home > news > article

Gen. Cartwright Q&A (Web Extra)
Following are additional questions and answers from an interview with Gen. James E. Cartwright, commander of the Strategic Command, that appeared in the January/February 2007 issue of DEFENSE SYSTEMS.
DEFENSE SYSTEMS: How big of an issue is cybersecurity?
CARTWRIGHT: The issue for the department over the last year has been to build an organization that finds the right balance between offensive and defensive cyber capabilities.
Historically, a balance between offense and defense is where you want to be. For America, we have historically chosen to build an offense that was layered and pushed off of our shores in order to solve problems before they became problems at home.
Cybersecurity today, Cartwrights rendition of it, is you log on to your laptop. You probably have a firewall or something and you put information on it. If somebody gets into your computer with a worm or a virus, it usually gets detected for you, and youre one of hundreds or thousands that are infected and you wait two to six weeks for Microsoft to give you a patch. Meantime, everything that was on your laptop is now exposed to the world and vulnerable. And if whats on your laptop is a competitive edge, youre giving up your competitive edge for that period of time.
Industry has now included that in their calculus of profit and advantage. But there comes a point at which you cannot afford to only defend and wait two to six weeks for a patch. Youre giving up too much competitive edge or resources, and until youre willing to push outside of your computer to a larger interface and collective defense, youve now reduced the cost of losing your competitive edge and you keep making a business case. The problem right now is that were on the Whack a Mole side of this game. A virus pops up, we smack it, and then over two to six weeks deploy a patch and accept the cost of the loss. At some point, you cant accept that loss anymore. Thats when you have to turn to a new strategy. That strategy could be to deploy capability farther from your boundaries.
For DOD, we have four armed services, and thats just a small part of it but they are the major contributors, and inside those services they have thousands of networks. None was visible to the services.
Not one was configured in a way that you would say, gosh, if this virus affected me here, how would I know who else it affects? We had no visibility. So we began getting the services to clean up these issues. Then we realized that the Defense perimeter has to be farther out, so JTF-GNO (Joint Task Force for Global Network Operations) was put in place to say anything that is .mil really needs be collectively defended so that we dont give up our competitive edge. We must become more responsive so that we detect problems before they become problems. That is our ultimate goal: to fix things in real time. Were not anywhere near there yet. Were still dealing with four completely different systems and eventually we have to integrate them. They dont have to be the same, but you must have the visibility so that the implication of a problem here is understood over there.
DEFENSE SYSTEMS: What power does JTF-GNO have? Do the services listen to it?
CARTWRIGHT: That was the whole issue. That was what STRATCOM took on with JTF-GNO, and when you start something like this bureaucracies tend to mandate.
I like the Disney principle a little bit more. Build a compelling argumentif youve got a line at your ride then build/scale it up. If nobody lines up at your ride, kill it. GNO was put together that way. We showed compelling reasons to any customer why GNO could defend their networks better than they could. Then we said what you really ought to do is organize your network this way. Well show you how to add valueso what they have done over the past two years is add value in a compelling way that doesnt mandate that anybody has to come on board. Once the customer sees the value, they will move toward a behavior (what kind of behavior?). You can write all the rules and regulations you want to afterward, which is what theyre actually doing now. Theyre starting to say, OK, whats the next rule if we demonstrate to everybody that if we put this in place itll make a big difference, and thats the way GNO sold itself.
Navy Rear Adm. Betsy Hight (deputy director of JTF-GNO) is an incredibly capable officer and has a way of explaining to people and showing them value and then having them come solicit her organizations help rather than the other way around. And as a person and as a command, I prefer to go show value and then let people go write the rules rather than write the rules and say you must do what STRATCOM tells you. The other way aroundhere is something thats really valuable, would you sign up for this? Would you wait in line, would you subscribe to me? If you will, then I think Ive found the niche and Im going to push at it and then Ill make the ride as big as the line gets. So thats the way JTF-GNO has moved.
But what were trying to do now is understand the limits of technology as it exists today, the limits of culture, and how exclusive are you willing to let people be? How much of it should be done with a firewall on your computer and how much of it do you want to have done in the larger domains at our coastlines, at our interfaces with the rest of the Internet world, etc.?
DEFENSE SYSTEMS: What are your thoughts regarding the current shape and structure of the military services?
CARTWRIGHT: There are a couple of different ways to approach this. The first is the skills and the tools that we give to the people have to enable them to operate in a much more diverse world. The good news is that most of it comes through IT-type things and most of the soldiers, sailors, airmen and Marines are very comfortable and enabled in that environment. They still have needs, but are very effective in doing that.
What you see from the constructs that we call the Future Combat Systems for the Armydistributed operations I think is the term that is the Marines are starting to use; and in the Navy its swarmwere really moving toward things that talk about surge and disaggregated activities that are widely separated but are then filed down. It means, that with either land forces or sea power, as the threat is diminished, your tentacles get farther and farther out. As the threat increases, you draw them in and aggregate the capabilities as appropriate for the threat. And so you move from a very dispersed mindset to a more aggregated mindset over time. Lets take Future Combat Systems in the Army. What youre looking to do is to quickly mask fires and capabilities for a problem and then disperse them as soon as the problem is over, then back out and move into the tentacles.
What youre looking for is that cultural awareness, that one-on-one interface with somebody that gives you the greatest understanding of each others problems. And you want as much of that as possible. But as the threat starts to rise, you start to pull back and build your defensive perimeters, your layering, and your capabilities and then the Army, the Marines and the Air Force are all starting to move in a direction because they have to cover so much more territory. So youve got to train now and find the skill sets and the technologies that allow you to do that as a military. Thats the challenge.
Another challenge is that, to an extent, manpower has been a commodity that, particularly when we had a conscription force, was almost treated as free. Now, people who pay the bills would never think of it that way, but you looked at it as if, OK, my pay is assumed, now I need to build a tank or a ship. The reality of an all-volunteer force is that youre looking for a slightly older force. I dont mean that as a pejorative, but a force thats got a little more experience in the supervisory ranks; a force thats better educatedand as you do that, the cost of people becomes a driver and its not assumed as free.
And then you have all of these diversity pressures, diversity of the threat, the larger area youve got to cover, and now youre paying a premium for your manpower, too. So how do these tensions resolve themselves for the service chiefs as they try to build a force for the combatant commanders to deploy? I think those are the tensions that are out there for the services. They are going to have to work their way through health care costs, education costs, the ability to retain these quality people longer; all these add to the expense of an individual that your operations and maintenance resources would start to drain off your modernization resources.
Im not a service chief. But from my eyes, thats what I see.

|