UNCLASSIFIED adoption, and optimization of its information domain. The DoD CIO is responsible for defining the security guidelines in the cloud environment. The risk and the responsibility for executing the security in the cloud environment is shared between the Cloud Service Provider(s) and the system owners. DoD CIO will identify the command and control (C2) requirements of the shared cybersecurity responsibility model between DoD and commercial vendors to ensure standard execution of C2 responsibilities for DoD information in commercial cloud. The specific requirements of securing a cloud environment will strain the traditional technical workforce and requires specialized skills where the Department currently has limited expertise. Historically, information security has been heavily focused on perimeter defense: limiting network access at the boundary. Unfortunately, this model is challenging for a commercial cloud environment where data is being accessed remotely and shared within and between deployments, regions, and from each Cloud Service Provider to other data locations, such as on-premises data centers at military installations. Therefore, the Department will shift its security focus from perimeter defense to securing data and services. This shift will be accomplished first through strong authentication for both people and machines and secure encryption mechanisms both at rest and in transit. In order to facilitate remote access, the DoD cloud environments will supply built­ in cryptographic technology that enables organizations to encrypt communications by default. Since the information security responsibility is shared between the Department and its Cloud Service Providers, the Department will include language in all cloud computing contracts directing Cloud Service Providers to monitor their cloud infrastructure and maintain authenticated, encrypted logging of security-relevant events that generate an audit trail and are engineered to be resistant to tampering. To address the workforce strain in adopting these new security postures, the Department will include cloud adoption assistance and specialized training for its workforce as a part of DoD Cloud Service Provider contracts. 2.4 Enable AI and Data Transparency DoD must enable decision makers to use modern data analytics, such as Al and machine learning (ML), at the speed of relevance to make time-critical decisions rapidly in the field to support lethality and enhanced operational efficiency. The algorithms used to inform decisions are dependent on the Department's data and information being organized, secure, and visible in a common environment. An environment where data is stored in a multitude of disparate and disjointed stove pipes reduces the efficiency and tempo ofthe Department. To maximize the utility ofcloud computing technologies, data must be managed properly and follow modern technologies like data lakes and data hubs, which are accelerated and amplified by cloud technology. Data stored in an enterprise DoD cloud will be highly available, well-governed, and secure. Data will be the fuel that powers those advanced technologies, such as ML and AL This critical decision making data will be made available through modem cloud networking, access control, and cross domain solutions to those who require access. Common data standards will be a key part of the Department's methodology for tagging, storing, accessing, and processing information. Ensuring an enterprise cloud environment will increase the transparency of this data, and drive the velocity of data analysis, processing, and decision making. Leveraging advances in commercial cloud security technologies will ensure the Department's information is protected at the appropriate level. Commercial cloud provides the ability to scale and secure both the collection and the analysis of data stored in an enterprise DoD cloud. This gives mission owners the capability to 5

Select target paragraph3