Back
Dana Deasy
Chief Information Digital Officer, Senior Vice President, Information Digital Technology & Security, Boeing

Dana Deasy Keynote 9-6-2018

🎥 Sep 06, 2018 📺 Billington CyberSecurity ⏱ 30m 👁 544 views
DOD CIO Dana Deasy delivered the opening keynote at the Billington CyberSecurity Summit on priorities of the Chief Information Officer at the Department of Defense
Watch on YouTube

About Dana Deasy

Dana Deasy, as the Department of Defense Chief Information Officer, has emphasized a digital modernization strategy built on four pillars: cloud, artificial intelligence, command and control communications, and next-generation cybersecurity. Speaking at several events in 2018 and 2019, he argued that AI would become "more than just a tool" and "a partner" to the warfighter, and described the Joint Artificial Intelligence Center as a vehicle for cross-service "national mission initiatives." He cited specific pilot projects, such as an algorithm to predict sand buildup in Black Hawk helicopter engines and the use of AI to map wildfire fire lines in real time, as examples of the technology’s potential. Deasy also stressed the need to reframe acquisition priorities from "cost, schedule and performance" to "security, cost, schedule and performance," calling security a "condition of doing business." He advocated for decentralizing compute power to the "tactical edge" and leveraging cloud to improve data and algorithm delivery to deployed forces. In addition, he described his approach to organizational leadership as leaving "your organization in a better place" with "enduring, sustainable" change, and noted that his early focus as DoD CIO was aligning his office with the National Defense Strategy.

Source: AI-verified profile updated from Dana Deasy's recent appearances. Browse all interviews →

Transcript (15 segments)
D
Dana Deasy0:00
Good morning, good morning all. Right, so I understand we've got sponsors here today. You can go out and visit them during the breaks. If you're really exciting, you can go down the first floor. I think there's a fashion show or some sort of clothing lined up down there. So I was gonna try to tell you the name of the place but I can't pronounce it. So, all right, well listen, thank you Tom for the very kind introduction. It's an absolute pleasure to be part of the ninth annual Billington Cybersecurity Summit. I'd like to thank Tom for giving me this opportunity to come and speak with you today, and for Margaret McDonald for organizing what everybody knows to be a first-class event. The agenda simply looks outstanding. I may be a bit biased in that Thomas Shelley, who works on my staff, is here participating in two panels, one on automation and one on innovation. I think we'll all agree these panels are very, very timely right now, and the panel lineups on who's participating looks phenomenal. I really wish I could stay all day and listen, as I'm sure there's a lot that I'll learn as well as all you will today. As you know, this is my first role in government as the DoD CIO. I find it incredibly unique and challenging. Now, if you'd asked me a year ago what I'd be doing, I would have never imagined it was working at the Pentagon. Earlier this year, I was enjoying retirement with my wife when I received a call from Deputy Secretary of Defense Shanahan asking me to come on board and be the department's next CIO. I was a bit surprised to say the least, but knew it was an opportunity I simply could not turn down, and my wife definitely agreed with me. Working alongside our service members and dedicated civilians at the department is truly an amazing honor. The opportunity to serve my country and help solve some of the greatest problems facing our country is something I take very, very seriously. Well, enough about me. Let's get down to talking about why I'm here. I'm sure you all want to hear about the future cyber direction for the department. First, a little level setting that I think might be helpful this morning. As you know, Secretary Mattis has three lines of effort in the National Defense Strategy that are paramount to everything that we do across the DoD. You can see these on the screen. They are: delivering lethality to the warfighters, continuing to foster and grow partnerships that cut across mission success, and enacting reforms that will maximize resources and minimize unnecessary risk. Now, as the CIO, I've identified four priorities to support Secretary Mattis's vision. These, shown behind me, are cloud, artificial intelligence, communications, command and control, or known as C3, and cybersecurity. The order of the topics is by no means the order of importance, but rather think of them as the order of integration. As you may have heard, we are developing a cloud enterprise capability at the department. The cloud will truly revolutionize the technology advances for our warfighter. Next, artificial intelligence is the agent of transformational change across the DoD. We must continue to research and develop new AI capabilities. Therefore, the department plans to stand up the Joint Artificial Intelligence Center, known as JAIC. The center will develop new AI capabilities and concepts that will support DoD's military missions and business functions. Now, next is C3 modernization, which is absolutely the key to successful mission assurance. Since we are now living in the digital age, we must have C3 systems that match the times. At the end of the day, we need the right communication at the right time to protect and enable the warfighter. Given that I am here today at a cyber conference, I suspect you'd like to hear more about our fourth area: cybersecurity. Cyber touches everything we do across the department. My mantra as I talk to people across the department is that we must have a cyber-first, cyber-always mindset in everything we do. Cybersecurity must be baked into every network, every system we develop, every piece of equipment that we acquire. As a matter of fact, when it comes to managing acquisition programs, I have been advocating changes inside the department from the phrase 'cost, schedule, and performance' to 'security, cost, schedule, and performance.' Whether a soldier downrange, a sailor at sea, a civilian in their offices around the world, we must all recognize that cybersecurity is not merely an IT problem. It is the responsibility of everyone to work together and practice good cyber hygiene to protect DoD systems and networks. Now, recently I was in traffic. Now that I moved to DC, I spend a heck of a lot more time in traffic, it seems, and thought to myself that cybersecurity is a lot like driving your car. When behind the wheel, you must be aware of all potential threats on the road ahead. You put your seatbelt on because it could save your life if you were to get into an accident. You must make sure your wipers work so you can see the road in a storm. You keep your eyes on the driving behaviors of the other drivers on the road. You must make sure to use Bluetooth so you can stay focused on driving, not finding your phone when it rings. As with driving, cyber threats are often unforeseen and unknown. Just like in a car, we want to avoid a crash, and cyber crashes can be devastating. Today, I would like to talk to you about a few of the key preventive measures that the department is leveraging. These measures are holistic, interwoven, and most importantly, focus on the entire ecosystem for the department, from endpoint security to comply-to-connect, to identity, credential, access management, and to our defense base, and finally, our people. First, starting with comply-to-connect. If you look at the graphic, you will see the first component is what we are calling comply-to-connect. We all know that networks are vulnerable to cyber threats. Operator defenders face a number of problems: they cannot defend what they can't see, cannot harden what they cannot find, may be late to remediate, and sometimes mitigations simply do not work. The operators and defenders will be more able to do their job if we know who and what is on our network at any time. While straightforward, we all know this is hard to do. Comply-to-connect will help the department identify and protect devices that are connected to the department's defense networking, and they will assure that they are automatically patched to ensure secure configurations. The changing nature of cyber threats requires we remain agile and ready. Next, I'd like to talk about ICAM. I have directed, and we are working on, an identity, credential, and access management strategy for the DoD that will replace a 2014 DoD identity and access management strategy. ICAM strategy will revolutionize how we create digital identities and the maintenance of associated attributes, including both people and non-person entities. ICAM creates a secure, trusted environment where any of our users can access all of the authorized resources, including applications and, of course, our valuable data to have a successful mission. It also will let us know who is on the network at any time. Now, I know what you're thinking. Most of you hear about identity credential management at DoD and what you think about is the Common Access Card, CAC. They have been a key component in DoD security. Some of you may have heard that the CAC is going away. Well, from my standpoint, the CAC will remain the department's principal authenticator for the foreseeable future. However, the department must be ready to adapt as we accommodate an environment where more than 4.5 million users, that is rapidly evolving due to current and emerging threats from our adversaries. Now, DoD has always been a pioneer when it comes to driving innovation. We must continue to do so and incorporate key storage and biometrics and prepare for a future where we need quantum-resistant cryptography. These innovations will become critical to ensure our warfighters continue to operate in a secure environment. Now, let's talk more about our defense industrial base. I know a large part of the audience today here is comprised of our industry partners. So first of all, a huge thank you for your attendance today. Many of you are likely familiar with the Defense Industrial Base, known as the DIB, cybersecurity program. Our DIB CS program is currently voluntary, yet critical, public-private information sharing program between the government and private industry. Voluntary organizations must follow the NIST standards for maintaining security. This program enables DoD to respond and mitigate threats from adversaries and ensure DoD information is protected. We must protect our information so our capabilities remain intact. Doing so will simply save the lives of men and women in uniform. Within the DIB is the DoD Cyber Crime Center, known as DC3, the operational focal point that allows DoD to share classified and unclassified cyber threats with the DIB. As of today, there are more than 300 cleared defense companies that participate in the DIB. Now, earlier this year, Deputy Secretary of Defense Shanahan highlighted the importance for the department to ensure that commercially provided products and services from industry are secure. The Deputy Shanahan said, and I quote, 'We want the bar to be set so high it will become the condition of doing business.' I cannot echo enough how much I agree with the Deputy's comments, because the security of systems and products we acquire are critical to our national defense. We have all read the headlines about exfiltration. We need to collectively up our game. Our standards to maintain and accountability needs to be held. We must do this as partners, and we all need the headlines to stop. Finally, I'd like to talk about people. I've talked about the importance of comply-to-connect and ICAM and partnerships, but the heart of everything and fundamental to all is the people. In 2016, Congress gave DoD the authority to create the Cyber Excepted Service, known as CES, that enables the department to manage our civilian cyber professionals, focusing on mission positions. CES allows for more agile recruitment of candidates and streamlined HR procedures and delivers market-competitive pay. Fortunately, we have been able to hire many very qualified people to fill our cyber positions. However, the department needs ways to continue to bring in the brightest minds. I'd like to think that all of you today are simply a recruiting arm extension for the department. Please help us to encourage young and smart digital natives to seek a job in government service. A couple of months ago, I had an absolute pleasure to spend some time with some college students who won a National Cyber Award. They were completely engaged, incredibly well-rounded, and very eager to hear what a cybersecurity job at the DoD looks like, feels like. Taking full advantage of the opportunity to do some real-time recruiting, we had a great conversation that day, and I remember it so well. They wanted to know about what the jobs looked like at the DoD, and I simply said, 'Working at the DoD is a calling. You are on a mission, and it is simply captivating.' It is clear that we must continue to recruit and retain an eager, motivated workforce that are not only driven to serve their country but also understand that the DoD mission is unlike any other. Maintaining a strong cyber workforce is paramount to the long-term success of protecting our country. In closing, I'd like to state we cannot do this alone. The integration of cloud, artificial intelligence, and C3 will only be fully successful with a robust cybersecurity environment. The long-term success of our warfighting capabilities depends not only on the diligence of our service members and our civilians but our allies and industry partners as well. Once again, Tom, thank you for inviting me to be part of the ninth annual Billington Cybersecurity Summit. It is a rare opportunity to bring together so many people that are as passionate as I am focused on the topic of cybersecurity. We are all here to secure the future of tomorrow, today. Thank you, and I believe we have some time here to take some questions from the audience this morning.
T
Tom Billington15:33
So I'd like to prompt you also for either a cue card, a mic which I can bring to you, or by note cards again, or in the middle of your table. We would welcome Q&A questions. And I'd like to start with one: could you elaborate further on the importance of end-to-end security?
D
Dana Deasy15:55
Yeah, could we put that chart back up that shows the end-to-end? Right there, you had it, perfect. Is this mic on? Are we good? Okay, so why I created this chart was, you could imagine the conversations are quite complicated inside the department when it comes to the topic of cyber, because depending on who you ask, what is the problem we're trying to solve for, you could get a very different response. So I know you're gonna hear from General Nakasone, and he's gonna give you a view of cyber from the offensive and defensive side. We talk to our DISA organization, they'll give you a view of how we think about cyber for protecting the network. Policy folks have their view. Heck, my own organization has their view. But what we didn't have was a way of describing this from an end-to-end. So what we've done is we spent some time creating a discussion that goes something like this: How do we ensure that the computer that somebody will sit down and use today should be on our network, it's properly configured to our standards, has been updated, has no malware? And if you can assure all that, how do we know then the person that's going to sit down at that computer is who they say they are? And if you can go through those processes, ensure they are who they say they are, they're most likely then going to sign on and use some form of an application. And signing on and using the application, how do we know that application was written in a way that makes it secure? So now they've signed on to a computer that should be compliant to connect to our environment, we've authenticated them, the application's good to go. That application's going to call upon data, and of course, in the Department of Defense, we have all types of data from unclassified to secret to top secret, and that data has to transcend and move across environments. So how do we make sure that all that is done? That person sitting at that system that we now think is secure, we've identified that person, using a secure application, and the data is encrypted and properly classified, could actually be supporting all the way out to an endpoint weapon system. Then we have to ask ourselves, how do we ensure the weapon systems, how they were built, designed, maintained, are secure? And then you sit there and say, well, why wouldn't the same standards that we apply to ourselves, shouldn't we be applying that to the defense industrial base? And then finally, all of this is for naught if we don't have methods to improve the critical infrastructure protection inside the US. So we have this conversation. What I always tell people, you can't have it at any one point. You have to discuss the entire ecosystem of cybersecurity. So Tom, that's what I'm referring to in that matter.
T
Tom Billington19:15
High in cybersecurity, could you talk a little bit about supply chain? I'm sure you're aware the White House is working on an executive order on supply chain. How is DoD interacting with other federal agencies on securing the supply chain?
D
Dana Deasy19:32
So to say the least, there is obviously a lot of active conversation across all agencies when it comes to supply chain. I think what's important here is this is a problem that both government needs to solve as well as private industry. So let's talk about the government side first. Coming from private industry and spending a number of years in sectors such as the energy sector and the financial services sector, I always was on the other side of this equation around how do we make sure from a private sector that we were getting all the support we could possibly need from the government. And that usually came in the form of a couple key things: how can we pass on indicators to the right government agencies that could give us back timely responses that then we could take appropriate action on? Well, that leads to the government to have to work across agencies in a much different way. To that end, we have a program right now where the Department of Defense, in support of Homeland Security, is working with the financial services sector right now to create a much more improved way that we can collect data from the financial services sector, bring it in through DHS, allow us to look at it, comment in an unclassified way, send the results back in a way that allows the private industry to act on it in a much quicker fashion. This is a template approach. This is the pathfinder we're doing right now, and it's starting to bear some really interesting results in terms of the volume of data we can take in, the speed of which we can read it, recognize it, and then send information back out that allows the financial industry to take action on it. We're going to be rolling this out to other critical infrastructure sectors as well, including Department of Energy, transportation, etc.
T
Tom Billington21:35
Thank you very much. We have several on the note cards. Mention is, can you tell us what DoD is doing to protect information vulnerable from the Internet of Things devices?
D
Dana Deasy21:49
Well, you have several components in that conversation. One is where are they coming from and how well do we understand the makeup of those devices. Those devices will obviously have two key components that will be made up of a series of the physical components, and it's the recognition that today supply chain around the world requires us to have a much better understanding of where the physical components are being manufactured and how they're being integrated together. And then you have a whole new complexity in how do you think about the software, not only in the component itself, but more importantly, as we know, the Internet of Things is really about a master integration of how do you bring sensors and intel together, aggregate that, then to take decisions and actions against it. So I think it's similar to the other conversation in that a more holistic way of thinking about the Internet of Things is gonna have to happen, just like I described to you how we think about the Department of Defense. That starts way back in the original fabrication, the integration of those devices, the software that is built for those devices, and then the integration software that brings the Internet of Things together. It allows you to then take decisions.
T
Tom Billington23:14
Thank you very much again. The room is open for live mic. I'll walk over here. And before I do, I'd like to ask about the recruitment and retention of the best and brightest. One attendee asks: what is being done to tap the best and brightest at, for instance, US military academies, West Point and Annapolis, and the like?
D
Dana Deasy23:37
So I'll give you part of this, and I'm gonna let Tom speak on the other half of this since it's the topic that he's working quite closely on. So I've spent a fair amount of time with the secretaries, under secretaries, and military chiefs on this topic of how do we think about what the next future leaders of the Department of Defense are going to need to look like. And everybody has absolute consensus on the fact that we are growing up in an era where I call the digital natives. These are people being born today where all they know and think of is a digital world, but yet we have to bridge that with the world of people who haven't always grown up with digital. And so there's a lot about how do we incorporate into the various programs across the Department of Defense, whether that be the Naval Academy, West Point, etc., how do we create a curriculum that starts to not only create cyber workforce warriors of the future, but just as important, how do you take the leaders of the day and make sure that they understand fully the breadth and the depth of the problems and the complexities that the adversaries are confronting us with today as well. Tom, did you want to add anything on that topic?
T
Tom Billington24:55
So I can firstly talk about the military, and I'll talk about where I recently came from, the US Coast Guard, one of the greatest organizations on the planet. The Coast Guard recognized that cyber is going to be important in all its missions. So for the first time ever, they have got a track where a cadet coming out of the Academy can go right into a cyber billet as opposed to going to sea first. Huge sea change, no pun intended, for the US Coast Guard. So I think the point is all the academies have recognized it. All the MSs set up cyber centers. There are a lot of competitions amongst academies, so moving very forward, very fast with that precious resource we have in the country. Secondly, on the military side, Congress recently gave us authorities to bring in people like we've never had before. So for example, I was at a reception last night with Billington with General McGee, who's one of his responsibilities is how do we bring in non-traditional folks from outside in. So for example, we could bring somebody in and assess them as a colonel or an O-6 right off the street. We're looking into that on the military side. And the civilian side, Congress also gave us authorities for the Cyber Excepted Workforce. We just completed phase one pilot. This gives us the ability to provide market-comparable market rates to our employees, amongst other things, about speedy hiring. Phase one was my shop in the Department of Defense CIO cybersecurity shop, as well as Joint Force Headquarters DODIN and US Cyber Command headquarters. One of the capstones of that pilot was a cyber fair that was held up at Fort Meade a few months ago. They brought people off the street and were able to hire people on the spot, which if you've ever been in government, is unique and exciting. Phase two starts this coming year, and we're gonna roll it out to the service cyber components as well as all of DISA.
M
Matt Beinart26:59
Okay, Matt Beinart from Defense Daily. I was just wondering, I know the deadline for proposals for JEDI was just extended. I was wondering, one, what was behind that decision, and then, with the extended deadline, do you now expect a contract to be awarded?
D
Dana Deasy27:21
Yeah, so, you know, you wouldn't be surprised if you heard me say this is a case I'm sure you all appreciate we're in the middle of an active RFP process. So it's really not appropriate for me to comment on when we'll be done with the process or the process itself. I can simply tell you, in any RFP, when you go through the initial phases of putting an RFP out on the street, you have a number of questions that come in. Those questions allow you a period of time to provide further clarifications. And sometimes, in providing the clarifications, it makes sense to provide some additional time for people to respond once you provide those clarifications, which is simply the case that's taking place here.
T
Tom Billington28:06
What one last very quick question. Having moved from CIO at JPMorgan now to CIO at DoD, any advice to industry in the room?
D
Dana Deasy28:12
You know, there is a part of it that the advice is the same, especially if you yourself are in a role where you look to your suppliers and partners to help you. What always helps me best is when I have suppliers and partners that come understand what it is we're trying to solve for. You can talk in our language. So I've stood up here today and I've told you about how we're thinking about cyber. It's inside a broader strategy called cloud and AI. And I always find it extremely helpful when the conversation can be fit around our particular strategy. So often people want to come and have a conversation with me about something that's not connected with what we're trying to solve for. And so my biggest advice I always give to people is make sure when you have those conversations that you keep them connected. I think the other thing I would say is the one thing that's incredibly different for me, and I was in the private sector for almost 37 years, is that the nature of what I find myself doing here every day. I used the expression in my speech earlier where I said I told the young people that we met with, this is a calling more than a job. And it really is. If you think about what it is we do every day, when I walk to the building and I see the young men and women that are serving our country, I never come to work and think about the job I have to do from 8 a.m. to 6 p.m. I think about the purpose and the mission. And it's really simple. All you have to do is walk the hallways of the Pentagon. It's very, very clear why you're there. That is the number one message I give people when they think about, do I want to come and serve and work in government, is it really is a calling and it really is so inspirational. And I feel very fortunate and proud that at least during my career, I've had an opportunity to come and serve the nation. Thank you.
T
Tom Billington30:33
Mr. Deasy, thank you very much for pursuing that calling on our behalf. I'm very now very excited now about...