The DoD recognizes the need to help DIB organizations improve their cybersecurity posture and operational resilience and to help the DIB protect DoD information that resides on and transits DIB information systems. A variety of services are available based on your specific needs. Visit the websites below for information about cybersecurity training, services, and products. You may also contact the DIB CS PMO at OSD.DIBCSIA@mail.mil to request additional details about these services.
DoD Defense Industrial Base Collaborative Information Sharing Environment (DCISE)
For a more comprehensive look at DCISE service offerings, please see their brochure here.
DCISE3:
DCISE has partnered with a service provider to offer real-time monitoring of your organization's network traffic, threat detection, and alerts as well as the option to block malicious traffic.
This service includes real-time network traffic monitoring for malicious sources and destinations and shares data anonymously at no cost. Malicious traffic is alerted on and, if desired, blocked. The service protects against DDOS and DNS attacks.
Cyber Resilience Analysis (CRA):
This program offers a structured review of an organization's cybersecurity posture with the goal of understanding cybersecurity capabilities and operational resilience and improving the ability to manage risk to critical services and assets.
A structured survey conducted either in a DC3-facilitated session or as a self-assessment produces a report with suggested actions aligned with the 10 security domains that map to the NIST SP 800-171 requirements to protect CUI and the NIST Cybersecurity Framework.
Adversary Emulation (AE):
This program analyzes an organization's vulnerability to threat actors based on network architecture, software, and processes. It includes technical, process, and policy evaluations in a single, actionable framework.
AE may include penetration testing, network mapping, vulnerability scanning, phishing assessments, and web application testing.
Email
DC3.Information@us.af.mil
DIB-VDP:
A voluntary program for DIB companies that provides vulnerability discovery triaging and validation. DIB-VDP researchers facilitate timely vulnerability remediation by the system owner to reduce risk. Leveraging the proven model is the most effective way to encourage vulnerability discovery with DIB companies' publicly accessible information systems.
Participation does not require DIB CS Program enrollment.
Email AFOSI.DC3.DIB-VDP@us.af.mil for more information.
National Security Agency (NSA) Cybersecurity Collaboration Center (CCC)
Protective Domain Name System (PDNS+):
The NSA's PDNS service combines commercial cyber threat feeds with the NSA's unique insights to filter external DNS queries and block known malicious or suspicious website traffic, mitigating nation-state malware, spear phishing, botnets, and more.
Attack Surface Management:
This service helps DIB customers find and fix issues before they become compromises by identifying DIB internet-facing assets, then leveraging commercial scanning services to find vulnerabilities or misconfigurations on these networks. Each customer receives a tailored report with issues to remediate, prioritized based on both severity of the vulnerability and whether or not it is being exploited.
Penetration Testing:
Leverages AI to automate pen-testing, enabling DIB companies to identify and mitigate vulnerabilities within their internal networks. The service also provides visualizations, tailored mitigation guidance, and the ability to verify if a DIB company has implemented the suggested mitigations effectively.
Threat Intelligence Collaboration:
Stay one step ahead of the adversary through NSA threat intelligence.
Visit: https://www.nsa.gov/About/Cybersecurity-Collaboration-Center/ or email DIB_Defense@cyber.nsa.gov for more information.
Project Spectrum
Sponsored by the DoD Office of Small Business Programs (OSBP), Project Spectrum offers a wide variety of services, including cybersecurity information, resources, tools, and training. Their mission is to improve cybersecurity readiness, resiliency, and compliance for small and medium-sized businesses and the federal manufacturing supply chain.
Project Spectrum includes information about security, risk, and compliance assessments, readiness checks, training, reviews of tools, current research, and policy. Project Spectrum provides information about U.S. Government and commercial services and tools, both free and fee based.
Visit: https://www.projectspectrum.io/#/