Government Technology Insider
  • About
  • State & Local
  • Civilian
  • Defense & IC
SUBSCRIBE
No Result
View All Result
  • Acquisition
  • AI & Data
  • Cybersecurity
  • CX
  • Digital Transformation
  • Hybrid Work
    • Work Smarter
  • Public Safety
  • Resources
    • Technology Trends Shaping the Future of Government
    • World of Work
    • Your Digital Transformation Path Starts Here
    • The Frontlines of Customer Experience
    • Innovative Solutions for Connecting Agencies
    • Be Ready For What’s Next
Government Technology Insider
  • Acquisition
  • AI & Data
  • Cybersecurity
  • CX
  • Digital Transformation
  • Hybrid Work
    • Work Smarter
  • Public Safety
  • Resources
    • Technology Trends Shaping the Future of Government
    • World of Work
    • Your Digital Transformation Path Starts Here
    • The Frontlines of Customer Experience
    • Innovative Solutions for Connecting Agencies
    • Be Ready For What’s Next
No Result
View All Result
Government Technology Insider
No Result
View All Result
Home Defense & IC

AFCEA WEST 2020: INOCCS, Zero Trust, and SecDevOps Help Balance Security and Speed

by Jenna Sindle
April 20, 2020
in Defense & IC
Reading Time: 5 mins read
A A
AFCEA WEST 2020: INOCCS, Zero Trust, and SecDevOps Help Balance Security and Speed
Share on FacebookShare on Twitter

Balancing cybersecurity and operational demands is an ongoing challenge for all of the armed services. At AFCEA WEST 2020, the Sea Services highlighted their strategies to balance those two seemingly competing needs. An essential component will be the Integrated Navy Operations Command and Control System (INOCCS), a “system of systems” for network operations that will allow warfighters to defend everything inside the network.

Speaking at AFCEA WEST on March 2, Manuel Hermosilla, executive director of 10th Fleet/Fleet Cyber Command, said that the long-planned INOCCS framework is now moving forward, adding, “We’re building out the architecture and design for the Navy digital platform transformation effort.” Improved network and systems management, zero trust security and SecDevOps are all parts of the Sea Services’ ongoing technology investment.

As Tim Smith, SolarWinds’s Senior Director – DoD, Civilian Government and Federal Systems Integrators, explained, the nation’s maritime services are looking for rich functionality and simplicity in execution. The transient nature of the enlisted sailors in the fleet  E3s and E5s conducting network management means that it needs to be simple to use to reduce the time spent learning the system. Add to that the fact that “each ship is supported by anywhere from one up to 17 separate networks, each with different security classifications, and it becomes clear that consistency and simplicity are crucial to managing them effectively,” he said.

Smith’s colleague, Omar Rafik, Senior Manager, Federal Sales Engineering for SolarWinds, added that security can be an overwhelming task, due to the diversity of those networks. “You could have one router, one firewall on a ship could literally generate tens of thousands of events in one day,” he said. “That could be 30 or 40 firewalls and hundreds of network devices on a ship. A SIEM – a security event management tool – becomes extremely important to have, to identify all of the threats that can possibly happen.”

Trust, yet Verify

Rafik said the Navy in particular is moving to a zero trust approach as a solution, not just for external security but to help combat insider threats. “The concept is simple,” he explained. “The threat model no longer assumes that computers, users and admins inside your network are secure. It just says, ‘Let’s assume that not only every person but every machine that’s touching your network is a potential external threat.’ So, now you lock everything down with multiple layers of security, multi-factor authentication and things of that nature.”

To make zero trust work, identities must be authenticated and permissions must be managed, even as people move around the network or come in through an expanding array of endpoints. Rafik said the answer is to employ ‘least privileged access,’ where everybody gets the minimum level of access, and additional access is provided as an exception. “That’s achieved through tools for access rights management,” he said, adding, “There’s also the concept of segmenting your network, where segments can have privileged access versus the rest of the network, even on the inside.”

Rafik gave this analogy: “Imagine your network being your home. You lock the outside door, and some people have keys to get in. But you don’t lock the doors on the inside because you feel secure. Zero trust is more like an apartment building where the outside door is locked, and people have keys to get in. But you don’t know who’s running up and down the halls or in the elevators. So you lock the doors to the hallway.”

Speed Counts

Smith said that speed is definitely a concern for the Sea Services. He referred to a panel at WEST 2020 with representatives from the Coast Guard, Marines and Navy as well as DISA where the issue of moving faster was discussed at length. In particular, these leaders were concerned with shortening development cycles to get new technology onto ships faster. “As opposed to the old waterfall approach (of software development), people are conducting SecDevOps – ‘let’s get it out there, let’s field it, and it we have to fix it and change it on the fly, we will do it.’ They need to get information to the warfighter quickly, and security still needs to be built in,” Smith said.

The challenges comes down to three areas, Smith explained: “They want to be secure, they want to comply with the INOCCS mandate, and they have to be fleet of feet.” The solutions can be found in tools that allow for consolidated management of multiple systems and applications, along with tools like SIEMs and access rights management. At the same time, despite the competing demands for speed and security, Rafik stressed that security always wins out. “They’d rather have it slow and secure than fast and not secure. They will never compromise security for speed.”

Tags: AFCEACoast GuardcybersecurityINOCCSManuel HermosillaMarinesnavyNetwork ManagementOmar RafikSea Services CyberSecDevOpsSIEMsolarwindsTim SmithWEST 2020Zero Trust

RELATED POSTS

secure cloud communications represented by a hand holding a cloud with various symbols representing communication things
Cybersecurity

How to Enhance and Secure Cloud Communications Between Agencies

March 30, 2023
FedRAMP is the Foundation of Trusted and Secure Government
Acquisition

FedRAMP is the Foundation of Trusted and Secure Government

March 29, 2023
Department of Defense Zero Trust Strategy
Defense & IC

Exploring the New Department of Defense Zero Trust Strategy: A Podcast with Verizon and Zscaler

March 28, 2023

TRENDING NOW

  • Advana

    Meet Advana: How the Department of Defense Solved its Data Interoperability Challenges

    9427 shares
    Share 3771 Tweet 2357
  • Exploring the New Department of Defense Zero Trust Strategy: A Podcast with Verizon and Zscaler

    86 shares
    Share 34 Tweet 22
  • FedRAMP is the Foundation of Trusted and Secure Government

    38 shares
    Share 15 Tweet 10
  • Why the Government Needs a Cloud-Native Workforce

    21 shares
    Share 8 Tweet 5

CONNECT WITH US

Advertisement Banner Ad Advertisement Banner Ad Advertisement Banner Ad
Advertisement Banner Advertisement Banner Advertisement Banner
Advertisement Banner Advertisement Banner Advertisement Banner
Advertisement Banner Ad Advertisement Banner Ad Advertisement Banner Ad
MaaS Nebula Software Factory Banner Ad MaaS Nebula Software Factory Banner Ad MaaS Nebula Software Factory Banner Ad
Advertisement Banner Ad Advertisement Banner Ad Advertisement Banner Ad
Advertisment Banner Ad Advertisment Banner Ad Advertisment Banner Ad
Advertisement Banner Advertisement Banner Advertisement Banner
Advertisement Banner Ad Advertisement Banner Ad Advertisement Banner Ad

BECOME AN INSIDER

Get Government Technology Insider news and updates in your inbox.

Strategic Communications Group is a digital media company that helps business-to-business marketers drive customer demand through content marketing, content syndication, and lead identification.

Related Communities

Financial Technology Today
Future Healthcare Today
Modern Marketing Today
Retail Technology Insider
Today’s Modern Educator

Quick Links

  • Home
  • About
  • Contact Us

Become a Sponsor

Strategic Communications Group offers analytics, content marketing, and lead identification services. Interested?
Contact us!

© 2023 Strategic Communications Group, Inc.
Privacy Policy      |      Terms of Service

No Result
View All Result
  • Home
  • About Government Technology Insider
  • State & Local
  • Civilian
  • Defense & IC
  • Categories
    • Acquisition
    • AI & Data
    • Customer Experience
    • Cybersecurity
    • Digital Transformation
    • Hybrid Work
    • Public Safety
  • Contact Us