“The program was designed to comply with contracting rules, but it exposed the department to unacceptable risk.”
Microsoft had engineers in China maintaining sensitive Pentagon computer systems. Their solution to security requirements was “digital escorts” who supposedly supervised the foreign workers. The escorts often lacked the technical knowledge to understand what they were watching. Chinese law compels citizens to assist government data collection on demand. Microsoft failed to disclose this arrangement in their security plans. Now the Pentagon is investigating whether anyone slipped something into the code. This is what happens when you let contractors police themselves.