DATA SOVEREIGNTY, SECURITY, SUPPLY CHAINS & THE CPCSC

THE CAF’S SUPPLY CHAIN CHALLENGE: PT 4

This Op-Ed is the fourth in a four-part series examining how to address critical supply chain challenges that directly impact the Canadian Armed Forces’ operational effectiveness and national security interests.

BY ALLAN MCDOUGALL & DAN DORAN

Canada’s Defence Industrial Base (DIB) faces a significant challenge when it comes to maintaining sovereign control in our new geopolitical climate. As a community, it holds a treasure-trove of information about Canada’s capabilities, limitations, and priorities. How can the DIB ensure that this data is not accessed inappropriately but that it also remains available and trustworthy for future use?  Meeting this challenge is not quite as clear-cut as many might imagine.

TRUST, SUPPLY CHAINS,
& THE LIMITS OF CONTROL

In this context, sovereignty should be understood simply. It is the condition that exists when a body exerts supreme power or authority over something. This goes beyond being able to have the final say. It also means that should a competing interest appear, the decision made can be enforced. In a community that has become somewhat conflict-averse, this can be an uncomfortable concept. It is, however, our new reality.

This raises the second part of the challenge in the DIB, the supply chain. Many in the DIB rely upon a network of entities (businesses, consultants, etc.) to provide the building blocks of their product or service. These networks of suppliers can be both extensive (many) and complex (relationships). Each one of these organizations is likely to hold sensitive data regarding the contract or their work in the contract.

So where does the real challenge lie and why is this a concern now?

Many of the more significant participants in Canada’s DIB are transnational in nature. They operate in several countries and many of these countries are beginning to enact laws that would allow them to gain access to data, even if that data resides on servers or systems outside of their own territory. As a result, they can fall under one (or many) regimes that seek to collect data, overtly or covertly.

READ: Canada Launches First Phase of Its Cyber Security Certification (CPCSC) for Defence Contracting

This may place members of the DIB in a difficult position. On one hand, the Crown expects that Specified Information will be protected against unauthorized disclosure. This is the premise behind the baseline controls that are put forward in the Canadian Program for Cybersecurity Certification (CPCSC). Where the data resides “on the cloud” or with a third-party provider, what steps need to be taken to demonstrate that such data is still under proper control?

At the heart of this issue lies trust. We trust that companies will live by their agreements, and we trust that our allies will not use such extraordinary steps to gather that information covertly. Where that trust is eroded (for whatever reason), we must look towards the other compensatory controls that would give us assurance that the various requirements are being met, controls maintained, and that the conditions communicated to us are, in fact, representative of actual conditions. This could mean increased transparency into the third-party’s operations or may involve the third-party having to cede control over certain aspects of their own infrastructure (such as access control to data).

Another option is to expand the nation-building projects to include the infrastructure necessary to house this data within a trusted community and that remains under sovereign control. Even with that infrastructure put in place, we will need to be cautious with respect to how that infrastructure is designed and implemented.

This challenge focuses largely on external service providers. Before we can declare a system to offer sovereign control, we need to look under the hood. What external service providers support the system? To what extent is their support critical to the infrastructure’s operations? If that external service provider decided to remove its services, would we lose access to the data or key processes?

Concurrently, we need to understand the external service provider’s core interests. If a foreign service provider, we need to understand at what point that service provider would act in its own interests, the interests of its nation of registration, or other interests than our interests. And again, we have seen that the context of trust has been eroded so a simple agreement or accord should not be considered enough in this regard.

Our last challenge involves the technology itself. As we move into new territory, we need to understand that our data is a marketable commodity. It has value. As a result, we need to be very careful with respect to how that data is handled, communicated, and otherwise treated by the systems (including external services). Can the service provider access the data and to what extent? Can they add, modify, or even delete it? Can they access, manipulate it or communicate it without (first) our consent or (second) our being aware of their actions?

This challenge will test Canada’s ability to act as a truly sovereign nation. While solutions may exist at a facility level (such as a server), data centers often rely upon a range of different services to ensure their performance and security. Once again, those third parties become avenues for external parties to attempt to lay claim to data or information held on systems – a reminder that sovereignty depends less on declaration than on consistent, demonstrable control.