An official website of the United States government
A .gov website belongs to an official government organization in the United States.
A lock (lock ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

In the News

News | Nov. 29, 2022

DOD Releases Path to Cyber Security Through Zero Trust Architecture

By C. Todd Lopez DOD News

WASHINGTON -- The Defense Department on Tuesday released its Zero Trust Strategy and Roadmap, which spells out how it plans to move beyond traditional network security methods to achieve reduced network attack surfaces, enable risk management and effective data-sharing in partnership environments, and contain and remediate adversary activities over the next five years.

"Zero trust is a framework for moving beyond relying on perimeter-based cybersecurity defense tools alone and basically assuming that breach has occurred within our boundary and responding accordingly," David McKeown, the department's acting chief information officer, said.

McKeown said the department has spent a year now developing the plans to get the department to a zero trust architecture by fiscal year 2027. Included in that effort was development of a Zero Trust Portfolio Management Office, which stood up earlier this year.

"With the publication of this strategy we have articulated the 'how' that can address clear outcomes of how to get to zero trust — and not only accelerated technology adoption, as discussed, but also a culture of zero trust at DOD and an integrated approach at the department and the component levels."

Getting the Defense Department to reach the goals laid out in the Zero Trust Strategy and Roadmap will be an "ambitious undertaking," McKeown said.

Ensuring that work will largely be the responsibility of Randy Resnick, who serves as the director of the Zero Trust Portfolio Management Office.

"With zero trust, we are assuming that a network is already compromised," Resnick said. "And through recurring user authentication and authorization, we will thwart and frustrate an adversary from moving through a network and also quickly identify them and mitigate damage and the vulnerability they may have exploited."

Spotlight: Engineering in the DOD

Resnick explained the difference between a zero trust architecture and security on the network today, which assumes a level of trust for anybody already inside the network.
"If we compare this to our home security, we could say that we traditionally lock our windows and doors and that only those with the key can gain access," he said. "With zero trust, we have identified the items of value within the house and we place guards and locks within each one of those items inside the house. This is the level of security that we need to counter sophisticated cyber adversaries."

The Zero Trust Strategy and Roadmap outlines four high-level and integrated strategic goals that define what the department will do to achieve that level of security. These include:

  • Zero Trust Cultural Adoption — All DOD personnel understand and are aware, trained, and committed to a zero trust mindset and culture to support integration of zero trust.
  • DOD information Systems Secured and Defended — Cybersecurity practices incorporate and operationalize zero trust in new and legacy systems.
  • Technology Acceleration — Technologies deploy at a pace equal to or exceeding industry advancements.
  • Zero Trust Enablement — Department- and component-level processes, policies, and funding are synchronized with zero trust principles and approaches.

Resnick said development of the Zero Trust Strategy and Roadmap was done in collaboration with the National Security Agency, the Defense Information Systems Agency, the Defense Manpower Data Center, U.S. Cyber Command and the military services.

The department and its partners worked together to develop a total of 45 capabilities and more than 100 activities derived from those capabilities, many of which the department and components will be expected to be involved in as part of successfully achieving baseline, or "target level" compliance with zero trust architecture within the five-year timeline, Resnick said.

"Each capability, the 45 capabilities, resides either within what we're calling 'target,' or 'advanced' levels of zero trust," he said. "DOD zero trust target level is deemed to be the required minimum set of zero trust capability outcomes and activities necessary to secure and protect the department's data, applications, assets and services, to manage risks from all cyber threats to the Department of Defense."

Across the department, every agency will be expected to comply with the target level implementation outlined in the Zero Trust Strategy and Roadmap. Only a few might be expected to achieve the more advanced level.

"If you're a national security system, we may require the advanced level for those systems," McKeown said. "But advanced really isn't necessary for literally every system out there. We have an aggressive goal getting to 'targeted' by 2027. And we want to encourage those who have a greater need to secure their data to adopt this advanced level."

Resnick said achieving the target level of zero trust isn't equivalent to a lower standard for network security.

"We defined target as that level of ability where we're actually containing, slowing down or stopping the adversary from exploiting our networks," he said. "Compared to today, where an adversary could do an attack and then go laterally through the network, frequently under the noise floor of detection, with zero trust that's not going to be possible."

By 2027, Resnick said, the department will be better poised to prevent adversaries from attacking the DOD network and minimize damage if it does occur.

"The target level of zero trust is going to be that ability to contain the adversary, prevent their freedom of movement, from not only going laterally but being able to even see the network, to enumerate the network, and to even try to exploit the network," he said.

If later on more is needed, he said, the requirements for meeting the target level of compliance can be adjusted.

"Target will always remain that level to which we're seeing and stopping the adversary," he said. "And for the majority of the DOD, that's really our goal."

Social Media Feed

X post
Today, the @DeptofWar CIO launched our Cybersecurity Awareness Month campaign. The initiative re-arms our warfighters, workforce, and the Defense Industrial Base on being "Brilliant at the Basics" by reinforcing core cybersecurity fundamentals across both Information Technology https://t.co/QBWbNPHzff
X post
Congratulations to Cheri Benedict, Cyber Supply Chain Advisor to the Federal CISO and Director of the Federal Acquisition Security Council (FASC), OMB, on her retirement after nearly 30 years of dedicated service to our nation. Yesterday, Marci McCarthy, Director of External https://t.co/DHjpMRxm9i Congratulations to Cheri Benedict, Cyber Supply Chain Advisor to the Federal CISO and Director of the Federal Acquisition Security Council (FASC), OMB, on her retirement after nearly 30 years of dedicated service to our nation. 

Yesterday, Marci McCarthy, Director of External https://t.co/DHjpMRxm9i
X post
Building the nation’s cyber workforce starts with connecting education to operational need. At the 2026 National Cyber Summit in Huntsville, Alabama, the @DeptofWar Cyber Workforce Innovation and Academic Engagement team advanced academic partnerships to explore how education, https://t.co/LQ7CeKLvHH Building the nation’s cyber workforce starts with connecting education to operational need. At the 2026 National Cyber Summit in Huntsville, Alabama, the @DeptofWar Cyber Workforce Innovation and Academic Engagement team advanced academic partnerships to explore how education, https://t.co/LQ7CeKLvHH
X post
This is why robust transport and edge computing are so important for @DeptofWar. Great article about how the 25th Infantry Division is pushing "the common operational picture from the cloud to the tactical edge" and transforming their command-and-control systems in the dirt. As
X post
How is the @DeptofWar advancing cyber lethality? At Hammercon 2026 at the Johns Hopkins Applied Physics Lab, over 500 defense, industry, and academic leaders gathered to discuss the latest in cyber operations, training, and recruiting. Mr. Mark Gorak, Mr. Matt Isnor, and Ms. https://t.co/CrvNoI3TuI How is the @DeptofWar advancing cyber lethality? At Hammercon 2026 at the Johns Hopkins Applied Physics Lab, over 500 defense, industry, and academic leaders gathered to discuss the latest in cyber operations, training, and recruiting.

Mr. Mark Gorak, Mr. Matt Isnor, and Ms. https://t.co/CrvNoI3TuI
X post
This week, the @DeptofWar CIO Cyber Workforce and Academic Engagement teams attended the SANS Institute’s Capitol Hill Cyber Workforce Forum to share best practices and discuss how the DoW is strengthening today’s cyber workforce and building the talent pipeline for tomorrow. We https://t.co/mmquBZi0Ds This week, the @DeptofWar CIO Cyber Workforce and Academic Engagement teams attended the SANS Institute’s Capitol Hill Cyber Workforce Forum to share best practices and discuss how the DoW is strengthening today’s cyber workforce and building the talent pipeline for tomorrow.

We https://t.co/mmquBZi0Ds
X post
Get your applications ready! The @DeptofWar Cyber Service Academy scholarship program (CSA) will be accepting applications starting Oct. 1. If you are accepted into the program, the DoW will provide you with tuition, room and board, a stipend, and paid summer internships, all https://t.co/r82MTUx2vd Get your applications ready! The @DeptofWar Cyber Service Academy scholarship program (CSA) will be accepting applications starting Oct. 1. 

If you are accepted into the program, the DoW will provide you with tuition, room and board, a stipend, and paid summer internships, all https://t.co/r82MTUx2vd
X post
Building the cyber defense of tomorrow requires a united front across industry, academia & government. Heading to the National Cyber Summit in Huntsville, AL? Join leaders from the @DeptofWar CIO for a fast-paced series of lightning round presentations designed to share how our https://t.co/ktejmkpjlN Building the cyber defense of tomorrow requires a united front across industry, academia & government.

Heading to the National Cyber Summit in Huntsville, AL? Join leaders from the @DeptofWar CIO for a fast-paced series of lightning round presentations designed to share how our https://t.co/ktejmkpjlN
X post
Transforming and securing the @DeptofWar digital ecosystem is an active, ongoing mission that requires continuous innovation. Today, @DoWCIODavies officially opened nominations for the 26th Annual CIO Awards to spotlight those who drive cybersecurity and empower our warfighters https://t.co/xiOXHHi0GA Transforming and securing the @DeptofWar digital ecosystem is an active, ongoing mission that requires continuous innovation.  Today, @DoWCIODavies officially opened nominations for the 26th Annual CIO Awards to spotlight those who drive cybersecurity and empower our warfighters https://t.co/xiOXHHi0GA
X post
At the Billington Cybersecurity Summit, @DeptofWar CIO Kirsten Davies discussed how the Department is accelerating our work to cut the red tape, reform our tools and optimize the acquisition and approval processes to deliver capability to the Warfighter faster and more https://t.co/WS5uwxEZOA
X post
At the Billington Cybersecurity Summit, @DeptofWar CIO Kirsten Davies discussed the challenges of network scale as we work to increase warfighter lethality. “When we think about this at scale, we have things that could break…so it’s not just one problem or the other, it’s a https://t.co/TRVcpyAT45
X post
Digital dominance requires seamless interoperability with our closest allies. The @DeptofWar CIO Hon. Kirsten Davies hosted Australian Secretary of Defence Meghan Quinn to advance critical defense priorities: AI implementation, Program Arcadia, secure communications, and https://t.co/bYYekuKgGK Digital dominance requires seamless interoperability with our closest allies.

The @DeptofWar CIO Hon. Kirsten Davies hosted Australian Secretary of Defence Meghan Quinn to advance critical defense priorities: AI implementation, Program Arcadia, secure communications, and https://t.co/bYYekuKgGK
X post
The events of September 11 remain forever etched into our hearts. The Department of War and the Office of the CIO remember every life taken and stand with the families who carry their legacy forward. This solemn 25th anniversary reinforces our sacred obligation to remain https://t.co/6c1L7iOLzi The events of September 11 remain forever etched into our hearts.

The Department of War and the Office of the CIO remember every life taken and stand with the families who carry their legacy forward. This solemn 25th anniversary reinforces our sacred obligation to remain https://t.co/6c1L7iOLzi
X post
DoW CIO Hon. Kirsten Davies took the stage with Alexis Bonnell of @OpenAI for a high-impact fireside chat at Billington Cybersecurity's record-breaking summit, discussing how @DeptofWar is modernizing and transforming its IT and cyber enterprise—cutting friction, delivering https://t.co/mzhWtfzV6s DoW CIO Hon. Kirsten Davies took the stage with Alexis Bonnell of @OpenAI for a high-impact fireside chat at Billington Cybersecurity's record-breaking summit, discussing how @DeptofWar is modernizing and transforming its IT and cyber enterprise—cutting friction, delivering https://t.co/mzhWtfzV6s
X post
The @DeptofWar CIO continues evaluating public and industry input on CMMC reform. Recent listening sessions and RFI submissions underscore that inconsistent government CUI designation and portion markings introduce friction across the industrial base. Addressing information https://t.co/QtSAPFY3GN The @DeptofWar CIO continues evaluating public and industry input on CMMC reform. Recent listening sessions and RFI submissions underscore that inconsistent government CUI designation and portion markings introduce friction across the industrial base. Addressing information https://t.co/QtSAPFY3GN
X post
What an amazing event! Congratulations to the grant winners in the DIBX Pitch Competition, your innovation and success is a great example for all of us. Thank you to Mr. James Mismash and the DIB leaders who attended Hon. Davies fireside chat and provided your insights during our https://t.co/WruW6BjPqY
X post
Engaging more than 4,000 military and civilian leaders at DAFITC, the DoW CIO team conducted a live skills-based assessment evaluating over 150 Airmen, Guardians, and cyber civilians across critical defense roles. Objective evaluations ensure precise talent alignment across the https://t.co/4KIQbSDjJ6 Engaging more than 4,000 military and civilian leaders at DAFITC, the DoW CIO team conducted a live skills-based assessment evaluating over 150 Airmen, Guardians, and cyber civilians across critical defense roles. Objective evaluations ensure precise talent alignment across the https://t.co/4KIQbSDjJ6
X post
At TechNet Augusta, the DoW CIO team engaged with Army, industry, and academic partners to advance skills-based hiring for the @DeptofWar cyber workforce. Discussions with @AUG_University and University of South Carolina Aiken focused on aligning cyber curricula with defense https://t.co/dqf60SXBqt At TechNet Augusta, the DoW CIO team engaged with Army, industry, and academic partners to advance skills-based hiring for the @DeptofWar cyber workforce. Discussions with @AUG_University and University of South Carolina Aiken focused on aligning cyber curricula with defense https://t.co/dqf60SXBqt
X post
The @DeptofWar CIO’s Director of DIB Operations, Cynthia Carpenter, and Director of External Engagement, Marci McCarthy, hosted a collaborative CMMC listening session at yesterday's #DIBX Conference. 60+ defense leaders discussed lowering barriers for small/medium DIB firms, https://t.co/sKL9b9jTxl The @DeptofWar CIO’s Director of DIB Operations, Cynthia Carpenter, and Director of External Engagement, Marci McCarthy, hosted a collaborative CMMC listening session at yesterday's #DIBX Conference.

60+ defense leaders discussed lowering barriers for small/medium DIB firms, https://t.co/sKL9b9jTxl
X post
National security demands agility, yet legacy compliance processes stall progress. The math simply does not math. Yesterday at the DIBX conference, @DeptofWar CIO Hon. Kirsten Davies and DASW IBG James Mismash, (@BusinessDefense) engaged in a highly dynamic fireside chat on https://t.co/BklolOniJ9 National security demands agility, yet legacy compliance processes stall progress. The math simply does not math. Yesterday at the DIBX conference, @DeptofWar CIO Hon. Kirsten Davies and DASW IBG James Mismash, (@BusinessDefense) engaged in a highly dynamic fireside chat on https://t.co/BklolOniJ9
See us on X
13,206
Follow Us