Editor’s Note: The Final Report of the Defense Science Board (DSB) Task Force on Resilient Military Systems is attached here.  Below is an excerpt of the Report’s Recommendations.

Recommendation: Protect the Nuclear Strike as a Deterrent (for existing nuclear armed states and existential cyber attack).

Recommendation: Determine the Mix of Cyber, Protected-Conventional, and Nuclear Capabilities Necessary for Assured Operation in the Face of a Full-Spectrum Adversary.

Recommendation: Refocus Intelligence Collection and Analysis to Understand Adversarial Cyber Capabilities, Plans and Intentions, and to Enable Counterstrategies.

In response to state-sponsored threats, the Task Force recommends the creation of a counterintelligence capability to directly address the most sophisticated threats using tools and techniques derived from both defensive and offensive U.S. cyber programs.

Recommendation: Build and Maintain World-Class Cyber Offensive Capabilities (with appropriate authorities).

Commander US CYBERCOM Develop a Capability to Model, War Game, Red Team and Eventually Train for Full Scale Peer-on-Peer Cyber Warfare.

USD(P) should establish a policy framework for Offensive Cyber Actions to include who has what authority (for specific actions), under what circumstances, under what controls.

Commander, US CYBERCOM to increase the number of qualified cyber warriors, and enlarge the cyber infrastructure commensurate with the size of the threat.

USD(P&R), in collaboration with the Commander, US CYBERCOM and the Service Chiefs establish a formal career path for DoD civilian and military personnel engaged in “Offensive Cyber Actions”

Recommendation: Enhance Defenses to Protect Against Low and Mid-Tier Threats.

Recommendation: Establish an enterprise security architecture, including appropriate “Building Codes and Standards”, that ensure the availability of enabling enterprise missions.  The architecture should allow for the ability to:

  • Segment the network
  • Provide continuous monitoring and situational awareness
  • Automate patch and threat management functions
  • Audit to the enterprise standard
  • Recover to a known (trusted) state
  • Provide out-of-band command and control for most sensitive systems

Recommendation: The DoD should leverage commercial technologies to automate portions of network maintenance and “real-time” mitigation of detected malware.

Recommendation: USD(P&R) should, incollaboration with the DoD CIO and the Service Chiefs, establish a formal career path for DoD civilian and military personnel engaged in cyber defense

Recommendation: Change DoD’s Culture Regarding Cyber and Cyber Security.

Establish a DoD-wide policy, communication, and education program to change the culture regarding cyber and cyber security

Recommendation: Build a Cyber Resilient Force.

DEPSECDEF should direct specific actions to introduce cyber resiliency requirements throughout DoD force structure.