DOD to Fast-Track Vendor Software Certification, Official Says
//

DOD to Fast-Track Vendor Software Certification, Official Says

2 mins read

The Department of Defense is drafting a vendors’ criteria to fast-track the security approval of software that DOD agencies and military service branches can use. 

A request for information will be issued on the draft criteria to gather feedback about the proposed software security controls, Rob Vietmeyer, the department’s chief software officer, said during a recent episode of the Ask the CIO podcast of Federal News Network. He stressed that instituting an accelerated authority to operate, or ATO, is a top priority for the administration.

“We’re interested in, how do we raise our posture from a supply chain security controls perspective? So, we’re trying to find that interface,” the DOD official remarked.

CMMC and Other Template Criteria

Providing vendors with a set of security controls by which they can demonstrate the safety of their products and pipelines will lift the months-long burden from Pentagon on risk management framework assessments, Vietmeyer commented. He also said that the planned DOD guidelines on the accelerated ATO will draw learnings from the approaches on department’s Cybersecurity Maturity Model Certification, or CMMC, and similar certification efforts.

AI Application in DevSecOps

In addition to ensuring commercial software security, the DOD is eying artificial intelligence applications in its development, security and operations platform, under a new initiative with MITRE, the department’s CSO said.

“When we look at the DevSecOps pipeline, what we find is there are emerging AI capabilities that appear to provide very powerful capabilities for us to be able to accelerate the department’s journey through agile development and our ability to deliver resilient capabilities into the to the warfighter faster,” the DOD official explained.

Previous efforts on an AI role in DevSecOps include a partnership between Mattermost and Mobius Logic initiated in October 2023 for linkage with Microsoft suites including AI Services, Azure, Teams and Entra ID.