Pentagon: Sooner is better for cybersecurity testing

11.06.2009
The director of one of the world’s largest software testing operations has some advice to offer CIOs about improving the security of their IT systems: The sooner you start security testing, the more secure your systems will be.

Steven Hutchison, test and evaluation executive for the Defense Information Systems Agency (DISA), has a staff of 1,300 military and contractor employees and an annual budget of $170 million. Hutchison’s team engages in developmental, operational interoperability and security testing for the Defense Department’s command and control and business applications.

“The volume of work is considerable,” Hutchison said in a recent interview. “My ballpark estimate is that we have 400 various test and evaluation activities in a given year.”

Cybersecurity is at the top of the Obama administration’s agenda, with plans to appoint a who reports to both the National Security Council and the National Economic Council. The Obama Administration also is beefing up its ability to respond to and launch .

Increasingly, DISA is putting its emphasis on security testing of its IT systems, as it tries to find and exploit vulnerabilities in software before and after it is deployed.