The Pentagon is working on a software ‘do not buy’ list to block vendors who use software code originating from Russia and China, a top defence department acquisitions official said on Friday.
Ellen Lord, the undersecretary of defence for acquisition and sustainment, told reporters the Pentagon had been working for six months on a ‘do not buy’ list of software vendors. The list is meant to help the department of defence’s acquisitions staff and industry partners avoid buying problematic code for the Pentagon and suppliers.
‘What we are doing is making sure that we do not buy software that has Russian or Chinese provenance, for instance, and quite often that’s difficult to tell at first glance because of holding companies,’ she told reporters gathered in a conference room near her Pentagon office.
The Pentagon has worked closely with the intelligence community, she said, adding ‘we have identified certain companies that do not operate in a way consistent with what we have for defence standards.’
Lord did not provide any further details on the list.
Lord’s comments were made ahead of the likely passage of the Pentagon’s spending bill by Congress as early as next week. The bill contains provisions that would force technology companies to disclose if they allowed countries like China and Russia to examine the inner workings of software sold to the US military.
The legislation was drafted after a Reuters investigation found that software makers allowed a Russian defense agency to hunt for vulnerabilities in software used by some agencies of the US government, including the Pentagon and intelligence agencies.
Security experts said allowing Russian authorities to look into the internal workings of software, known as source code, could help adversaries like Moscow or Beijing to discover vulnerabilities they could exploit to more easily attack US government systems.
Lord added an upcoming report on the US military supply chain will show that the Pentagon depends on foreign suppliers, including Chinese firms, for components in some military equipment.
She said the Pentagon also wants to strengthen its suppliers’ ability to withstand cyber attacks and will test their cyber security defences by attempting to hack them.
Want stories like this in your inbox?
Sign up to exclusive daily email
More Stories from North America