UNCLASSIFIED
adoption, and optimization of its information domain. The DoD CIO is responsible for defining
the security guidelines in the cloud environment. The risk and the responsibility for executing the
security in the cloud environment is shared between the Cloud Service Provider(s) and the system
owners. DoD CIO will identify the command and control (C2) requirements of the shared
cybersecurity responsibility model between DoD and commercial vendors to ensure standard
execution of C2 responsibilities for DoD information in commercial cloud. The specific
requirements of securing a cloud environment will strain the traditional technical workforce and
requires specialized skills where the Department currently has limited expertise.
Historically, information security has been heavily focused on perimeter defense: limiting
network access at the boundary. Unfortunately, this model is challenging for a commercial cloud
environment where data is being accessed remotely and shared within and between deployments,
regions, and from each Cloud Service Provider to other data locations, such as on-premises data
centers at military installations. Therefore, the Department will shift its security focus from
perimeter defense to securing data and services. This shift will be accomplished first through
strong authentication for both people and machines and secure encryption mechanisms both at rest
and in transit. In order to facilitate remote access, the DoD cloud environments will supply built
in cryptographic technology that enables organizations to encrypt communications by default.
Since the information security responsibility is shared between the Department and its Cloud
Service Providers, the Department will include language in all cloud computing contracts directing
Cloud Service Providers to monitor their cloud infrastructure and maintain authenticated,
encrypted logging of security-relevant events that generate an audit trail and are engineered to be
resistant to tampering. To address the workforce strain in adopting these new security postures,
the Department will include cloud adoption assistance and specialized training for its workforce
as a part of DoD Cloud Service Provider contracts.
2.4 Enable AI and Data Transparency
DoD must enable decision makers to use modern data analytics, such as Al and machine
learning (ML), at the speed of relevance to make time-critical decisions rapidly in the field to
support lethality and enhanced operational efficiency. The algorithms used to inform decisions are
dependent on the Department's data and information being organized, secure, and visible in a
common environment. An environment where data is stored in a multitude of disparate and
disjointed stove pipes reduces the efficiency and tempo ofthe Department. To maximize the utility
ofcloud computing technologies, data must be managed properly and follow modern technologies
like data lakes and data hubs, which are accelerated and amplified by cloud technology.
Data stored in an enterprise DoD cloud will be highly available, well-governed, and secure.
Data will be the fuel that powers those advanced technologies, such as ML and AL This critical
decision making data will be made available through modem cloud networking, access control,
and cross domain solutions to those who require access. Common data standards will be a key part
of the Department's methodology for tagging, storing, accessing, and processing information.
Ensuring an enterprise cloud environment will increase the transparency of this data, and drive the
velocity of data analysis, processing, and decision making. Leveraging advances in commercial
cloud security technologies will ensure the Department's information is protected at the
appropriate level.
Commercial cloud provides the ability to scale and secure both the collection and the
analysis of data stored in an enterprise DoD cloud. This gives mission owners the capability to
5