Air Force Cracks Down on Non-Compliant Computers and Software

Audio of this article is brought to you by the Air & Space Forces Association, honoring and supporting our Airmen, Guardians, and their families. Find out more at afa.org

The lead cyberspace operations unit in the Department of the Air Force is hardening security standards on department networks at a time when advanced artificial intelligence is increasing the risk of a range of cyber threats.

The 16th Air Force’s 688th Cyberspace Operations Wing, Joint Base San Antonio-Lackland, Texas, is enforcing the Department of Defense’s Comply to Connect cybersecurity framework in a two-phased strategy, focusing first on non-compliant hardware and next on non-compliant software, the wing said in a July 30 release.

Uniformed and civilian Air Force and Space Force personnel began reporting systems flashing quarantine messages in early July, as images of quarantined laptops screens were posted on the unofficial Air Force amn/nco/snco Facebook page. Federal News Network previously reported the issue.

The Pentagon’s Comply to Connect (C2C) standard dates back nearly a decade to the fiscal 2017 National Defense Authorization Act’s Section 1653. The objective is to block any device or program that doesn’t comply with department standards. C2C fits into the broader Zero Trust security framework initiated following a 2021 executive order. Zero Trust covers 91 specific DOD cybersecurity initiatives which are supposed to all be in place DOD-wide by the end of fiscal 2027.

The original target for compliance with C2C was June 2026, but the military’s sprawling networks and information technology systems have long struggled to keep up with advancing technology standards.

Today, the rise of new generative artificial intelligence models offers attackers new tools to rapidly find flaws and penetrate systems, creating increased urgency to shut down vulnerabilities, said retired Air Force Col. George Dougherty, author of “Beast in the Machine: How Robotics and AI Will Transform Warfare and the Future of Human Conflict” in an interview with Air & Space Forces Magazine.

“They have the ability to map networks automatically and find and exploit potential vulnerabilities at high speed,” Dougherty said.

Noncompliant devices present those vulnerabilities and AI tools make them easier to find, said Dougherty, formerly director of innovation under the Department of the Air Force’s program acquisition executive for command, control, communications, and battle management.

Raju Ranjan, an engineer from the AFNet Sustainment and Operations Branch, discusses plans for a modern software-based perimeter with Capt. Christopher Kodama, a Branch engineer, at Hanscom Air Force Base, Mass., which will deliver zero trust capability to applications across the Air Force. (U.S. Air Force photo by Mark Herlihy)

The Process

The 688th Cyber Wing kicked off its network hardening efforts on July 8, according to the wing release, but the reported quarantines started even earlier. Cyber operators checked network devices against five “security pillars,” including endpoint firewalls, up-to-date software patches, digital certificates, data at rest encryption, and anti-malware software. Each pillar secures the network against a different sort of intrusion.

“Devices that did not meet standards were quarantined and flagged for hands-on remediation from local communication squadrons to restore compliance and strengthen overall network security,” according to the release.

The release did not specify how many cyber operators were involved or how many devices were checked during the “initial rollout.”

Spokespersons for the 16th Air Force did not provide an immediate response to a July 31 Air & Space Forces Magazine query.

The Wing’s next step to protect networks begins in August with the rollout of automated application whitelisting, a process that ensures only verified individuals and programs can perform tasks on a network; unauthorized users and software will be blocked. The project will automate whitelisting, so the network can rapidly identify and remove unapproved software and prevent unauthorized applications from running on the network, according to the release.

Squadrons at JBSA-Lackland are compiling “unit-specific lists of mission-essential, approved software,” as part of the August preparation.

“While no network is entirely risk-free, pairing the C2C framework with application whitelisting strengthens the 688th CW’s efforts to harden Air Force networks into a more resilient foundation for modern warfighting and for sustaining the long-range kill chain,” according to the release.

Audio of this article is brought to you by the Air & Space Forces Association, honoring and supporting our Airmen, Guardians, and their families. Find out more at afa.org