Government Technology Insider
  • About
  • State & Local
  • Civilian
  • Defense & IC
SUBSCRIBE
No Result
View All Result
  • Acquisition
  • AI & Data
  • Cybersecurity
  • Digital Transformation
  • Hybrid Work
    • Work Smarter
  • Public Safety
  • Resources
    • The Frontlines of Customer Experience
    • Innovative Solutions for Connecting Agencies
    • Be Ready For What’s Next
Government Technology Insider
  • Acquisition
  • AI & Data
  • Cybersecurity
  • Digital Transformation
  • Hybrid Work
    • Work Smarter
  • Public Safety
  • Resources
    • The Frontlines of Customer Experience
    • Innovative Solutions for Connecting Agencies
    • Be Ready For What’s Next
No Result
View All Result
Government Technology Insider
No Result
View All Result
Home Defense & IC

AFCEA WEST 2020: INOCCS, Zero Trust, and SecDevOps Help Balance Security and Speed

by Jenna Sindle
April 20, 2020
in Defense & IC
Reading Time: 5 mins read
A A
AFCEA WEST 2020: INOCCS, Zero Trust, and SecDevOps Help Balance Security and Speed
Share on FacebookShare on Twitter

Balancing cybersecurity and operational demands is an ongoing challenge for all of the armed services. At AFCEA WEST 2020, the Sea Services highlighted their strategies to balance those two seemingly competing needs. An essential component will be the Integrated Navy Operations Command and Control System (INOCCS), a “system of systems” for network operations that will allow warfighters to defend everything inside the network.

Speaking at AFCEA WEST on March 2, Manuel Hermosilla, executive director of 10th Fleet/Fleet Cyber Command, said that the long-planned INOCCS framework is now moving forward, adding, “We’re building out the architecture and design for the Navy digital platform transformation effort.” Improved network and systems management, zero trust security and SecDevOps are all parts of the Sea Services’ ongoing technology investment.

As Tim Smith, SolarWinds’s Senior Director – DoD, Civilian Government and Federal Systems Integrators, explained, the nation’s maritime services are looking for rich functionality and simplicity in execution. The transient nature of the enlisted sailors in the fleet  E3s and E5s conducting network management means that it needs to be simple to use to reduce the time spent learning the system. Add to that the fact that “each ship is supported by anywhere from one up to 17 separate networks, each with different security classifications, and it becomes clear that consistency and simplicity are crucial to managing them effectively,” he said.

Smith’s colleague, Omar Rafik, Senior Manager, Federal Sales Engineering for SolarWinds, added that security can be an overwhelming task, due to the diversity of those networks. “You could have one router, one firewall on a ship could literally generate tens of thousands of events in one day,” he said. “That could be 30 or 40 firewalls and hundreds of network devices on a ship. A SIEM – a security event management tool – becomes extremely important to have, to identify all of the threats that can possibly happen.”

Trust, yet Verify

Rafik said the Navy in particular is moving to a zero trust approach as a solution, not just for external security but to help combat insider threats. “The concept is simple,” he explained. “The threat model no longer assumes that computers, users and admins inside your network are secure. It just says, ‘Let’s assume that not only every person but every machine that’s touching your network is a potential external threat.’ So, now you lock everything down with multiple layers of security, multi-factor authentication and things of that nature.”

To make zero trust work, identities must be authenticated and permissions must be managed, even as people move around the network or come in through an expanding array of endpoints. Rafik said the answer is to employ ‘least privileged access,’ where everybody gets the minimum level of access, and additional access is provided as an exception. “That’s achieved through tools for access rights management,” he said, adding, “There’s also the concept of segmenting your network, where segments can have privileged access versus the rest of the network, even on the inside.”

Rafik gave this analogy: “Imagine your network being your home. You lock the outside door, and some people have keys to get in. But you don’t lock the doors on the inside because you feel secure. Zero trust is more like an apartment building where the outside door is locked, and people have keys to get in. But you don’t know who’s running up and down the halls or in the elevators. So you lock the doors to the hallway.”

Speed Counts

Smith said that speed is definitely a concern for the Sea Services. He referred to a panel at WEST 2020 with representatives from the Coast Guard, Marines and Navy as well as DISA where the issue of moving faster was discussed at length. In particular, these leaders were concerned with shortening development cycles to get new technology onto ships faster. “As opposed to the old waterfall approach (of software development), people are conducting SecDevOps – ‘let’s get it out there, let’s field it, and it we have to fix it and change it on the fly, we will do it.’ They need to get information to the warfighter quickly, and security still needs to be built in,” Smith said.

The challenges comes down to three areas, Smith explained: “They want to be secure, they want to comply with the INOCCS mandate, and they have to be fleet of feet.” The solutions can be found in tools that allow for consolidated management of multiple systems and applications, along with tools like SIEMs and access rights management. At the same time, despite the competing demands for speed and security, Rafik stressed that security always wins out. “They’d rather have it slow and secure than fast and not secure. They will never compromise security for speed.”

Tags: AFCEACoast GuardcybersecurityINOCCSManuel HermosillaMarinesnavyNetwork ManagementOmar RafikSea Services CyberSecDevOpsSIEMsolarwindsTim SmithWEST 2020Zero Trust

RELATED POSTS

Design Secure Application Software That Transforms Government Agencies
Civilian

Design Secure Application Software That Transforms Government Agencies

June 28, 2022
Contributed Articles

DMARC: A Critical Tool for State and Local Government Cybersecurity

June 21, 2022
Balancing Security and Customer Experience for Digital Government
CX Service and Delivery

Balancing Security and Customer Experience for Digital Government

June 20, 2022

TRENDING NOW

  • Advana

    Meet Advana: How the Department of Defense Solved its Data Interoperability Challenges

    5369 shares
    Share 2148 Tweet 1342
  • For the Army to Reach Modernization Goals, a Tactical Data Fabric is Crucial

    41 shares
    Share 16 Tweet 10
  • Design Secure Application Software That Transforms Government Agencies

    12 shares
    Share 5 Tweet 3
  • Customer and Industry Partnerships Are Helping Deliver 5G Solutions to Federal Agencies

    102 shares
    Share 41 Tweet 26
  • 2022 Government Investigations Technology Guide Discusses Nine Factors Investigators Should Consider in Technology Solutions

    12 shares
    Share 5 Tweet 3

CONNECT WITH US

MaaS Nebula Software Factory Banner Ad MaaS Nebula Software Factory Banner Ad MaaS Nebula Software Factory Banner Ad
Advertisement Banner Ad Advertisement Banner Ad Advertisement Banner Ad
Advertisement Banner Advertisement Banner Advertisement Banner
Advertisement Banner Ad Advertisement Banner Ad Advertisement Banner Ad
Advertisement Banner Advertisement Banner Advertisement Banner
Advertisement Banner Ad Advertisement Banner Ad Advertisement Banner Ad
Advertisement Banner Advertisement Banner Advertisement Banner
Advertisement Banner Advertisement Banner Advertisement Banner

BECOME AN INSIDER

Get Government Technology Insider news and updates in your inbox.

Strategic Communications Group is a digital media company that helps business-to-business marketers drive customer demand through content marketing, content syndication, and lead identification.

Related Communities

Financial Technology Today
Future Healthcare Today
Modern Marketing Today
Retail Technology Insider
Today’s Modern Educator

Quick Links

  • Home
  • About
  • Contact Us

Become a Sponsor

Strategic Communications Group offers analytics, content marketing, and lead identification services. Interested?
Contact us!

© 2021 Strategic Communications Group, Inc.
Privacy Policy      |      Terms of Service

No Result
View All Result
  • Home
  • About Government Technology Insider
  • State & Local
  • Civilian
  • Defense & IC
  • Categories
    • Acquisition
    • AI & Data
    • Digital Transformation
    • Cybersecurity
    • Hybrid Work
  • Contact Us