UNCLASSIFIED
utilization when compared to traditional IT infrastructure that is constantly in use, even when
demand is minimal. This efficiency will also eventually improve the government's budgeting,
billing, and payment practices by providing detailed resource usage reports for all mission owners.
This transparency will further drive more efficiencies in the future on how applications are built.
Additionally, the cloud pay-for-use model will provide the flexibility to optimize costs
across the IT portfolio and allow DoD to adapt to changing priorities, budgetary conditions, and
industry developments. To achieve this cost transparency, strong governance will need to be put
in place for how applications are built and data is transmitted and stored. As we develop these
standards, implement them, and subsequently learn and better align our services and data to an
enterprise solution, we can look to automated tools and techniques to better inform accurate
tracking of financial execution of cloud resources.
2.3 Proactively Address Cyber Challenges
DoD must create a standard cloud-based cyber architecture that addresses the needs of
commercial and internal-based clouds and encompasses infrastructure, applications, and data. This
must include the ability to keep the environment "evergreen" in terms of security and technology.
DoD will produce a unified cybersecurity architecture that addresses cloud and the needs
of classified and unclassified missions and data. The capabilities will be tested and assessed
independently and frequently to ensure that cybersecurity attributes remain effective against
developing threats.
DoD must embrace modern security mechanisms built into modern commercial cloud
providers' platforms to ensure the security of these large amounts of data and to safeguard the
information. This requires shifting the focus of security from the perimeter edge of the network to
actively controlling use of the data itself. In addition to modern encryption algorithms and key
management built into commercial cloud services, proper tagging of data will allow for it to be
tracked and protected at the necessary levels. DoD will develop a Data Management Strategy that
provides the focused discussion with respect to data.
In addition to DoD data security, each Cloud Service Provider will be integral to combating
cyber challenges and securing the cloud. The Cloud Service Providers will automatically scan
infrastructure resources and generated logs, which will be used to identify vulnerabilities early and
to make intrusion detection and mitigation in near-real time a reality across much ofthe enterprise.
With the rise of hardware vulnerabilities, such as Spectre, and increased insider threat, a focus
must be applied to both software and hardware- which change at an incredible pace. Keeping up
with those changes is difficult, but failure to keep pace has created significant security risks and
will only increase in the years to come. Here, again, modern commercial providers have addressed
this problem. Moving infrastructure from DoD-managed, on-premises facilities to the cloud will
take advantage ofthe rapid roll out ofsoftware and hardware updates. Cloud Service Providers are
able to shift workloads within their data centers such that updates are seamless to customers.
Hardware with defects or vulnerabilities is constantly swapped out and software patches are
applied with vigor in a secure and fault tolerant manner.
Although commercial cloud has many security advantages and opportunities for the
Department, the transition to the commercial cloud environment also presents new security
challenges. The transition from traditional IT management to the managed cloud service model
alters the balance of visibility and control with ease of use, automation, leading edge technology
4