Rapid Acquisition and Fielding for Information Assurance and Cyber Security in the Navy

Isaac R. Porche III, Shawn McKay, Megan McKernan, Robert W. Button, Bob Murphy, Kate Giglio, Elliot Axelband

ResearchPublished Dec 21, 2012

Identifying an agile and adaptable acquisition process that can field new information technology capabilities and services in relatively short and responsive time frames is a pressing issue for the U.S. Navy. Damaging malware can mutate within hours or days, requiring a defense that is sufficiently responsive to mitigate each variant. The Navy's Program Manager, Warfare (PMW) 130, an office in the Navy's Program Executive Office for Command, Control, Communications, Computers, and Intelligence, is focused on rapidly and proactively fielding innovative capabilities to stay ahead of cyber threats. It requires an acquisition and fielding cycle that can deliver hardware security products within 12–18 months, software security products within six to 12 months, and incremental development for both hardware and software every three months. These time frames are far shorter than the Navy's traditional acquisition cycle time, which can be 36 months from concept approval to initial operational capability or eight to ten years for full operational capability. With a focus on these goals, a RAND study sought to identify ways to accelerate or bypass the traditional acquisition process in response to the unique demands of PMW 130 information technology and cyber programs, with lessons derived from and recommendations applicable to programs across the U.S. Department of Defense.

Key Takeaways

Acquisition Processes for Information Technology and Cyber Capabilities in the U.S. Navy Need to Be Faster and More Adaptable

  • The Navy's traditional acquisition process takes far too long for information technology and cyber programs that must develop and field capabilities within very short time frames.
  • Navy programs in these areas require processes capable of handling two distinct processing speeds: one for all information systems and one for emergent needs.
  • The testing phase, as well as certification and accreditation, can cause significant delays for time-sensitive programs in the traditional acquisition process.
  • Successful rapid acquisition programs in the Army, Air Force, Marine Corps, and joint organizations offer lessons for the Navy as it develops its own streamlined processes for computer network defense and similar program areas.

Information Technology and Cyber Programs Require Stable Funding and Unique Governance and Authority Arrangements to Ensure Efficiency and Sustainability

  • New authorities at the program executive office and program manager levels are needed to better address the assessment, validation, sourcing, resourcing, and fielding of operationally driven urgent requests.
  • The current budgeting process takes too long. However, there are many potential funding sources outside the traditional process for incremental acquisition like that required for cyber programs. Certain initiatives might warrant dedicated budget lines.
  • On a related note, several contracting solutions are available to Navy programs that could be amenable to short cycle times, allowing programs to leverage the agility of the private sector.

Recommendations

  • The Navy should establish business rules that harmoniously allow two processing speeds for certification and accreditation packages for its Computer Network Defense program. It should also work directly with the required authorities to streamline acquisition, give more oversight to the program manager, allocate testing facilities to the organization that manages the program, and create a dedicated certification authority staff position.
  • The Navy's Program Manager, Warfare (PMW) 130, Information Assurance and Cyber Security Program Office, should be involved in changes to the Navy Modernization Process and make use of best practices to get through the process more quickly.
  • Navy programs that require rapid acquisition, particularly those involved with cyber issues, should ensure that they have a stable source of funding and that they have explored all available funding options. Similarly, they should investigate rapid contracting options, including incentives for contractors.
  • Throughout the Navy, programs would benefit from a culture that fosters agile governance and is responsive to the rapid-response needs of information technology programs. Thus, the Navy should implement continuous fielding strategies for these capabilities, focus on integrating authorities and processes, and ensure that processes are efficient and that funding is available to fulfill incremental upgrade needs that must be handled outside the traditional acquisition process.

Topics

Document Details

Citation

Chicago Manual of Style

Porche, Isaac R. III, Shawn McKay, Megan McKernan, Robert W. Button, Bob Murphy, Kate Giglio, and Elliot Axelband, Rapid Acquisition and Fielding for Information Assurance and Cyber Security in the Navy. Santa Monica, CA: RAND Corporation, 2012. https://www.rand.org/pubs/technical_reports/TR1294.html.
BibTeX RIS

This publication is part of the RAND technical report series. RAND technical reports, products of RAND from 2003 to 2011, presented research findings on a topic limited in scope or intended for a narrow audience; discussions of the methodology employed in research; literature reviews, survey instruments, modeling exercises, guidelines for practitioners and research professionals, and supporting documentation; and preliminary findings. All RAND technical reports were subject to rigorous peer review to ensure high standards for research quality and objectivity.

This document and trademark(s) contained herein are protected by law. This representation of RAND intellectual property is provided for noncommercial use only. Unauthorized posting of this publication online is prohibited; linking directly to this product page is encouraged. Permission is required from RAND to reproduce, or reuse in another form, any of its research documents for commercial purposes. For information on reprint and reuse permissions, please visit www.rand.org/pubs/permissions.

RAND is a nonprofit institution that helps improve policy and decisionmaking through research and analysis. RAND's publications do not necessarily reflect the opinions of its research clients and sponsors.