Zero trust at DoD hinges on thawing stubbornness in the workforce国防部的零信任政策取决于能否消除员工队伍中的顽固情绪。
Resnick said he has seen the spirit of innovation in leadership, but it’s the mid-tier of the workforce that sometimes pushes back.

Randy Resnick , the boss of the Pentagon’s young Zero Trust Portfolio Management Office, offered a glimpse of what it’s like to sit in his seat and drive some of the most aggressive cybersecurity advances in government.
“So, imagine the [Defense Department] being a really big ship, with the smallest rudder you ever saw in your life trying to try to turn that ship,” he said at the 2024 TechNet Cyber conference presented by the Armed Forces Communications & Electronics Association International on Tuesday. “That’s what the Department of Defense is.”
He doesn’t mean it derogatorily. He said it as more a statement of fact than a judgment. And, to the department’s credit, with help from outgoing Chief Information Officer John Sherman and a great deal of documents to keep these offices on the same page, they’ve made progress on the “gargantuan challenge” of getting workforce culture to support cyber security imperatives. But there’s still some work to be done.
Much of the discussion Resnick led at the event in Baltimore centered around the complex technology undergirding zero-trust, which both the military services and civilian agencies are tasked with implementing to some effect in the next few years. The DoD offices has until 2027 to hit almost a hundred different targets for zero trust. Meanwhile, the department’s 2025 budget requested roughly $977 million for zero-trust transition, C4ISRNET previously reported.
Zero-trust is, as Resnick said, just that: nothing is trusted, and as a result, there are behind-the-scenes tests that verify and validate access with, ideally, minimal intrusion on user experience. It’s an access control strategy, but it’s also analytics, automation and data.
Zero-trust is very specific but it’s also seemingly ubiquitous. The White House, even, has made cyber defenses a priority of every federal agency.
“Really, zero-trust is all of us,” said Leslie Beavers, the principal deputy CIO at the Defense Department, on Tuesday.
However, for it to work, zero-trust needs to be defined. And all the players need to be one the same page. That’s something that has happened only recently, said Resnick.
“Industry was all over the map with zero trust,” he said. “Everybody had a ZT solution. Everybody was approaching government employees and purchasers, and people were very, very, very confused in the government.”
So, Resnick’s office put structure around zero-trust. The goal, first and foremost, was to stop adversaries’ exploitation of DoD data, he said. Then, they got to work on a number of foundational documents to lay out goals and plans for achieving them, including the DoD Zero Trust Strategy and Roadmap and the “Overlays” plan.
It was an effort to synchronize the theory and actual approach of zero-trust, but inadvertently, it also influenced other countries’ zero-trust plans and reset industry’s understanding of what DoD needs, Resnick said.
“Without a doubt, I now have conversations with industry that are completely aligned to the DoD zero trust approach,” he said. “We didn’t have this two years ago. It’s a pleasure to have a conversation now, because now we’re all on the same page.”
Now that the level setting has been done, there remains the issue of change management.
T he federal workforce, for one, skews older than the private sector. Data from 2022 less than 6% of government IT employees are under the age of 30, and 30% are 55 or older. While officials said the Defense Department often has more reliable and robust funding to go after new technology, federal civilian agencies may not, creating an environment where government is at various stages of adoption, and not always willing to embrace change. The pervasiveness of legacy systems also makes change hard, especially when the skills needed versus the skills available vary.
Resnick said he has seen the spirit of innovation in leadership, but it’s the mid-tier of the workforce that sometimes pushes back — the “permafrost,” as he calls it.
“They feel threatened because they do the old style of cybersecurity,” he said. “I did it myself; I totally understand. But ... if they haven’t learned now, then [they’re] never going to learn. And so I truly believe it’s a generational thing. We’re going to have to wait them out until they retire out.”
That’s not to say training isn’t happening. Resnick said they worked with Defense Acquisition University to get access for CAC-holders to cyber classes that vary in length and intensity.
He said he sees a gap in industry training for zero-trust and urged members to populate that space.
Molly Weisner is a staff reporter for Federal Times where she covers labor, policy and contracting pertaining to the government workforce. She made previous stops at USA Today and McClatchy as a digital producer, and worked at The New York Times as a copy editor. Molly majored in journalism at the University of North Carolina at Chapel Hill.
五角大楼新成立的零信任组合管理办公室负责人兰迪·雷斯尼克 (Randy Resnick) 向我们展示了坐在他的职位上,推动政府一些最激进的网络安全进步是什么感觉。
“所以,想象一下国防部是一艘非常大的船,却用你这辈子见过的最小的舵来试图转动这艘船,”他在周二由国际武装部队通信与电子协会主办的2024年TechNet网络安全会议上说。“国防部就是这种情况。”
他这么说并没有贬义,更多的是在陈述事实,而非妄下断言。值得称赞的是,在即将离任的首席信息官约翰·谢尔曼的帮助下,以及大量文件确保各部门步调一致,该部门在应对“艰巨挑战”——即如何使员工文化支持网络安全需求——方面取得了进展。但仍有一些工作要做。
在巴尔的摩举行的活动中,雷斯尼克主持的大部分讨论都围绕着支撑零信任的复杂技术展开。未来几年,军方和民事机构都肩负着落实零信任的重任。国防部各部门需要在2027年之前实现近百项不同的零信任目标。与此同时,据C4ISRNET此前报道,国防部2025年的预算申请了约9.77亿美元用于零信任转型。
正如雷斯尼克所说,零信任的核心在于:不信任任何事物,因此,后台会进行测试来验证访问权限,理想情况下,这些测试应尽可能减少对用户体验的干扰。它不仅是一种访问控制策略,还融合了分析、自动化和数据技术。
零信任原则虽然非常具体,但似乎也无处不在。甚至连白宫都已将网络安全防御列为所有联邦机构的优先事项。
“实际上,零信任关乎我们所有人,”国防部首席副信息官莱斯利·比弗斯周二表示。
然而,雷斯尼克表示,要让零信任机制发挥作用,首先需要对零信任进行定义,并且所有参与者都必须达成共识。而这一点直到最近才得以实现。
他说:“当时整个行业对零信任的理解非常混乱。每个人都声称自己有零信任解决方案。每个人都在接触政府雇员和采购人员,政府内部对此感到非常非常非常困惑。”
因此,雷斯尼克的办公室围绕零信任原则构建了框架。他表示,首要目标是阻止对手利用国防部数据。随后,他们着手制定一系列基础性文件,阐明实现目标的计划和方案,其中包括《国防部零信任战略和路线图》以及“叠加层”计划。
雷斯尼克表示,此举旨在协调零信任的理论和实际方法,但无意中也影响了其他国家的零信任计划,并重新定义了业界对国防部需求的理解。
“毫无疑问,我现在与业界人士的对话完全符合国防部的零信任理念,”他说。“两年前我们还没有这样的对话。现在能进行这样的对话真是太好了,因为我们现在都达成了共识。”
既然层级设定已经完成,接下来就剩下变革管理的问题了。
联邦政府员工的年龄结构比私营部门更为老龄化。2022年的数据显示,政府IT员工中30岁以下的不到6%,而55岁及以上的员工则占30%。虽然官员们表示,国防部通常拥有更可靠、更充足的资金来引进新技术,但联邦民事机构可能缺乏这样的资金,导致政府在新技术应用方面处于不同的阶段,并且并非总是乐于接受变革。此外,遗留系统的普遍存在也使得变革举步维艰,尤其是在所需技能与现有技能不匹配的情况下。
雷斯尼克表示,他看到了领导层的创新精神,但有时正是中层员工——他称之为“永久冻土层”——会进行抵制。
“他们感到受到威胁,是因为他们仍然沿用老一套的网络安全方法,”他说。“我自己也曾这样做过;我完全理解。但是……如果他们现在还不吸取教训,那就永远也学不会了。所以我真心认为这是一个代际问题。我们只能等到他们退休了。”
这并非意味着培训没有进行。雷斯尼克表示,他们与国防采办大学合作,为持有通用访问卡(CAC)的人员提供参加网络安全课程的途径,这些课程的时长和强度各不相同。
他表示,他发现行业在零信任方面的培训存在不足,并敦促成员们填补这一空白。
莫莉·韦斯纳是《联邦时报》的专职记者,主要报道与政府劳动力相关的劳工、政策和合同方面的新闻。她曾先后在《今日美国》和麦克拉奇报业集团担任数字内容制作人,并在《纽约时报》担任过文字编辑。莫莉毕业于北卡罗来纳大学教堂山分校,主修新闻学。