity and integration among control systems and controlled equipment. IoT endpoint devices will be employed for many purposes, including &#8220;informational&#8221; functions (e.g., status reports on condition and capacity) and those for &#8220;control&#8221; (e.g., activation/deactivation). Distinct to the now-emerging IoT &#8220;4th generation&#8221; of SCADA systems, control functionality will be increasingly automated with decisions made on a machine-to-machine basis, without human intervention.</p>



<p>From the federal perspective, the IoT promises optimization of infrastructure operations through interconnected SCADA systems.  If properly implemented, conceivably security can be enhanced as IoT systems can accelerate receipt of information on system status and facilitate rapid response to either cyber or physical threats.  However, as I commented in my <a href="http://www.federaltimes.com/story/government/solutions-ideas/2016/02/04/reconciling-risk-and-value-internet-things/79826836/">second blog</a>,<span class="rte rte-comment"><a href="http://www.federaltimes.com/story/government/solutions-ideas/2016/02/04/reconciling-risk-and-value-internet-things/79826836/">http://www.federaltimes.com/story/government/solutions-ideas/2016/02/04/reconciling-risk-and-value-internet-things/79826836/</a>, Feb. 10, 2016,</span>  &#8220;authentication, identity management and transaction processing add to exposed [attack] surfaces&#8221; for IoT systems. Positive security results for IoT-enabled SCADA systems will have to be achieved through a collaborative effort of federal authorities with relevant standards setting organizations<span class="rte rte-comment"> (SSOs)</span>, network architects, system engineers, equipment manufacturers, infrastructure operators<span class="rte rte-comment">,</span> and technical cyber specialists.   </p>



<p>DHS leads the federal government’s efforts to address the cybersecurity of critical infrastructure. DoD has recognized its need to protect the cybersecurity of the manufacturing capabilities of the defense industrial base<span class="rte rte-comment"> (DIB)</span>. Advanced manufacturing capabilities rely upon Industrial Control Systems (ICS). If we think of SCADA as large-scale control systems that typically cover a broad geographic area and multiple-site infrastructure systems (e.g., dams and irrigation, pipelines), ICS may be considered a subset of SCADA that refers to industrial automation and is more site-specific.</p>



<p>IoT instrumentalities will create new vulnerabilities for connected ICS. Endpoint devices would monitor equipment condition and utilization, for example. Resource allocation could be accomplished through communication of &#8220;status&#8221; to the host service<span class="rte rte-comment"> (at the core),</span> or by peer-to-peer communication around the periphery of connected devices. Equipment could receive software updates or scheduled service based upon the condition and utilization reports. While these &#8220;conditions&#8221; can exist today, with the advent of IoT the quantity of at-risk equipment will increase as will the number and diversity of industries using connected devices. The scale of the prospective &#8220;industrial IoT&#8221; elevates the cybersecurity risk to the advanced manufacturing capabilities of the defense industrial base<span class="rte rte-comment">DIB</span>.</p>



<p class="wp-block-paragraph">The risk is a function of threat, vulnerability and consequences of cyber-physical attacks:</p>



<ul class="wp-block-list"><li><strong>Threat:</strong> From the attacker’s perspective, an attraction of an &#8220;IoT-directed&#8221; attack is the potential for higher <span class="rte rte-comment">&#8220;</span>return on investment<span class="rte rte-comment">&#8220;</span> achieved if an attack at a single point of vulnerability produces wide and lasting impact. Some attackers (nation-states, sponsored agents or even commercial rivals) will find motivation to damage the U.S. economy, selected industry sectors, individual business rivals, particular factories or even specific equipment on a production line.</li><li><strong>Vulnerabilities</strong>: Potentially insecure junctures along the IoT &#8220;stack,&#8221; (i.e., applications, devices and platforms, sensors, transport<span class="rte rte-comment"> (connectivity)</span>, analytics and infrastructure) produce increased attack surfaces. Only one point of weak controls along the IoT &#8220;stack&#8221; is sufficient for an adversary to mount an attack<span class="rte rte-comment">, by malware insertion, intended</span> to disrupt or corrupt control functions of connected equipment.</li><li><strong>Consequences</strong>: Connected equipment sharing control systems indicates that a targeted IoT attack, upon an ICS system at one factory (or a group of connected factories) could produce serious, long-lasting damage to critical manufacturing capabilities.</li></ul>



<p>The damage from an IoT attack upon ICS might not have the immediacy or threaten physical harm to the safety of Americans as could a SCADA attack upon power grids or flood control infrastructure, but the economic damage and the impairment of defense manufacturing capabilities could be profound. Here too, there is real-world evidence of the power — and danger — of ICS attacks. Once inserted into the ICS that controlled Iran’s uranium enrichment facilities, the <span class="rte rte-comment">&#8220;</span>Stuxnet<span class="rte rte-comment">&#8220;</span> virus produced high rates of failure of centrifuge equipment and crippled Iran’s nuclear ambitions. This is an early but cautionary example of how malicious software code can be spread among ICS with devastating industrial effect. </p>



<p class="wp-block-paragraph">U.S. leaders and responsible industry officials must plan for and defend against counterpart but evolved threats that will accompany the adoption of IoT functionalities in SCADA and ICS. My next blog will look at mitigation of cyber-physical risks and potential federal responses.  I will also consider the role of statute, regulation and acquisition practices in the federal response.</p>



<p class="wp-block-paragraph"><em>Robert Metzger is a shareholder at law firm Rogers Joseph O&#8217;Donnell PC, where he&#8217;s a member of the Government Contracts Practice Group and head of the Washington, D.C. office.</em></p>
]]></content:encoded>
	</item>
		<item>
		<title>Reconciling risk and value for the Internet of Things</title>
		<link>https://www.federaltimes.com/opinions/2016/02/04/reconciling-risk-and-value-for-the-internet-of-things/</link>
					<comments>https://www.federaltimes.com/opinions/2016/02/04/reconciling-risk-and-value-for-the-internet-of-things/#respond</comments>
		
		<dc:creator><![CDATA[Robert Metzger]]></dc:creator>
		<pubDate>Thu, 04 Feb 2016 19:33:33 +0000</pubDate>
				<category><![CDATA[Inside the Agencies]]></category>
		<category><![CDATA[Opinion]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2016/02/04/reconciling-risk-and-value-for-the-internet-of-things/</guid>

					<description><![CDATA[The Internet of Things: enormous opportunities, paired with vulnerabilities and consequences.]]></description>
		
					<wfw:commentRss>https://www.federaltimes.com/opinions/2016/02/04/reconciling-risk-and-value-for-the-internet-of-things/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">13410</post-id><media:thumbnail url="https://one.sightlinemg.com/wp-content/uploads/2026/08/635854350849568071-metzgerjpg.jpg.jpg" width="3603" height="2027" type="image/jpeg" />
<media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/635854350849568071-metzgerjpg.jpg.jpg" width="3603" height="2027" type="image/jpeg" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph"><em>Robert Metzger is a shareholder at law firm Rogers Joseph O&#8217;Donnell PC, where he&#8217;s a member of the Government Contracts Practice Group and head of the Washington, D.C. office.</em></p>



<p class="wp-block-paragraph">The Internet of Things (IoT) presents enormous opportunities accompanied, unfortunately, by potential for both new security vulnerabilities and aggravated consequences.</p>



<p class="wp-block-paragraph">The IoT operates by connection of end-point devices (such as sensor networks) to control systems and by communication along the edge as well as to the core. Devices both collect information and act upon instruction. Control systems may be central or distributed. Attack surfaces, as seen by adversaries, will multiply, to include end point devices, network interconnections and transport infrastructure, and the control systems that incorporate core functions, such as data analytics, which act upon received information to generate instruction communicated to devices. Authentication, identity management and transaction processing add to exposed surfaces. IoT implies massive interconnectivity and constant interdependence among devices, communications and control.</p>



<p class="wp-block-paragraph">For critical infrastructure, for illustration, the IoT could enable electrical generators to self-monitor, predict fault, adjust function, and call for maintenance. (Such functionality is present today for certain civil aircraft engines.) And, the IoT can produce &#8220;liquidity&#8221; in asset utilization; through autonomous communications among machines, generators can distribute or balance load without operator intervention. Some sensitive systems in the defense sector will be isolated from the IoT, but many will not. IoT devices might be used for defense logistics purposes, e.g., widespread distribution of wireless smart tags to monitor readiness, track availability and inform disposition decisions for physical assets such as pre-positioned military stores. The defense industrial base is likely to employ IoT devices for such purposes as efficient resource allocation and enhanced functionality.</p>



<p class="wp-block-paragraph">The IoT likely will proliferate devices and systems at risk of discrete attacks – an &#8220;attack once, impact many&#8221; paradigm. This exposure results where devices and dependent systems possess common vulnerabilities and suffer circulation of common injury, and where corruption spread among linked applications affects numerous connected systems. Applied to the infrastructure example, one IoT attack could degrade or disable many power generators across an entire grid. An IoT attack, conceivably, could &#8220;poison&#8221; the military logistics decision system, leaving commanders without knowledge of equipment availability and readiness.</p>



<p>My <a href="http://www.federaltimes.com/story/government/solutions-ideas/2015/12/11/how-iot-poses-security-risk-our-critical-infrastructure/77152806/">previous blog</a><span class="rte rte-comment"> (Federal Times, Dec. 11, 2015)</span> asked whether the federal government is doing a good job to protect against IoT security threats. My answer was, &#8220;not well.&#8221; Our goal should be to move to where the answer becomes, &#8220;not yet,&#8221; and eventually, &#8220;yes.&#8221;</p>



<p class="wp-block-paragraph">The IoT, I suggested, presents &#8220;cyber/physical&#8221; risks because cyber attacks will impact physical devices. For systems it acquires and supports, the federal government can use its acquisition authority to encourage and eventually mandate actions to reduce vulnerability to IoT cyber/physical attacks, to mitigate the consequences and to promote resilience and expedite recovery afterwards.</p>



<p class="wp-block-paragraph">This authority is exercised through procurement regulations, solicitation requirements, and by specific contract terms. Caution is necessary because federal agencies rely upon and need access to the diversity and innovation of commercial sources, and because the goal is not to frustrate U.S. exploitation of the IoT but to protect federal systems and critical infrastructure against its new vulnerabilities.</p>



<p class="wp-block-paragraph">Targeted supply chain risk management and cyber initiatives can improve understanding of new risks and reduce exposure to IoT cyber/physical threats. I offer five recommendations:</p>



<ol class="wp-block-list"><li>Create market and tax incentives to encourage defense industrial base and other private sector critical infrastructure participants to self-assess for cyber/physical and IOT vulnerabilities and act to eliminate them;</li><li>Promote continuing development of scalable IoT and cyber/physical norms, standards and best practices, while taking care to avoid both prescriptive solutions or the potential chaos of competing and conflicting norms;</li><li>Develop and validate methods of authentication and authorization, as may rely (for example) upon embedded, tamper-proof and cryptographically secure chips, in order to enhance transaction security among IoT applications, devices and core systems;</li><li>Cause federal agencies responsible for critical systems and infrastructure to assess vulnerability of present and planned systems to cyber/physical threats, and to implement protection plans;</li><li>Begin to develop regulations to require defense primes and critical infrastructure contractors to adopt systems to anticipate and avoid cyber/physical vulnerabilities and to monitor and report on cyber/physical attacks.</li></ol>



<p class="wp-block-paragraph">It is now considered essentially impossible to eliminate entirely the risk of a cyber attack. Apart from defensive measures, the inevitability of cyber/physical attacks through the IoT emphasizes also the importance of reaction, recovery, reporting, and information exchange after attack. For key defense systems and critical infrastructure, it may prove necessary to inventory at-risk electronic components and connected cyber-active systems, to expand reporting obligations to include malicious code events and hostile exploits of cyber-active parts, and to collect and rapidly exchange event and exploit information. Data analytics and automated decision methods can be employed to predict risks, disseminate device-specific reports, advise or implement defensive measures, and to effect wide-scale recovery actions. These measures can be accomplished – but we need a national strategy to protect security and privacy, while we promote the IoT and leverage its value, clear leadership among interested federal agencies and (hopefully) consensus between the Executive branch and Congress.</p>
]]></content:encoded>
	</item>
	</channel>
</rss>
