Recent Bills
- H.R. 10171August 27, 2026
- H.R. 10156August 27, 2026
- H.R. 10172August 27, 2026
- H.R. 10160August 27, 2026
- H.R. 10181August 27, 2026
- H.R. 10176August 27, 2026
- H.Res. 1496August 27, 2026
- H.R. 10164August 27, 2026
- H.R. 10170August 27, 2026
- H.Res. 1494August 27, 2026
- H.R. 10163August 27, 2026
- H.R. 10157August 27, 2026
Committees
- Administration
- Agriculture
- Agriculture, Nutrition, And Forestry
- Appropriations
- Armed Services
- Banking, Housing, And Urban Affairs
- Budget
- Commerce, Science, And Transportation
- Education and Workforce
- Energy And Commerce
- Energy And Natural Resources
- Environment And Public Works
- Ethics
- Finance
- Financial Services
- Foreign Affairs
- Foreign Relations
- Health, Education, Labor, And Pensions
- Homeland Security
- Homeland Security And Governmental Affa…
- Indian Affairs
- Indian and Insular Affairs
- Intelligence
- Judiciary
- Natural Resources
- Oversight And Government Reform
- Permanent Select Intelligence
- Rules
- Rules And Administration
- Science, Space, And Technology
- Select Intelligence
- Small Business
- Small Business And Entrepreneurship
- Subcommittee on Aviation
- Subcommittee on Border Security and Enf…
- Subcommittee on Coast Guard and Maritim…
- Subcommittee on Commodity Markets, Digi…
- Subcommittee on Conservation, Research,…
- Subcommittee on Counterterrorism and In…
- Subcommittee on Cybersecurity and Infra…
- Subcommittee on Disability Assistance a…
- Subcommittee on Economic Development, P…
- Subcommittee on Economic Opportunity
- Subcommittee on Emergency Management an…
- Subcommittee on Energy and Mineral Reso…
- Subcommittee on Federal Lands
- Subcommittee on Forestry and Horticultu…
- Subcommittee on General Farm Commoditie…
- Subcommittee on Health
- Subcommittee on Highways and Transit
- Subcommittee on Livestock, Dairy, and P…
- Subcommittee on Nutrition and Foreign A…
- Subcommittee on Oversight and Investiga…
- Subcommittee on Oversight, Investigatio…
- Subcommittee on Railroads, Pipelines, a…
- Subcommittee on Transportation and Mari…
- Subcommittee on Water Resources and Env…
- Subcommittee on Water, Wildlife and Fis…
- Transportation And Infrastructure
- Veterans' Affairs
- Ways And Means

Hearings to examine defense of the Department of Defense Information Network; to be immediately followed by a closed session in SVC-217 at 3:30 p.m.
Meeting•Senate Armed Services Subcommittee on Cybersecurity•May 21, 2025 · 2:30 PM
Summary
Senate Armed Services Subcommittee on Cybersecurity held a meeting on May 21, 2025 at 2:30 PM in Russell Senate Office Building, Room 222.
Record
The meeting has its transcript on the record.
Transcript
The transcript runs to 1,203 lines and 63,809 characters, as the Government Publishing Office printed it.
senate-hearing-61611.txt1[Senate Hearing 119-163]2[From the U.S. Government Publishing Office]34 S. Hrg. 119-16356 DEFENSE OF THE DEPARTMENT OF DEFENSE7 INFORMATION NETWORK89=======================================================================1011 HEARING1213 BEFORE THE1415 SUBCOMMITTEE ON16 CYBERSECURITY1718 OF THE1920 COMMITTEE ON ARMED SERVICES21 UNITED STATES SENATE2223 ONE HUNDRED NINETEENTH CONGRESS2425 FIRST SESSION2627 __________2829 MAY 21, 20253031 __________3233 Printed for the use of the Committee on Armed Services3435[GRAPHIC NOT AVAILABLE IN TIFF FORMAT]3637 Available via: http://www.govinfo.gov3839 __________4041 U.S. GOVERNMENT PUBLISHING OFFICE4261-611 PDF WASHINGTON : 20254344-----------------------------------------------------------------------------------4546 COMMITTEE ON ARMED SERVICES4748 ROGER F. WICKER, Mississippi, Chairman4950DEB FISCHER, Nebraska JACK REED, Rhode Island51TOM COTTON, Arkansas JEANNE SHAHEEN, New Hampshire52MIKE ROUNDS, South Dakota KIRSTEN E. GILLIBRAND, New York53JONI ERNST, Iowa RICHARD BLUMENTHAL, Connecticut54DAN SULLIVAN, Alaska MAZIE K. HIRONO, Hawaii55KEVIN CRAMER, North Dakota TIM KAINE, Virginia56RICK SCOTT, Florida ANGUS S. KING, Jr., Maine57TOMMY TUBERVILLE, Alabama ELIZABETH WARREN, Massachusetts58MARKWAYNE MULLIN, Oklahoma GARY C. PETERS, Michigan59TED BUDD, North Carolina TAMMY DUCKWORTH, Illinois60ERIC SCHMITT, Missouri JACKY ROSEN, Nevada61JIM BANKS, INDIANA MARK KELLY, Arizona62TIM SHEEHY, MONTANA ELISSA SLOTKIN, MICHIGAN6364 John P. Keast, Staff Director65 Elizabeth L. King, Minority Staff Director6667_________________________________________________________________6869 Subcommittee on Cybersecurity7071 MIKE ROUNDS, South Dakota, Chairman7273TOM COTTON, Arkansas JACKY ROSEN, Nevada74JONI K. ERNST, Iowa KIRSTEN E. GILLIBRAND, New York75TED BUDD, North Carolina GARY C. PETERS, Michigan76ERIC SCHMITT, Missouri ELISSA SLOTKIN, Michigan7778 (ii)7980 C O N T E N T S8182_________________________________________________________________8384 may 21, 20258586 Page8788Defense of the Department of Defense Information Network......... 18990 Members Statements9192Statement of Senator Mike Rounds................................. 19394Statement of Senator Jacky Rosen................................. 39596 Witness Statements9798Stanton, Lieutenant General Paul T., USA Director, Defense 499 Information Systems Agency/Commander, Joint Force Headquarters,100 Departmentof Defense Information Network.101102 (iii)103104 DEFENSE OF THE DEPARTMENT OF DEFENSE INFORMATION NETWORK105106 ----------107108 WEDNESDAY, MAY 21, 2025109110 United States Senate,111 Subcommittee on Cybersecurity,112 Committee on Armed Services,113 Washington, DC.114 The Subcommittee met, pursuant to notice, at 2:30 p.m. in115room SR-222, Russell Senate Office Building, Senator Mike116Rounds (Chairman of the Subcommittee) presiding.117 Subcommittee Members Present: Senators Rounds and Rosen.118119 OPENING STATEMENT OF SENATOR MIKE ROUNDS120121 Senator Rounds. [Unaudible] the Cybersecurity Subcommittee122today.123 You did an excellent job at the Army's Cyber Center of124Excellence on Fort Eisenhower and it is great to see that the125Army is cultivating and rewarding capable cyber operators and126leaders like yourself.127 Your testimony on securing and defending the Department of128Defense Information Network (DODIN) comes at a critical129juncture for our Nation's cybersecurity posture. Our military130must maintain a ceaseless vigil against relentless attacks on131our networks from sophisticated adversaries.132 This is not a theoretical battle. Cyber operators actively133defend our networks against State and nonState actors 24/7 365134days a year.135 The fundamentals of the cyber domain present a persistent136challenge. Adversaries require only a single successful breach137while we must maintain perfect defensive integrity across all138systems at all times.139 The department has invested billions in active defense of140the network that supports the entire Department of Defense141(DOD). Defense Information Systems Agency (DISA), is the142organization responsible for providing and running the143department's secure systems and networks.144 The organization responsible for protecting and securing145the daily operations of those networks is an organization146called the Joint Force Headquarters Department of Defense147Information Network (JFHQ DODIN), and Lieutenant General148Stanton oversees both, and as such is one of the many149individuals across the department that is dual hatted.150 The DODIN has been around for 10 years and the directive to151elevate it to a subunified command represents a significant152organizational milestone. Making it a subunified command allows153it to be task oriented underneath Cyber Command to focus on154running and securing the DOD's networks and will further155strengthen our defense.156 DISA and JFHQ DODIN use different tools to protect DOD157networks such as Thunderdome and the zero trust security158program, both of which are being implemented very quickly.159 Today we will hear about these two systems, which will be160ready by 2027 along with other important network security161programs.162 Despite progress in these security programs, the road ahead163demands continued focus and urgency, from securing the164operational technology in end user devices and weapon systems165to implementing artificial intelligence capabilities that can166detect adversary activities before they approach our networks167or hunt them down if they make it in.168 The technological imperatives are clear. We must develop169and implement emerging technologies in innovative ways securely170and quickly. Our adversaries are rapidly innovating and we must171do the same.172 The threat of cyber attacks is not diminishing. It grows173more sophisticated each day. When we examine the resources near174peer competitors like China are devoting to developing their175cyber forces the gravity of the threat becomes more stark.176 They are aggressively pursuing technology to enhance their177effectiveness in cyberspace and continue to make significant178investments in artificial intelligence to build more179sophisticated capabilities.180 American technological superiority has historically been181our asymmetric advantage and we must maintain this in the cyber182domain. We cannot permit a capability gap to develop in such an183all-encompassing and important domain of warfare.184 The first proverbial shots to be fired will take place in185this domain. Any attack in any other domain will be preceded by186an attack on our vital cyber networks.187 While initiatives to develop capabilities such as exquisite188artificial intelligence-enabled (AI-enabled) cyber defense are189underway, the timelines associated with delivery of these190needed cybersecurity capabilities and environments are,191clearly, too slow.192 Extended deployment schedules create operational risk that193our forces have to mitigate through other means. Our194adversaries operate on compressed timelines. Our response195capabilities much match or exceed their tempo.196 Today, I look forward to understanding more of the notable197achievements in securing and defending the DODIN. I am198particularly interested in how DISA and JFHQ DODIN intend to199accelerate delivery of these critical systems to enhance our200defensive capabilities from the cell phone to the laptop to the201enterprise network.202 This subcommittee stands ready to provide the support203needed to guarantee these vital efforts succeed in protecting204our Nation's most critical networks.205 I will now recognize my friend and colleague, the ranking206member Senator Rosen, for opening remarks.207 Senator Rosen?208209 STATEMENT OF SENATOR JACKY ROSEN210211 Senator Rosen. Well, thank you, Chairman Rounds, and I212would like to begin by welcoming our witness, General Stanton,213and thanking him for joining us today to discuss the security214and resilience of the Department of Defense Information215Network, what we know as DODIN. So much easier to say DODIN.216Lots faster.217 This is a critical issue, not just for cybersecurity218professionals but for every person in uniform and for every219single mission around the globe. We must rely on trusted real-220time access to information and communication.221 As the director of the Defense Information Systems Agency222and the commander of the Joint Force Headquarters, DODIN--so we223have JFHQ and DODIN. We are going to be an alphabet--lots of224acronyms today.225 General Stanton, we are so proud. You oversee one of the226largest, most complex and most targeted networks in the world,227one that supports the President, the Secretary of Defense, the228Joint Chiefs of Staff, and our warfighters operating across the229globe.230 That is no small task, sir, and I want to recognize the231incredible scope of your mission and the personnel who support232it.233 We are operating in an era of persistent threats--cyber234threats--where our adversaries are probing. They are testing235our systems every single day seeking any opportunity however236small to degrade our command and control, to disrupt our237operations, or steal our most sensitive information.238 This makes defense of the DODIN a linchpin for our national239security, for our national safety, our personal security.240 As a former systems analyst and computer programmer, I have241seen how much the technological landscape has evolved since I242began and how deeply integrated digital infrastructure has243become to our operations and, frankly, every single bit of our244lives.245 But with that evolution comes an expanded attack surface,246and as we integrate to more cloud-based services--AI tools,247zero trust architectures--we also face increasingly complex248security challenges.249 In this hearing I hope we can explore how DISA is managing250that complexity, how you are building resilience into the251system, how you are attracting and retaining cyber talent, and252integrating innovation into what you do without compromising253our operational security.254 I am also particularly interested in how your team is255implementing zero trust principles across such a vast and,256frankly, diverse enterprise and what this subcommittee can do257to support this critical effort.258 We know that the threats are evolving faster than ever and259that is not ever going to change, I do not think. So must260evolve our defenses to meet the ever changing threat.261 So I look forward to today's discussion, to working with262you, with Chairman Rounds, and our colleagues on both sides of263the aisle to ensure the DODIN remains well protected, agile,264and always mission ready.265 So thank you, Mr. Chair, and I yield back.266 Senator Rounds. Thank you.267 Lieutenant General Stanton, you may begin if you have268opening remarks. Your full statement will be in the record.269270STATEMENT OF LIEUTENANT GENERAL PAUL T. STANTON, USA DIRECTOR,271 DEFENSE INFORMATION SYSTEMS AGENCY/COMMANDER, JOINT FORCE272 HEADQUARTERS, DEPARTMENT OF DEFENSE INFORMATION NETWORK273274 Lieutenant General Stanton. Chairman Rounds, Ranking Member275Rosen, thank you for your support and the privilege of276representing the men and women of the Joint Force Headquarters277Department of Defense Information Network and the Defense278Information System Agency.279 I appreciate the opportunity to share our progress in280designing, building, deploying, and defending the Department of281Defense Information Network. It is a central resource and282critical weapon system for meeting our Nation's objectives283including defending the Homeland, deterring China, and284rebuilding our military.285 Our mission never rests. It is hard to imagine any aspect286of planning, preparing, or executing modern warfighting that287does not include data production, consumption, transport, or288analysis.289 Joint Force Headquarters DODIN and DISA have the290responsibility of securely delivering real-time globally291accessible information to the joint warfighter.292 We ensure the right data is at the right place at the right293time, empowering commanders to make better and faster decisions294than our adversaries. We are war fighters supporting war295fighting. We inculcate the warrior ethos.296 Joint Force Headquarters DODIN and DISA maintain distinct297responsibilities, yet support one another to balance298performance and security in the context of risk.299 On behalf of U.S. Cyber Command, the Joint Force300Headquarters DODIN organizes, observes, and maneuvers within301cyberspace to defeat enemy aggression and preserve302functionality for friendly operations.303 Under the direction of the DOD chief information officer304DISA designs, builds, and securely operates the DODIN. Together305we enable the inherently joint partner and enterprise-scale306capabilities that ensure mission success.307 Accordingly, our priorities to meet the urgency of our308challenges are consistent for both the command and the agency.309 First, we are building collective readiness across the310department and with our industry partners. Success in war311fighting requires forces that are manned, organized, trained,312and equipped to operate effectively at both the individual and313collective levels.314 Cyber operations require combining skill sets such as host,315network, and data analysis toward mutually supporting outcomes.316Each must do his or her part with confidence and competence.317 Importantly, our headquarters must also confidently issue318DODIN wide orders, knowing that receiving organizations are319ready to execute. The elevation of Joint Force Headquarters320DODIN to a subunified command will significantly increase321readiness by establishing a unified command structure that322drives consistent training standards and readiness evaluations323across all 45 organizations that own a portion of the DODIN324battle space.325 Our second priority is campaigning. We are proactively326planning and prioritizing to defeat cyber adversaries and to327provide functionally relevant capability to war fighters at the328time and place of need.329 Understanding cyberspace dependencies, the enemy's intent,330the enemy's capabilities, and the potential for the enemy's331capability to actually impact the mission provides focus for332our defensive operations.333 We prioritize our limited resources against the most334critical systems and preserve our freedom of action while335imposing cost on the adversary.336 Just as fast as capabilities are in place they require337upgrades. Our third priority is, therefore, continuous338modernization. We actively field emerging technologies and339iterate within our development process.340 We design for extensibility with the understanding that341technology and the operating environment will inevitably342change. As we rebuild our military we shape the information343environment according to how we intend to use it. We ensure it344is always ready to meet expeditionary war fighting345requirements.346 Our final priority is to establish lethality. We impose347cost on our enemies and provide decision advantage to our348warfighters. Deterrence in the cyber domain includes raising349the cost of attack beyond that which an adversary is willing or350able to bear.351 Thinking beyond cyberspace, all battlefield operations are352subject to the proliferation of data. We must transform it to353enable lethal and oftentimes kinetic action.354 We are charged with sensing and transporting disparate data355streams into a coherent and comprehensive picture that empowers356decisionmakers at all levels.357 Securing our Nation requires a robust, resilient, and well358defended cyber environment. I am proud to represent the359individuals serving Joint Force Headquarters DODIN and DISA,360who carry out this mission every day.361 With the continued support of this committee our cyber362forces will remain prepared to meet the challenges of today and363the threats of tomorrow.364 Thank you, and I look forward to your questions.365 [The prepared statement of Lieutenant General Stanton366follows:]367368 Prepared Statement by Lieutenant General Paul T. Stanton369 Chairman Rounds, Ranking Member Rosen, and distinguished members of370the subcommittee, thank you for your support and for the privilege of371representing the men and women of Joint Force Headquarters--Department372of Defense Information Network (JFHQ-DODIN) and the Defense Information373Systems Agency (DISA).374 I appreciate the opportunity to share our progress in designing,375building, deploying, and defending the Department of Defense376Information Network (DODIN)--a central resource and critical weapon377system for meeting our Nation's objectives from the tactical to the378strategic.379 Our mission never rests. It is hard to imagine any aspect of380planning, preparing, or executing modern warfighting that does not381include data production, consumption, transport, or analysis. JFHQ-382DODIN and DISA have the profound responsibility of securely delivering383real-time, globally accessible information to the joint warfighter in384the heat of conflict. We ensure the right data is at the right place at385the right time, empowering commanders at echelon to make better and386faster decisions than our adversaries. We are warfighters supporting387warfighting--this is a culture shift built on inculcating the Warrior388Ethos.389 We conduct our missions in the cyber domain where persistent390threats are rapidly evolving, growing in sophistication, and constantly391attempting to compromise operations across all warfighting domains. We392cannot be complacent. The rate at which our adversaries are adopting393new technology is staggering and unprecedented. Our advantage is that394the cyber domain is manmade. As we rebuild our military, we will shape395the information environment according to how we intend to use it, while396ensuring it is always ready to meet expeditionary warfighting397requirements.398 JFHQ-DODIN and DISA maintain distinct responsibilities yet support399one another to balance performance and security in the context of risk.400On behalf of U.S. Cyber Command, JFHQ-DODIN organizes, observes, and401maneuvers within cyberspace to defeat enemy aggression and preserve402functionality for friendly operations. Under the direction of the DOD403Chief Information Officer, DISA designs, builds, and securely operates404the DODIN. Together, we enable the inherently Joint, Partner, and405enterprise scale capabilities that ensure mission success.406 The dual-hatted role as head of both JFHQ-DODIN and DISA bridges407policy, acquisition, operations, and advocacy to meet cyberspace408requirements of our warfighters. Effectively defending the DODIN409requires a detailed understanding of how it is designed and employed;410the JFHQ-DODIN must constantly coordinate with DISA as the environment411continuously evolves. So, too, must DISA understand JFHQ-DODIN's view412of the threats and adversarial campaigns targeting our capabilities413such that we design, extend, and mature the environment with414operational effectiveness at the forefront. The streamlined leadership415model drives priorities for mutual benefit, speeds decisions, and416consistently leverages policies and authorities to synchronize effects417and efficiently apply resources to meet requirements.418 Accordingly, our priorities meet the urgency of our challenges and419are consistent for the command and agency. We are focused on four420priorities: 1) Readiness--building collective readiness across421Department and with our industry partners; 2) Campaigning--proactively422planning and prioritizing to defeat cyber adversaries and provide423functionally relevant capability to warfighters at the time and place424of need; (3) Continuous Modernization--shaping the cyber domain to our425advantage at pace with evolving technology and threats; and 4)426Establishing Lethality--imposing cost on our enemies while providing427the decision advantage to our warfighters.428 building collective readiness429 Success in any warfighting domain requires forces that are manned,430organized, trained, and equipped to operate effectively at both the431individual and collective levels. The military servicemembers,432civilians, and contractors who make up our workforce must be qualified433on their respective cybersecurity weapon system and be fully confident434in their ability to organize collaboratively in executing mission435tasks. Cyber operations require combining skillsets such as host,436network, data, and intel analysis toward mutually supporting outcomes;437each must do his or her part with confidence and competence.438Importantly, our headquarters must confidently issue DODIN-wide orders439knowing that receiving organizations are ready to execute.440 The elevation of JFHQ-DODIN to a sub-unified command will441significantly increase readiness by establishing a unified command442structure, ensuring consistent training standards and rigorous443readiness evaluations across all 45 organizations that own a portion of444the DODIN battlespace. Consistency and readiness standardization enable445rapid dissemination of orders and intelligence for effective execution446across a distributed footprint. Common capabilities employed in a447common manner achieve both speed and scale.448 Capabilities we put onto the DODIN or into the hands of the joint449warfighter must be intuitive, performant, and resilient. Deployed450technology will continue to evolve rapidly, demanding modifications to451training and qualification standards that the force must master452rapidly. DISA enhances Department-wide readiness by ensuring that453industry builds solutions that can be effectively incorporated into our454training models, maximizing utility and proficiency.455 Our workforce will be held to a rigorous qualification process for456cybersecurity standards. We are committed to building a robust training457environment, including continuous learning opportunities, exchange458programs, and industry engagements, to ensure our personnel can459demonstrably execute their responsibilities. Ultimately, our success460depends on cultivating a culture of critical thinking and self-461improvement, supported by organizational resources.462 As we improve tactical readiness within our formations, we must463also more strategically align our readiness with Combatant Command464requirements. DISA has field offices and field commands embedded with465each Combatant Command so that we can remain engaged with emerging466requirements and/or dependencies on cyberspace capabilities. If a467Combatant Command cannot meet its mission based on a network, data, or468infrastructure limitation, then we must quickly modify our support to469addresses emergent challenges. DISA's readiness is informed by and470improves Combatant Command readiness.471 We have recently seen our readiness materialize during the472execution of a Joint Staff Globally Integrated Exercise. JFHQ-DODIN and473DISA participated in Exercise ELITE CONSTELLATION together for the474first time in March. We were able to move and maneuver our network475operations in synchronization with demands from the Combatant Commands.476We matured rapidly over a 10-day period and captured many lessons to477shape our forthcoming participation in the exercise's next stage in478June.479 campaigning480 Key amongst our observations is that the joint force depends on481operationally relevant information systems that must be consistently482deployed and actively defended across the enterprise. As the combat483support agency providing the foundational infrastructure and enterprise484services for the Department, and as a command focused on cyber defense485at operational level of war, we must plan, prepare, and execute486coordinated tasks toward mutually supporting outcomes--we must487campaign.488 As JFHQ-DODIN elevates to a sub-unified command, we progress beyond489incident response to address our adversaries' determined and490coordinated approach to attacking the DODIN and we must view technical491vulnerabilities at DODIN-wide scale. The enemy's actions are492purposeful. Through analysis, we must recognize that an incident in one493portion of the network is likely correlated to others distributed494across the DODIN. We must anticipate vice react. We must understand495that a technological vulnerability can be exploited across its entire496deployment and drive DODIN-wide defenses vice point-in-time fixes.497 Importantly, we must understand the missions of our supported498commands such that we develop cyber defenses that preserve operational499effectiveness. How a system is used determines how it must be defended.500Understanding the cyberspace dependencies, the enemy's intent, the501enemy's capabilities, and the potential for the enemy's capability to502impact mission execution provides focus for defensive operations,503prioritizes limited resources against the most critical systems, and504preserves our freedom of action while imposing cost on the adversary.505 The supported command's mission requires functionally relevant506capability at a time and place that meets warfighter needs. The507Department fights with Joint and Partner formations at echelon508requiring integrated systems of systems available within the theater of509operations. We cannot attempt to deliver individual widgets, but rather510capability suites that address mission-relevant problems.511 A prime example is the complex mission partner network essential to512reestablishing deterrence in the Indo-Pacific. This cyber terrain,513characterized by significant complexity and diversity across numerous514networks and coalition partners must be integrated. We must actively515build the future environment where we share information seamlessly,516anticipate threats proactively, and respond to crises with coordinated517precision. DISA must organize reenforcing and dependent capabilities518into functional relevance delivered within the First Island Chain on519timelines supporting U.S. Indo-Pacific Command. A hybrid-cloud520environment secured with Zero Trust enabled by enterprise identity521control and access management must be connected by resilient and522encrypted transport. Nodes must be strategically placed and enabled523according to the Combatant Command's plan. DISA must campaign to meet524the requirements.525 continuous modernization526 As fast as capabilities are emplaced, they require upgrades with527new applications, modernized security, and newly acquired data sets.528Change is inevitable and we must fundamentally adjust our approach to529technological advancement and the development of capabilities. The530traditional approach of technical refresh, replacing our cyber terrain531with simple one-for-one upgrades on a years-long predictable schedule532will not keep us competitive. As we rebuild our military, we must533continuously shape every aspect of the cyber terrain to our advantage534at pace with evolving technology and threats.535 This means actively fielding emerging technologies and iterating536within our development processes. Interoperability was the baseline,537but now we require integration--beyond interoperable--where information538and capabilities are seamlessly exchanged across systems. We design for539extensibility with the understanding that technology and the operating540environment will inevitably change; our architecture must accommodate541future advancements. We will build systems that are inherently542responsive to the ever-changing operating environment and capable of543adapting to new challenges and opportunities.544 The DODIN is a well-designed amalgamation of industry products and545commercial capabilities tailored to support the unique requirements for546warfighting. Industry solutions are designed for commercial markets. We547must work with industry partners to provide capability that operates in548extreme expeditionary environments under constant observation and549attack by our enemies. Limited bandwidth over long distances pushes the550bounds of physics, requiring a deep understanding of mission context to551mitigate risk and build, operate, and defend for mission success.552Industry is on our team accordingly.553 DISA is actively transforming the Defense Information Systems554Network with cutting-edge technologies, including software-defined wide555area networking, next-generation transport solutions, and optimization556through hybrid cloud architecture. These efforts establish a highly557resilient and reliable global network core capable of supporting all558DOD and partner mission requirements. Importantly, DISA works directly559with the Combatant Commands to inform placement and prioritization.560 Similarly, DISA works with the Combatant Commands and the Joint561Staff to develop enterprise-level global decision support capability.562Using a Development, Security, and Operations approach, DISA's program563managers remain in contact with the user population to deliver564intermediate capability on sprint cycles. This approach optimizes565development and ensures that the evolving system remains nested with566the dynamic mission.567 DISA also remains current by adopting Capability-as-a-Service from568cutting edge commercial partners. Full Content Inspection (FCI) is a569good example of rapidly incorporating state-of-the-art technology into570our defensive posture and leveraging contracted support for immediate571execution. Directed to modernize the Internet Access Points (IAPs) in572the Fiscal Year 2024 NDAA, DISA is postured for FCI integration across573the 10 DISA managed IAPs by September 30, 2025. DISA and JFHQ-DODIN are574also teaming to implement FCI across all DODIN boundary connections.575 DISA's implementation of Zero Trust cyber defenses, Thunderdome,576exemplifies a strategic shift toward continuous verification across the577Department. By minimizing attack surfaces, improving interoperability,578and enhancing visibility, Thunderdome has demonstrated its579effectiveness with successful deployments and a perfect score on the580DOD's Zero Trust Strategy assessment. Thunderdome is an integral581component within the design of DODNet, DISA's ongoing effort to582modernize and secure networks for all Defense Agencies and Field583Activities. Importantly, Thunderdome is designed for extensibility,584composability, and continuous analytic development.585 establishing lethality586 The design of the architecture and our approach to defenses deliver587and maintain the network to deny adversaries any advantage. Deterrence588in the cyber domain includes raising the cost of attack beyond what our589adversaries are willing or able to bear. Our approach is proactive,590leveraging deliberate planning to create and execute cyber defensive591engagement areas that canalize the enemy onto terrain of our choosing,592enabling full observability. Direct contact introduces opportunities to593delay, deny, and degrade enemy actions in unique and dynamic ways.594 Beyond cyber operations, all battlefield operations are subject to595the proliferation of data that must be transformed to enable action. We596are charged with sensing and transporting disparate data streams into a597coherent and comprehensive picture that empowers decisionmakers at598every level. Our mission includes establishing the enterprise599architecture that supports global consistency and reusability that600accelerates action.601 Internally, we have recognized that DISA and JFHQ-DODIN require602robustness in our intelligence, planning, and data analysis capacity to603meet emergent demands. To that end, we have created a Data Analytics604Support Cell from existing resources to transform how we process and605act upon information. We are orchestrating data flows within our606environment to aggregate and correlate data that answer decision-607support requirements. Our team is building on-demand analytics as new608decisions emerge. We are increasingly deploying AI and machine learning609to bolster threat detection and leverage data as a strategic asset for610Combatant Commanders and coalition partners.611 DISA's Joint Operational Edge Coalition Environment (JOE-CE)612represents a leap ahead approach to coordinating data exchange. Real-613time data accessed at the tactical edge through a multi-cloud, data-614centric architecture empowers commanders with a comprehensive615operational picture for superior decisionmaking in contested616environments. Built with robust redundancy and failover mechanisms,617JOE-CE will strengthen deterrence by ensuring the resilience and618continuity of coalition operations, even in the face of cyberattacks619and other disruptions.620 closing621 The virtues of a Warrior Ethos transcend warfighting environments.622Securing our Nation requires a robust and resilient cyber defense and I623am proud to represent the individuals serving at JFHQ-DODIN and DISA624who carry out this mission every day.625 As we restructure our organizations for the optimization of our626workforce, we are evaluating mission requirements, core competencies,627and automation technologies that will drive operational effectiveness628and performance efficiency.629 With the continued support of this Committee, we remain prepared to630meet the challenges of today and the threats of tomorrow. We are631focused and dedicated to safeguarding the DODIN and defending our632national interests in cyberspace. Thank you, I look forward to your633questions.634635 Senator Rounds. Lieutenant General Stanton, thank you.636 I will begin, and we will move back and forth in 5-minute637rounds and we will do a couple of them and then if we have638other members join they will be welcome to come in as well.639 In April the Zero Trust Portfolio Management Office640announced a 2030 timeline for full implementation of zero trust641across operational technology devices and a date of 2035 for642weapons systems.643 Given the rapid evolution of threats targeting these644systems, what interim security measures are being deployed to645mitigate risks during this extended period?646 Lieutenant General Stanton. Senator, I appreciate your647question.648 DISA has introduced Thunderdome, which is our649implementation of zero trust. So we are able to look at650individual systems. The individuals that are using those make651informed decisions about what resources they are able to652access.653 We follow the zero trust principles. In fact, Thunderdome654was recently assessed by a third party meeting all 132 of the655132 Department of Defense standards and activities for zero656trust.657 We have it in action already. We have implemented zero658trust in coordination with United States Southern Command659(SOUTHCOM), and in addition we have it embedded into the660evolution of what we refer to as DOD.net, the modern and secure661infrastructure and architecture that DISA is providing.662 Senator Rounds. Since this is an open session let us talk a663little bit about Thunderdome, and can you give us a little bit664of an indication here so that folks that are listening to it665and they are--it sounds interesting but just exactly how does666it work?667 Lieutenant General Stanton. Yes, Senator.668 So we have a number of appliances and software products669that are state-of-the-art provided by our commercial industry670partners that we integrate into a coherent solution.671 We first check to see who individuals are in the672environment. We also check the State and security of the device673upon which they are operating.674 We put those two together to make sure that the user on the675device are authorized to access resources, and then we have676fine-grained controls that determine which resources they are677able to access.678 Senator Rounds. So when you are doing this for the next679couple of years it really is a challenge for any defense system680to actually modernize while still maintaining that operational681capability, and what you have done is taken Thunderdome and682during this interim time period you have integrated into the683systems and every--basically, every single user along with the684platform that they are on is checked before it is authorized685entrance into the DODIN.686 Accurate?687 Lieutenant General Stanton. Yes, Senator.688 Senator Rounds. Okay, and successful in terms of--what do689you--is it 100 percent successful? Is it--what is the690probability of somebody getting around that and what is the691biggest risk to it?692 Lieutenant General Stanton. So another inherent principle693to zero trust is to continuously evaluate the access to the694resources. So it is not just getting into the DODIN but it is695each time that you go to access resources you are reevaluated.696 So the risk of someone gaining access that exists. We will697never be 100 percent secure. However, we check and validate698every subsequent access and if the enemy gained a foothold into699the environment they cannot operate without impunity and we log700everything to track what is happening in the environment.701 Senator Rounds. Kind of leads me into the next question,702which is the September 2024 DODIN command operational framework703introduced new requirements for reporting readiness through the704department's readiness tool called the Defense Readiness705Reporting System, or DRRS.706 What specific cybersecurity metrics--what are the metrics707for being--you know, what are you capturing with that and how708do these metrics provide a more comprehensive view of the DODIN709operational readiness?710 Lieutenant General Stanton. Senator, readiness is my711number-one priority and the question you are asking is exactly712what we are driving toward.713 We have baseline metrics that assess the effectiveness of a714cybersecurity service provider. The Joint Force Headquarters715DODIN has evaluations teams that travel out to the 45 DODIN716areas of operation and assess the effectiveness of their Cyber717Security Service Provider Programs (CSSPs).718 We record that in the Defense Readiness Reporting System719(DRRS). We can do better and we are working on establishing720additional metrics that can develop a more comprehensive721picture for us to have confidence that all of the DODIN areas722of operation can operate effectively.723 Senator Rounds. Thank you.724 Senator Rosen?725 Senator Rosen. Well, thank you. I was going to ask726something different about the workforce first but I am going to727build on the zero trust architecture.728 I understand when you say who is the person user, who is729the device. You are going to check them every time. We have730that a lot in our own--in other things that regular people do731with banking, other kinds of things.732 But I would think--as I am listening to you I am thinking733about how does the user or device get into the registry, if you734will? I am thinking that that could be a point of735vulnerability.736 So how often--like, I know there is many ways that people737gain access, understanding that you have things all around the738globe. But thinking that there is a point of vulnerability739because if somehow someone can put themselves as a trusted user740or device then that is how one maybe big way they can get into741the system, not the silent way. So how are you securing that742piece, if you will?743 Lieutenant General Stanton. Yes, Senator.744 Enterprise Identity Credentialing and Access Management, or745EICAM as we refer to it, is a central component to the746effective employment of a zero trust environment.747 Senator Rosen. Yes.748 Lieutenant General Stanton. So making sure that we know who749you are and we have multiple different forms of validating your750identity is an inherent principle.751 Additionally, once we issue a certificate it authenticates752you into the environment. That certificate is time bound and753continuously checked and we have measures by which we can754revoke it.755 So in the event that we see something that is anomalous756through our logging we can revoke that certificate on the spot757and deny further access into the environment.758 Senator Rosen. Thank you. That answers the question for me,759and I guess the question we always ask do you have the760resources that you need now to continue to build out your zero761trust architecture, going forward, as we are entering into the762National Defense Authorization Act (NDAA) season, if you will?763 Lieutenant General Stanton. Thank you, Senator.764 There are two primary initiatives through which DISA is765implementing zero trust. So DOD.net is our initiative to766establish a modern and secure infrastructure for the defense767agencies and field activities. They had independently run their768networks previously. We are in the process of migrating them.769 As we do we build in the Thunderdome zero trust model into770that environment. Additionally, we are working with a multi-771partner environment executive agent to incorporate Thunderdome772into our implementation of the multi-partner environment, or773MPE, as we refer to it.774 We are not waiting.775 Senator Rosen. Okay.776 Lieutenant General Stanton. We are moving out aggressively.777 Senator Rosen. Very good. This all leads to my first778question that I was going to ask is about--well, it is kind of779two part, the impacts of recent civilian workforce cuts and780DODIN's ability to conduct your assigned missions.781 But I think it is more than that because sometimes the782workforce cuts--we understand we want to streamline, do things783better. We are going to do things better with computing for784sure.785 But that can have an impact on both our future recruitment,786retention, morale, which is key to maintaining our readiness787and preparing for the future.788 We know we have these issues, particularly when the public789sector is--can be very lucrative for folks who work in that.790 So if you would kind of speak of the snapshot of the impact791of these cuts from deferred retirement, probationary employees,792planned reductions in force, and how is this really going to793impact you, going forward?794 Lieutenant General Stanton. Thank you, Senator.795 First, I would like to acknowledge that I personally have796the utmost respect for anyone that has raised his or her right797hand and sworn an oath to support and defend the Constitution798of the United States, as do all of our civilian and uniformed799service members that operate within the Joint Force800Headquarters and within DISA.801 We will suffer about a 10 percent loss in terms of the802numbers of individuals that are within the Defense Information803Systems Agency. It is giving us an opportunity to ruthlessly804realign and optimize how we are addressing what is an evolving805mission.806 Things like the multi-partner environment and initiatives807like DOD.net are driving our workforce to perform roles that808they had not previously, and so we are doing a realignment and809we are going back to the Department to ask for what we refer to810as a surgical rehiring.811 We need to hire the right people back into the right812position----813 Senator Rosen. That is my point.814 Lieutenant General Stanton. --to then lead us forward.815 Senator Rosen. So we will talk about those resources.816 If I can, this is my last part on this question because on817April 10th there was a memo that was issued by the Secretary of818Defense that announced the termination of several contracts and819insourcing of Information Technology (IT) consulting and820management services to our civilian workforce.821 Could you provide any details to us in this open hearing?822If not, we can do it in the closed. But what are your security823concerns here? Everyone does take an oath but you have these824public-private partnerships, and with all of this happening how825is that really impacting you?826 Lieutenant General Stanton. Thank you, Senator.827 So reviewing contracts is a necessary part of our business828in the IT world. As technology changes we have to continually829evaluate whether or not we have the right industry partner830performing the right mission, and so we routinely evaluate831our----832 Senator Rosen. I just want to be sure it is the right--it833is strategic and not--surgical, not just across the board.834 Lieutenant General Stanton. That is absolutely correct, and835that has been our approach and the Department of Defense has836given us within the DISA the opportunity to handle it through a837surgical lens.838 So our contracts are aligned to the highly technical IT and839cybersecurity workforce. They are not consulting contracts.840These are individuals that are putting hands on keyboard, that841are running fiber optic cables, that are performing server842maintenance in a global footprint.843 Our contracts are healthy and are in a good spot. The844impetus and drive from the department is, however, forcing our845industry partners to evaluate how they are presenting their846technical force to us and we are gaining some efficiencies in847the process.848 Senator Rosen. Thank you. I appreciate it.849 Senator Rounds. Let us follow that up a little bit.850 You not only have to have the tools but you have got to851have the manpower as well. Talk a little bit about just the852size and the scope of what this is to begin with.853 You are protecting the Department of Defense's entire854system. Talk about how big that is and about the number of855people that you employ either in uniform or by contract to856begin with.857 Lieutenant General Stanton. Yes, Senator.858 Our population size is, roughly, 20,000. Slightly more than859half are contracted. About 6,800 are civilians and about 1,200860are active duty military service members.861 Senator Rounds. Then the pipeline for bringing in862individuals, what types of professional backgrounds or what863types of training are you looking for for the majority of these864individuals?865 Can you give us a sense for the folks that are out there866that are looking at it wondering whether or not some young man867or young woman decided they want to be involved in this? Talk868about what the qualifications are that you are looking for or869that you can train for?870 Lieutenant General Stanton. Senator, I will tell you that871the first characteristic that we target in recruiting is872inquisitiveness and the ability to innovate--someone that is873going to be a lifelong learner that is going to adjust on the874fly.875 The technology that we put in their hands today will not be876that which they are using 2 years down the road and so someone877has to be willing to engage with and learn on their own so that878they can incorporate new technology.879 I am quite proud of our Scholarship for Service program880that we have within DISA where we actively recruit highly881technical folks and help pay for the remaining 2 years of their882tuition in order to bring them onto our team for three to 5883years.884 Senator Rounds. So you would actually for--okay, I will885just take an example. Dakota State University in Madison, South886Dakota, is known for their cybersecurity operations.887 You would actually look for someone who had an interest in888coming to work either in uniform or outside of uniform, bring889them in and offer to pick up their costs of education,890basically, for the 2-years with an agreement that they come to891work for you. Is that what we are talking about?892 Lieutenant General Stanton. Yes, Senator. Absolutely.893 Senator Rounds. So what type of an appetite do you have for894young men and women who want to serve? How many are you895talking?896 Lieutenant General Stanton. So in this past year we brought89739 individuals into our Scholarship for Service program.898 Senator Rounds. Could you do a hundred?899 Lieutenant General Stanton. Yes, Senator, we can.900 Senator Rounds. Could you do 150?901 Lieutenant General Stanton. Yes, Senator, we can.902 Senator Rounds. Could you do 200?903 Lieutenant General Stanton. Yes, Senator.904 Senator Rounds. So for young men and women out there, this905is not like a selected group only. This is to where you need906more individuals that have this interest?907 Lieutenant General Stanton. We do, Senator, and we recently908in February published our workforce strategy within DISA and909part of it is to do exactly what we are discussing. Create a910pipeline. Not necessarily hire an individual and expect them to911stay for 30 years and become a member of the Senior Executive912Service.913 Some will, and we need that, but many will stay on our team914for three to 5 years, be enthused by being able to execute the915mission, be in contact with the adversary, support our Nation,916and then they will move on and do other things.917 Senator Rounds. So let us just----918 Senator Rosen. Can I ask a question?919 Could you talk about--like, give a job description? You920talk about people going into the phone lines, hardware,921software.922 Could you just--if we were talking to young folks when we923go back home give us a couple of actual job descriptions that924you might get people--we are just sitting here chatting, if925that is all right with you I would like to be able to tell some926of those young folks.927 Senator Rounds. Yes. No, let us--yes, this is--this is928important because it is not just the type of a job description929but the types of tools they are going to be working with as930well.931 Senator Rosen. That is right. I was a software developer. I932do not want to--do not make me work with the tools to put the933hardware in but let me code away.934 There are different kinds of things. Maybe you might give935us some insight so when we talk to young people, which we do936all the time, we might share with them the jobs that you are937thinking about filling.938 Lieutenant General Stanton. Fantastic, Senator. We need939data analysts. We need data engineers. We need data scientists.940We need folks that understand routing and large-scale routing,941so folks that know how to configure a router securely.942 We need folks that are also very willing to dive into943newest cybersecurity tools and actually implement them, and944when we establish a defense our intent is to gain and maintain945contact with the adversary. So folks that understand host946analysis and network analysis from a cybersecurity perspective947are at the top of our list as well.948 Senator Rounds. Fair to say that these young men and women949that want to come and participate on this would have the950opportunity to learn tools that enable or that are part of an951artificial intelligence system or agent in terms of952accelerating inquiries as to people trying to get into the953systems?954 Would be fair to also say that quantum is not far off with955regards to what they would be working--the environment they956would be working in?957 Lieutenant General Stanton. Yes, Senator. I will start with958artificial intelligence. It is central to our way forward. It959is central to our current operations but absolutely central to960the direction that we are headed.961 Quantum is a little bit further out, but as I said962previously as soon as quantum breaks and becomes a technology963that is readily available it will proliferate very rapidly, and964so we need individuals that can adjust dynamically to the965change in the technology.966 Senator Rounds. Thank you.967 Senator Rosen?968 Senator Rosen. I am just going to build--we are just going969to have a good time building on each other here.970 How are you leveraging the AI? We know that the quantum is971a little ways away but how are you leveraging the AI972capabilities, particularly as you are modernizing,973streamlining, and thinking about all of your architecture?974 So just to kind of build off each other a bit.975 Lieutenant General Stanton. Yes, Senator.976 So, first, I will start with what I think would be obvious,977large language models and chatbot capabilities across different978classification levels.979 I have them on all of my machines currently and I use them980on a daily basis. So chatbot capabilities to help make the981workforce more efficient.982 We are also using AI to help us model and understand our983transport network. So if you think about undersea cables as an984example, if one were to be cut based off of an anchor that was985dragged across the ocean floor can we do the what if analysis986to understand how much bandwidth we have left so that we can987dynamically reallocate how we move data from one spot to the988next.989 We are using AI in that context. We are also using it for990network defense.991 Senator, to your point earlier, we need to be able to see992the enemy's campaign and not just an incident in--or an event993in isolation. So being able to make correlations across very994large data sets in real time is key to our success.995 We are using AI inside of our Thunderdome zero trust996environment so we log everything and all of those logs from997every----998 Senator Rounds. Learning from it.999 Lieutenant General Stanton. Then we learn from it,1000absolutely, Senator.1001 Then, last, looking at the threat detection, again, from a1002campaign perspective, being able to zoom out and not just look1003at the incident that manifests in an alert from our1004cybersecurity system but how do I trace that all the way back1005to the enemy's infrastructure that they use to gain access?1006 Senator Rosen. You mentioned something that is going to be1007a little bit of a hot button coming forward, and I just want to1008know if you have any opinion on this.1009 What if an anchor cut an undersea cable and how would you1010dynamically move things around? So we think about all this1011computing and, of course, we cannot do a lot of it without1012spectrum, right? Do you have an opinion about spectrum in this1013regard?1014 We know that there are other things that use the DOD1015spectrum, our airplanes and our--you know, all of our military.1016You know, our tanks, airplanes, radar and all of that.1017 But do you have an opinion about spectrum? Of course, while1018there is no dynamic spectrum sharing right now--we understand1019that. But if you would, you do not have to but I know that is1020not why you are here but I just know we are going to be talking1021about it a lot.1022 Lieutenant General Stanton. Yes, Senator.1023 So I think any discussion about spectrum has to be1024conducted through the lens of the military warfighting1025capability upon which that spectrum depends.1026 So if we take the--what is colloquially known as the lower1027three bands as an example, that is where we maintain our1028stationkeeping radars.1029 So a stationkeeping radar is required to track objects that1030move at mach 15. That is 15 miles per second. There is no room1031for error and there is no room for ambiguity or disambiguation1032and latency associated with that analysis.1033 So we need to make--be very, very clear that we understand1034what systems are operating within the portions of the spectrum1035and then be incredibly confident that we can deconflict the1036military operations from however it might be used commercially.1037 Senator Rosen. Thank you. I know as we move a little bit1038closer to the NDAA this is going to be--we can maybe dig deeper1039in the classified but this is going to be an area for1040discussion so you can give us any other input that you cannot1041do in an open setting.1042 Lieutenant General Stanton. Yes, ma'am.1043 Senator Rounds. I agree. I think you were referring1044specifically to the 3.1 to 3.45 gigahertz portion----1045 Lieutenant General Stanton. Yes, Senator.1046 Senator Rounds. --which always seems to be under attack.1047Nonetheless, it is--just the physics of it are such that it is1048the best place to have the radar and a lot of our other1049capabilities located today and fully utilized today.1050 Let me go back to this just a little bit because I think1051the young men and women that are out there that are looking at1052this some of them would love to have the uniform on.1053 Some would say that maybe they do not want to have the1054uniform on but they would still love to participate and to help1055their country.1056 Can you talk a little bit about, okay, a young man, young1057woman, come in. They want to participate in this. Love the1058excitement of actually engaging with adversaries on a--you1059know, in the protection of our system.1060 But at some stage of the game industry is going to come and1061industry is going to look at these folks and say, you realize1062how valuable you are. That happens on a regular basis now.1063 Can you talk about how you can compete with industry that1064recognizes just how valuable these young, talented individuals1065are and what we can do to, perhaps, keep them with us for a1066little bit longer before they finally decide to head on out and1067join the business community?1068 Lieutenant General Stanton. Yes, Senator.1069 So, first, in my experience and my personal opinion the1070mission is the most enticing characteristic that we have to1071offer young men and women--old men and women, too.1072 Being in the game, in contact with our adversaries in1073defense of the Nation is exhilarating. It is challenging but it1074is also motivating.1075 So I think that there are a number of the folks that we1076bring in when they are young that will get that taste and stay1077with us. But I also think that we need to be willing to let1078folks go.1079 So the concept of a pipeline, I think, is critically1080important. Knowing that today's youth switch jobs readily--my1081daughter had her first job for a year and she already has a new1082job, and she has a master's degree in nursing and is quite1083talented.1084 But that is how our youth is switching jobs now. We have to1085be receptive of that concept and we have to acknowledge that1086coming to work for us, gaining security clearances, gaining1087operational experience, is going to make them better when they1088go to industry.1089 When we partner with industry we have to recognize that1090folks that learned how to fight defensively in cyberspace with1091us are now defending industry. I think that there is positive--1092there is a positive aspect to that.1093 Some subset of them will stay on our team and we need to1094make sure that we develop them effectively.1095 Senator Rounds. Do you have the resources to be able to1096compete enough to keep some of those top level folks there1097today?1098 Have we provided you with the authorizations and the1099funding to be able to do that, to make it worth their time to1100stay with the team?1101 Lieutenant General Stanton. Senator, I believe that we do1102and, again, it is a combination. I do not think we will ever be1103able to pay an individual as much as they would make in the1104private sector. However, we can pay them enough and we can give1105them the mission that is the reason why they stay.1106 Senator Rounds. For some of them we are talking not just1107defensive operations but offensive operations as well.1108 Commercial sector does not give them the opportunity to1109reach out and touch someone whereas within the operations here1110within CYBERCOM occasionally they have the opportunity to reach1111out and actually touch someone and make a difference. Fair1112enough?1113 Lieutenant General Stanton. Gaining and maintaining contact1114with the enemy is central to the evolution of defensive cyber1115operations. Doctrinally, the United States military goes on the1116defense to posture for the offense.1117 Why is cyberspace any different? It is not.1118 Senator Rounds. Great. Senator Rosen?1119 Senator Rosen. I am going to build on this one because I1120speak from personal experience writing software, designing it.1121When you hit that enter key, boy, you are a bum or a hero. It1122is dynamic. It is exciting. It is challenging.1123 You solve problems and it is a--I speak a lot from personal1124experience on that. I understand the mission.1125 We have talked a lot about for folks in some of these very1126specific kinds of jobs where if you rotate out--sometimes1127people rotate in order to gain experience for their next1128promotions--you end up losing some of your skills if you do not1129keep them up all the time.1130 We have talked about not rotating certain folks so they can1131maintain and grow in the cyber area, and I have also set up,1132because I did this for a living, something that I thought of on1133others as well, a civilian cyber reserve.1134 So there is a lot of jobs in cyber security that--they1135could be engineering, they could be programming, linguistics--1136there are so many areas--that you might be a professor.1137 You might be someone who is a little bit older who wants to1138give back but does not want to quit their other job. So1139standing up a civilian cyber reserve so we can surge up or have1140people come to teach us. We have some pilot programs out there.1141 Just wondering if you--I know it is kind of off the cuff--1142how you feel about--this would allow for some of those folks1143that may leave to continue to stay engaged in a Reserve1144component, if you will, like we do in other areas of our1145military.1146 Lieutenant General Stanton. Yes, Senator.1147 So, first, just to nerd out for a second, I wrote my first1148computer program in 1985 in the Basic programming language on1149an Apple 2C computer. So----1150 Senator Rosen. I am a little bit ahead of you because I1151wrote my first programs on key punch cards in Basic, okay.1152 [Laughter.]1153 Lieutenant General Stanton. But I----1154 Senator Rosen. I walked around campus like that.1155 Lieutenant General Stanton. I absolutely share that1156thrill----1157 Senator Rosen. It was exciting.1158 Lieutenant General Stanton. --of when the compiler actually1159completes.1160 Senator Rosen. When the compiler--yes, oh yes. It is real.1161It is real.1162 Lieutenant General Stanton. Yes, Senator. But to the--I1163think that retaining our talent through the reserves and1164keeping them engaged is critical to our success and it also1165gives the opportunity for gaining a different perspective that1166is incredibly valuable for the ultimate defense of the Nation.1167 Someone operating, for instance, in the Joint Force1168Headquarters DODIN leaves and goes to industry and works at a1169bank or works at an oil company they are gaining a very1170different perspective that is certainly relevant to defense,1171and keeping them in the reserves allows them to bring that1172perspective and infuse it into our forces at the time of need.1173We must do that.1174 Senator Rosen. Thank you.1175 Senator Rounds. We want to give you a little bit of a1176break. We will be going into a closed session in the Secure1177Compartmentalized Information Facility (SCIF) shortly and we1178wanted to give you a little bit of a break.1179 I have really appreciated your responses to these and,1180hopefully, we are giving folks back home a little bit of a1181sense of just what you do and the opportunities that are out1182there for young men and women to come in to help us in this1183very challenging environment.1184 Senator Rosen, do you have anything else to add before we1185close out?1186 Senator Rosen. Oh, no. I will give you a break, and this is1187a topic I think both of us could talk--all of us could talk1188about all day. There are so many important issues.1189 So just appreciate--we will look forward to what we can1190talk about in the closed session.1191 Thank you, Mr. Chairman.1192 Senator Rounds. Very good, and with that, this will1193conclude the open portion of today's Cybersecurity Subcommittee1194hearing.1195 For the information of members who will not be joining us1196for the closed briefing, questions for the record will be due1197to the committee within two business days of the conclusion of1198this hearing.1199 With that, the open portion of the hearing will stand1200adjourned.1201 [Whereupon, at 3:13 p.m., the Subcommittee adjourned.]12021203 [all]