NDIA and DoD Joint Working Group Cybersecurity for Advanced Manufacturing NDIA Manufacturing Division Meeting October 21-22, 2015 Joint Working Group - Cybersecurity for Manufacturing NDIA Cyber, Manufacturing, SE and Logistics Divisions • NDIA White Paper revealed the threats to the “digital thread” that transits defense contractors’ manufacturing operations networks and control systems – Theft of technical info -- can compromise national defense and economic security – Alteration of technical data -- can alter the part or the process, with physical consequences to mission and safety – Disruption or denial of process control -- can shut down production • In December 2014 meeting, Kristen Baldwin (DASD(SE)) endorsed recommendations and offered to support effort’s next phase • NDIA has formed a new Joint Working Group to work with DoD – Four NDIA divisions: Cyber, Logistics, Manufacturing and Systems Engineering – Corresponding Government offices: DoD CIO; Joint Staff J4, Knowledge-Based Logistics Division; Manufacturing & Industrial Base Policy; and Office of Deputy Assistance Secretary of Defense for Systems Engineering – Other Government offices: Air Force Research Lab; Idaho National Laboratory; White House Office of Science and Technology Policy; Sandia National Laboratories October 21-22, 2015 NDIA Recommendations for DoD 1. Work with industry on risk-based, voluntary standards and practices for factory floor cybersecurity. – Evaluate NIST framework as starting point. 2. Conduct forums with industry to help understand and implement DFARS clause, including factory floor implications. 3. Update DoD guidance on the Program Protection Plan (PPP) to include protection in factory floor systems. 4. Use red teams to expose vulnerabilities and R&D to fill gaps 5. Assist small and medium suppliers with training and investments – NIST Manufacturing Extension Partnership to deliver training – Defense Prod Act Title III and Manufacturing Technology investments – Training for DoD contracting officers October 21-22, 2015 NDIA JWG 2.0 Members As of October 21, 2015 Government NDIA Vicki Barbur (M) Dean Bartels (M) Dave Chesebrough (C) Marilyn Gaska (M) James Goodwin (C) Jason Gorey (C) Jim Holtzclaw (M) David Huggins (SE) Larry John (M) Tom McCullough (SE) Tom McDermott (SE) Mike McGrath (M) Heather Moyer (M) Brench Boden (AFRL) Kaye Ortiz (M) Megan Brewster (OSTP) Martha Charles-Vickers (Sandia NL) Don Davidson (CIO) Chris Fall (OSTP) October 2015 (JS J4) Bob21-22, Pickett Chris Peters (M) Frank Serna (SE) Devu Shila (M) Tim Shinbara (M) Joe Spruill (M) Sarah Stern (SE) Rebecca Taylor (M) John Toomer (C) Mary Williams (M) Adele Ratcliff Jeff Wolske (SE) (MIBP) Melinda Reed (SE) Craig Rieger (Idaho National Lab) Melinda Woods (MIBP) C=Cyber; L=Logistics; M=Manufacturing; SE=Systems Engineering Organizations represented: AEFI AMT ANSER Boeing BriteWerx Concurrent Technologies DBS DMDII Draper Engility GA Tech Lockheed Martin McGrath Analytics MTEQ NCMS Raytheon Six O’Clock Ops The Lucrum Group United Technologies Waverly Labs JWG 2.0 Launch November 13th, 2015 8:30am – 12:30pm NDIA Headquarters, 2111 Wilson Boulevard, Arlington VA Our launch meeting will be designed to: • Coordinate goals and expectations between the Government and NDIA teams • Develop a project schedule and operational structure • Identify topic-specific subgroups October 21-22, 2015