In mid-December 2017, the White House signed the $700 billion National Defense Authorization Act (NDAA). The law sets policies and budget guidelines for the U.S. military for the next fiscal year, including cyber-related projects and initiatives. While established cyber programs are bolstered by the Act, the 2018 NDAA proscribes some new efforts. For example, all Kaspsersky products and services (including from company subsidiaries) are prohibited across the Department of Defense (DoD), an initiative working in tandem with the Department of Homeland Security’s (DHS) push to ban Kaspersky from federal government offices. Similarly, in an effort to safeguard U.S. communications channels from cyber risks, the NDAA forbids the acquisition of satellite technology from a foreign country or any company affiliated with one. These mandates are important as they acknowledge the potential threats that exist when acquiring technologies and/or services from sources outside a secure chain.
Of particular note, is a provision that could force the federal government to upgrade its out-of-date IT systems. The Modernizing Government Technology Act (MGTA), which was enacted in tandem with the NDAA, creates a $500 million fund over the course of two years to be used for modernizing legacy IT systems. Trying to secure old and outdated legacy systems has been thorn in the side of government cyber security efforts. In 2016, 71 percent of federal IT system administrators used old operating system to run important applications. The MGTA will provide necessary funding to address these technical shortcomings.



