Maintaining a Competitive Advantage: An Analysis of the Efficiency and Effectiveness of the Marine Corps Assessment and Authorization Process

Abstract

Maintaining a competitive advantage in conflict requires a Marine Corps that can rapidly develop and field technologies to the operational forces. In the 2019 "Commandant's Planning Guidance," the Commandant of the Marine Corps emphasized the need to enhance our capabilities in artificial intelligence, sensor-based data collection, and data-enabled decision-making. Vital to this effort is the Risk Management Framework (RMF), the mandated process by which we assess and mitigate cybersecurity risks to these systems in the rapidly evolving threat environment. To maintain its effectiveness, the Marine Corps must continue to make process improvements that support the rapid development of secure systems. This study conducts a qualitative analysis of the Marine Corps' utilization of the RMF to determine whether current assessment and authorization processes adequately address the current threat environment in a timeline that supports the warfighter. We use a mixed-methods approach to investigate the successes, shortfalls, and inefficiencies of the RMF through the experiences of interviewed subjects involved in the Marine Corps assessment and authorization process. We find that the current Marine Corps assessment and authorization process is slow, stovepiped, and compliance-based. The increasing requirement to develop and field new technologies to the operational forces and the evolving nature of security threats require the Marine Corps to improve its risk mitigation strategy.

Open PDF

Document Details

Document Type
Technical Report
Publication Date
Sep 01, 2021
Accession Number
AD1164217

Entities

People

  • Daphne Williams
  • Marc B. Bucks

Organizations

  • Naval Postgraduate School

Tags

Communities of Interest

  • Cyber
  • Materials and Manufacturing Processes
  • Weapons Technologies

DTIC Thesaurus Topics

  • Artificial Intelligence
  • Business Administration
  • California
  • Computer Access Control
  • Cybersecurity
  • Department Of Defense
  • Governments
  • Information Exchange
  • Information Systems
  • Law
  • Military Science
  • National Governments
  • National Security
  • Organizational Structure
  • Risk
  • Risk Analysis
  • Risk Management
  • Security
  • Standards
  • Systems Engineering
  • United States
  • United States Government
  • United States Naval Academy

Readers

  • Defense Acquisition Program Management
  • Enterprise Information Systems Architecture and Joint Command Capability Interoperability Support.
  • Naval Personnel Management

Technology Areas

  • AI & ML
  • AI & ML - DoD AI Strategy
  • Cyber