Pentagon Bans Tech Vendors Fro... Note
ProPublica

Pentagon Bans Tech Vendors From Using China-Based Personnel After ProPublica Investigation

The Defense Department has updated its cybersecurity rules for tech companies providing cloud services. These new regulations prohibit IT vendors from utilizing China-based personnel on their computer systems. Companies are now mandated to keep a detailed digital record of maintenance performed by foreign engineers. These changes were prompted by a ProPublica investigation that revealed Microsoft had used engineers in China for nearly a decade. This practice potentially exposed sensitive government data to cyber threats from China. The previous system relied on U.S.-based "digital escorts" who often lacked the technical expertise to effectively supervise foreign engineers. The Defense Department now requires personnel from non-adversarial countries to work on its cloud systems. Supervisors must be technically qualified for the systems they are overseeing. Furthermore, cloud providers must maintain comprehensive audit logs identifying all escorts and escorted personnel, including their country of origin. These updated requirements aim to mitigate significant national security risks. Congress has called for stronger security measures and criticized Microsoft's previous practices. Microsoft has stated its commitment to adhering to the new directives and has already made changes to its support model.