Defense Department’s Multi-Cloud Cloud Strategy: A Role for SIEM

Industries Tim Frank

It’s difficult to recall a time over the last ten years when cloud requirements were not at the forefront of the Defense Department’s modernization efforts. Cloud capability reviews and requirements, in some form, extend from the Pentagon’s net-centricy efforts — to the Joint Information Environment, Digital Modernization, and up through to today.

Naturally, Congress has noted the value of the approaches to cloud in virtually every annual National Defense Authorization Act over this timeframe. While we wait for a Senate-passed version of the Fiscal Year 2023 bill and a conferenced version later this year, we can look to the Senate and House Armed Services Committee reports for what is coming.

The Senate Armed Services Committee referenced DoD’s multi-cloud strategy in writing:

"The Department of Defense's decision to implement a cloud smart strategy and use a multi-cloud architecture that allows for portability and interoperability across multiple vendors is a positive development. The Department should use the latest cloud management software technology and enterprise-wide multi-cloud management principles that allow for applications, data, and programs to be portable and interoperable between public, private, and edge cloud environments while minimizing the cost and complexity of any unavoidable refactoring. Without such enabling multi-cloud management technology, the Department will not realize the benefits and operational efficiencies and security of a resilient multi-cloud architecture, which will lead to unnecessary stove-piping with potential national security concerns."

Similarly, the House Armed Services Committee noted:

"The Committee supports the Department’s decision to deploy a multi-cloud architecture. A multi-cloud approach aligns better with the Department’s mission and offers many benefits including allowing for more comprehensive future innovations, easier data portability, increased resilience and security, and decreased stove-piping. The Committee directs the Chief Information Officer of the Department of Defense to provide a briefing to the House Committee on Armed Services not later than March 31, 2023 on the strategy for future multi-cloud projects."

While DoD undertakes the effort to meet these requirements regarding multi-cloud approaches, the time is right to also consider the advantages of Security Information Event Management (SIEM) capabilities as applied to cloud. Among other benefits, a SIEM capability aims to centralize and aggregate all security-relevant events as they’re generated from their source, can add context and threat intelligence to security events, and ingest all data (users, applications) from cloud and on-premises sources and make them available for monitoring, alerting, investigation and adhoc searching, while reducing risk by enabling faster detection and incident response to newly discovered and ongoing threats with ready to use relevant content. By utilizing SIEM for cloud, DoD can quickly deploy, scale and consolidate all relevant security information in a single repository, ensuring that it’s protected, indexed and analyzed.

It is clear that commercial-off-the-shelf SIEM has tremendous benefits that lead to effective network security. This capability provides a single security management system that offers full visibility into activity within Department of Defense networks, thus allowing Security Operations Centers to respond to threats in real time. As the Department continues to increasingly transition to a software-as-a-service model, security must remain a key consideration in moving to the cloud.

The Department should explore expanding SIEM for higher sensitivity controlled unclassified information (CUI). Perhaps JFHQ-DODIN and the Military Services might conduct a pilot program for a commercial-off-the-shelf SIEM capability for impact level 5 (IL5), with JFHQ-DODIN aligning that effort with the security orchestration and automated response pilot activity that was directed in the National Defense Authorization Act for fiscal year 2022?

For more information, check out our "Take Your SIEM to the Cloud" whitepaper.

Related Articles

Know Your Customer Again
Industries
9 Minute Read

Know Your Customer Again

The Know Your Customer use case is always going to be at the forefront of any Financial Services Industries institution. Nimish Doshi will provide more details in this blog for a prescriptive path on using Splunk products for KYC.
EU AI ACT: KEY ISSUES TO WATCH
Industries
8 Minute Read

EU AI ACT: KEY ISSUES TO WATCH

The EU is currently developing one of the world’s first comprehensive regulations on Artificial Intelligence. Initially proposed in April 2021, the draft AI Act is now entering its last stage of negotiations, with the stated aim by policymakers to agree on a final text before the end of the year. Given the scope of the Regulation, and its likely impact in the EU and beyond, it’s an opportunity to review some of the key issues still in discussion and what they could mean for AI adoption and innovation in Europe.
Building a Resilient Future: Insights from Our Public Sector Community at .conf26
Industries
3 Minute Read

Building a Resilient Future: Insights from Our Public Sector Community at .conf26

.conf26 focused on driving real-world impact across the public sector.