10 of 15 of DOD’s Major IT Projects Are Behind Schedule, GAO Found

Casimiro PT/Shutterstock.com

Lack of talent is one of the key reasons Defense officials cited for shortfalls implementing cybersecurity best practices. 

The Defense Department’s software development approaches are helping to avoid cost increases and schedule delays for many major information technology systems, but uneven implementation of cybersecurity best practices may be introducing risk to these programs, according to a watchdog report.  

In the first of a series of annual reviews of major Defense IT systems, the Government Accountability Office examined 15 business and non-business DOD IT programs and found 10 programs had schedule delays, including one 5-year delay. Eleven had decreased cost estimates as of December 2019, according to the audit, which was released to the general public just before the holidays

While GAO didn’t make any specific recommendations in the audit, DOD in its comments said the audit “highlight[s] opportunities for continued improvement to acquiring IT capabilities.” The main challenge for DOD’s major IT systems is the agency’s mixed record on incorporating cybersecurity best practices. 

While all 15 programs are using cybersecurity strategies, only eight conducted cybersecurity vulnerability assessments, which help determine whether security measures are strong enough. In addition, 11 of the 15 programs conducted operational cybersecurity testing, but only six conducted developmental cybersecurity testing. 

“According to the DOD Cybersecurity Test and Evaluation Guidebook, programs that do not perform developmental testing are at an increased risk of cost and schedule growth and poor program performance,” the audit notes. “In addition, according to the guidebook, programs that do not perform operational testing are at risk of not resolving operational cybersecurity of the operational effects of discovered vulnerabilities.”

But addressing cybersecurity takes software development talent, and nearly all of the 15 programs told GAO they had trouble with government and contractor software development staff. Nine programs said it was hard to find staff with the requisite expertise, and another seven said it was hard to find enough software development staff. Seven more programs said hiring staff in time was a problem, and six said staffing plans didn’t come to fruition.

DOD in its comments said continued implementation of the DOD Cyber Strategy, which addresses talent and cyber workforce issues, will help mitigate these challenges.

The bulk of the report was dedicated to tracking estimated cost and schedule fluctuations for each program as well as describing what kind of software development method programs are using. 

Almost every program audited is relying on continuous iterative software development, which is the Defense Science Board’s recommended methodology. Seven programs are using agile development and three are using DevOps. Just two programs are using DevSecOps, though, which is considered the latest and greatest software development method. DOD released its DevSecOps reference architecture in 2019

Three programs are still using the older waterfall development, which GAO said may contribute to cost growth and schedule delays. 

The 11 programs that saw decreasing costs include the Air Force’s Maintenance Repair and Overhaul Initiative, which had the lowest decrease in estimated costs at .03%, and the Army Contract Writing System, which had the largest decrease in estimated costs at 33.8% below the original estimated sticker price. Program officials reported three main reasons for decreasing cost estimates: lower than expected costs for the contracts, good program management and contract cost revisions. 

The Defense Logistics Agency also attributed a small decrease in estimated costs to running a competitive awards process, and the Air Force reduced costs on one of its programs by reducing the scope of the project. 

Four programs experienced cost estimate increases. The National Security Agency’s Public Key Infrastructure Increment 2 program exceeded cost estimates because of testing delays, program officials said, and Army officials indicated the Integrated Personnel and Pay System-Army Increment 2 program sustained costs increases because of development challenges. 

Most of the major IT programs—10 of the 15—are behind their original schedules, with delays ranging from a month to five years. GAO listed two examples describing why programs were delayed. Defense officials said a need to fix “significant cybersecurity and performance issues” led to an over three-month delay on the Defense Information Systems Agency’s Teleport Generation 3 program. And a longer than expected maintenance period as well as a lengthy budget approval process delayed the Navy’s Consolidated Afloat Networks and Enterprise Services program, according to the audit. 

X
This website uses cookies to enhance user experience and to analyze performance and traffic on our website. We also share information about your use of our site with our social media, advertising and analytics partners. Learn More / Do Not Sell My Personal Information
Accept Cookies
X
Cookie Preferences Cookie List

Do Not Sell My Personal Information

When you visit our website, we store cookies on your browser to collect information. The information collected might relate to you, your preferences or your device, and is mostly used to make the site work as you expect it to and to provide a more personalized web experience. However, you can choose not to allow certain types of cookies, which may impact your experience of the site and the services we are able to offer. Click on the different category headings to find out more and change our default settings according to your preference. You cannot opt-out of our First Party Strictly Necessary Cookies as they are deployed in order to ensure the proper functioning of our website (such as prompting the cookie banner and remembering your settings, to log into your account, to redirect you when you log out, etc.). For more information about the First and Third Party Cookies used please follow this link.

Allow All Cookies

Manage Consent Preferences

Strictly Necessary Cookies - Always Active

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data, Targeting & Social Media Cookies

Under the California Consumer Privacy Act, you have the right to opt-out of the sale of your personal information to third parties. These cookies collect information for analytics and to personalize your experience with targeted ads. You may exercise your right to opt out of the sale of personal information by using this toggle switch. If you opt out we will not be able to offer you personalised ads and will not hand over your personal information to any third parties. Additionally, you may contact our legal department for further clarification about your rights as a California consumer by using this Exercise My Rights link

If you have enabled privacy controls on your browser (such as a plugin), we have to take that as a valid request to opt-out. Therefore we would not be able to track your activity through the web. This may affect our ability to personalize ads according to your preferences.

Targeting cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites. They do not store directly personal information, but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising.

Social media cookies are set by a range of social media services that we have added to the site to enable you to share our content with your friends and networks. They are capable of tracking your browser across other sites and building up a profile of your interests. This may impact the content and messages you see on other websites you visit. If you do not allow these cookies you may not be able to use or see these sharing tools.

If you want to opt out of all of our lead reports and lists, please submit a privacy request at our Do Not Sell page.

Save Settings
Cookie Preferences Cookie List

Cookie List

A cookie is a small piece of data (text file) that a website – when visited by a user – asks your browser to store on your device in order to remember information about you, such as your language preference or login information. Those cookies are set by us and called first-party cookies. We also use third-party cookies – which are cookies from a domain different than the domain of the website you are visiting – for our advertising and marketing efforts. More specifically, we use cookies and other tracking technologies for the following purposes:

Strictly Necessary Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Functional Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Performance Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Social Media Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Targeting Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.