Pentagon creating software 'do not buy' list to keep out Russia, China
WASHINGTON (Reuters) - The Pentagon is working on a software “do not buy” list to block vendors who use software code originating from Russia and China, a top Defense Department acquisitions official said on Friday.
FILE PHOTO: An aerial view of the Pentagon building in Washington, June 15, 2005. REUTERS/Jason Reed
Ellen Lord, the under secretary of defense for acquisition and sustainment, told reporters the Pentagon had been working for six months on a “do not buy” list of software vendors. The list is meant to help the Department of Defense’s acquisitions staff and industry partners avoid buying problematic code for the Pentagon and suppliers.
“What we are doing is making sure that we do not buy software that has Russian or Chinese provenance, for instance, and quite often that’s difficult to tell at first glance because of holding companies,” she told reporters gathered in a conference room near her Pentagon office.
The Pentagon has worked closely with the intelligence community, she said, adding “we have identified certain companies that do not operate in a way consistent with what we have for defense standards.”
Identifying these companies has meant that they are put on a list that is shared with the Pentagon’s acquisitions staff.
Lord did not provide any further details on the list.
Lord’s comments were made ahead of the likely passage of the Pentagon’s spending bill by Congress as early as next week. The bill contains provisions that would force technology companies to disclose if they allowed countries like China and Russia to examine the inner workings of software sold to the U.S. military.
The legislation was drafted after a Reuters investigation found that software makers allowed a Russian defense agency to hunt for vulnerabilities in software used by some agencies of the U.S. government, including the Pentagon and intelligence agencies.
Security experts said allowing Russian authorities to look into the internal workings of software, known as source code, could help adversaries like Moscow or Beijing to discover vulnerabilities they could exploit to more easily attack U.S. government systems.
She also said in the briefing that an upcoming report on the U.S. military supply chain will show that the Pentagon depends on Chinese components for some military equipment.
The industrial base report will show “there is a large focus on dependency on foreign countries for supply, and China figures very prominently.”
Reporting by Mike Stone; Editing by Chris Sanders and Bernadette Baum
Our Standards:The Thomson Reuters Trust Principles.