Information Systems Security Program
Abstract
The Information Systems Security Program funding line supports the Army Network Modernization Strategy LOE 1, Unified Network. Efforts are aligned to support the Network-Cross Functional Team capability set approach to achieve the network modernization strategy. Project 491: Army CIO/G6 manages Project 491 Project 491: Information Assurance (IA) Development supports the implementation of the National Security Agency (NSA) developed Communications Security (COMSEC) Modernization and Key Management (KM) technologies within the Army. This including current and next generation encryption techniques, current and future Key Management Infrastructure (KMI) and technology migrations. This program provides oversight in developing policies, guidance, standard operating procedures and recommendations in integrating COMSEC and KM techniques into specific systems in support of securing the Army Tactical and Enterprise Networks. This entails architecture studies, system integration and testing, developing installation kits, and technological collaborations with NSA, DISA and other Services for enterprise and last mile implementations. The program assesses, develops and integrates Cyber Security (CS)/COMSEC tools (hardware and software) which provide protection for fixed infrastructure post, camp and station networks as well as tactical networks. The cited work is consistent with Strategic Planning Guidance (SPG) and the Army Modernization and Strategy Plan (AMSP). IA Development funding implements and establishes functional and technical boundaries of cryptographic, key management and IA capabilities in coordination with the NSA, the DISA, and Joint Services, to secure National Security Systems (NSS), and National Security Information (NSI). Technical evaluations assess the security, operational effectiveness and network interoperability of advanced concept technologies to develop policies, standards, and fundamental building blocks for Army COMSEC capabilities that reduce the risk of future material solutions that could underperform and disrupt classified operations. Develop and publish the COMSEC Implementation Planning Guidance to identify, standardize, and govern the insertion of CS capabilities to bridge operational gaps and support the DoD and NSA mandated requirements to enhance network capacity while providing for secure information exchange of voice, video, and data in accordance with the Army Network Campaign Plan. This will be accomplished by interoperability evaluation, standards testing, and CS, System of System Network Vulnerability Assessments (SoS NVA) for Army Capability Sets for CS/COMSEC capabilities that provide protections for tactical and fixed infrastructure post, camp, and station networks. Project 491 FY 2022 Justification: This funding enables the continuation of oversight for the executions of the Army's COMSEC Modernization initiatives including major Advanced Cryptographic Capabilities (ACC) updates and replacements of existing devices and systems to meet NSA mandates. Continue to support the evaluation and testing of new technologies to support DoD Cryptographic Moderation 2 (CM2) Army implementations including Transmission Security (TRANSEC), EKMS to KMI migration and S-ICAN/ITN architecture future Capability Set developments. Support efforts to provide updated end-to-end, tactical-to-strategic COMSEC standardization and implementation guidance to meet Army's operational requirements. Continuous funding will enable the evaluations and maturity assessment of new COMSEC and key management capabilities developed by DoD joint KMI program for Army fielding to protect and strengthen the Army Network posture, with reduced cryptographic interoperability issues for both embedded and standalone systems. This funding also supports the risk reduction testing to document operational value of commercial products prior to insertion for Army use. Provide timely test and evaluate results to enable the Army to make sound investment strategic decisions and to reduce or eliminate duplications. Also supports efforts to update and develop policies to posture Army's operations to implement innovative cryptographic and key management tools and services. Perform System of System Network Vulnerability Assessments (SoS NVA) to provide protections for the Army Integrated Tactical Networks. The Defensive Cyberspace Operations (DCO) program provides initial capabilities that enable passive and active cyberspace defense operations to preserve friendly cyberspace capabilities and protect data, networks, net-centric capabilities, and other designated systems. Big Data Pilot provides an advanced analytics capability capable of ingesting structured, semi-structured, and unstructured data from multiple data sources (e.g., Joint Regional Security Stacks (JRSS), intrusion detection systems, intrusion prevention systems, network device log files, trouble tickets, firewalls, proxies, web and applications server log files, etc) and proves situational awareness of cyberspace battlefield. It provides the computer network defense provider with common analytic platform which informs and reduces risk associated with future material solutions and forms a blueprint for future Big Data Analytics. Big Data (analysis-of-all DoD Information Network sensor data) provides two optimized and accredited clusters deployed in support of JRSS and Defense Research and Engineering Network (DREN) with a tools suite accessible to Cyber Mission Forces via secure remote access. The Army's DCO activities are a construct of active cyberspace defenses which provide synchronized, real-time capability to discover, detect, analyze, and mitigate threats to and vulnerability of DoD networks and systems. Project DV4 & DV5: COMSEC is governed by the Chairman of the Joint Chiefs of Staff Instruction (CJCSA) 6510. In order to ensure Warfighters continue to have secured communications (i.e., encrypted data and voice), Army communications systems are required to support modern cryptographic capabilities by implementing modern algorithms. These efforts are consistent with Strategic Planning Guidance (SPG). These funding lines support the Army Network Modernization Strategy LOE 1, Unified Network. Efforts are aligned to support the Network-Cross Functional Team capability set approach to achieve the network modernization strategy. Project DV4: The Army Key Management Infrastructure (AKMI) is the Army's implementation of the National Security Agency (NSA) KMI ACAT IAM program, automating the functions of COMSEC electronic key management, control, planning, and distribution. AKMI supports the Army's ability to communicate and distribute Cryptographic data on the Army's tactical and strategic networks by limiting adversarial access to and reducing the vulnerability of, Army Command, Control, Communications, Computers, Cyber, Intelligence (C5I) systems. AKMI devices receive, store, manage, and transfer electronic key through the network to be loaded into communication devices such as radios and satellites to secure the network. Without this technology Warfighters are required to manually receive their cryptographic products by traveling to COMSEC account locations (which may not be co-located) and manually fill their devices. Project DV4 FY 2022 Justification: This funding line supports COMSEC technologies within the Army with allocations for the following: $0.987M, Reprogrammable Single Chip Universal Encryptor (RESCUE) to create a secure, reprogrammable cryptographic engine in providing Cryptographic Modernized Capabilities including future Over the Network Keying (OTNK) to Fill Devices and End Cryptographic Units (ECU)s. The RESCUE is a potential solution for meeting the cryptographic requirements for the NGLD-M which is available as an option for integration by NGLD-M hardware developers. As of FY2022 NGLD-M development will transfer from PE 0303140A, Project DV4 to PE 0605144A, Project BY6 funding line starting FY2022. PE 0605144A, Project BY6 was established to clearly identify requirements for NGLD-M development and is not considered a new start effort. Project DV5: Crypto Modernization (Crypto Mod) performs test, evaluation, development, and configuration management for cryptographic devices that receive key through fill devices and allow for secure communication through Army devices such as radios and satellite terminals. This program utilizes National Security Agency (NSA) developed Communications Security (COMSEC) technologies within the Army providing encryption, trusted software, or standard operating procedures, and integrating these mechanisms into specified systems in support of securing the Army Tactical and Enterprise Networks. The effort supports network operations from end-to-end throughout the force and the Common Operating Environment (COE) thus mitigating networked vulnerabilities to Army information security systems. In order to ensure Warfighters continue to have secured communications (i.e., encrypted data and voice), Army communications systems are required be upgraded to modern algorithms to meet emerging threat developed by our adversaries. Crypto Modernization necessitates the utilization of the latest NSA cryptographic capabilities in order to defeat adversarial efforts to decrypt, disrupt, or exploit US Army networks. COMSEC is the Army's implementation of NSA protections to create a unified network that is protected, resilient, and survivable. Project DV5 FY 2022 Justification: The program continues testing and evaluation of COMSEC devices to confirm capability and interoperability on Army networks and tactical systems as well as identifying risk areas for compliance with COMSEC regulations and procedures. The program will test and evaluate Crypto Systems compliant devices, Suite B IPSec devices built on commercial standards, Cryptographic High Value Product (CHVP), Commercial Solutions for Classified (CSfC) Guidance, and new software releases to High Assurance Internet Protocol Encryptor (HAIPE) 4.X devices in accordance with AR 700-142 Revision dated 8 June 2018. The program tests interoperability and provides ways to insert Data At Rest (DAR) and Data In Transit (DIT) technology within the existing and future network infrastructure. Additionally, this program evaluates performance of technologies and provides direction to ensure the lowest impact on performance while providing the greatest protection from loss of sensitive data.
Document Details
- Document Type
- R2 Budgetary Justification
- Publication Date
- Oct 01, 2022
- Source ID
- 0303140A_7_2040_PB_2022
- Change Summary Explanation
- FY 2022 decrease of $13.108 million based on establishment of the new funding line in support of NGLD-M development. Funding was realigned from PE 0303140A Project DV4 to 0605144A Project BY6 starting in FY 2022.
- Service Agency Name
- Army
Entities
Organizations
- United States Army
Related Documents
- Child Project: Information Assurance Development
- Child Accomplishment: Oversight and implementation guidance of emerging Cryptographic and CS capabilities to ensure interoperability to maintain compliance with DoD, NSA, and Army policies and regulations. (CIO/G6)
- Child Cost Item: c64c769dddf36256c8fc6622e25dcc96
- Child Cost Item: 28573d60388f8b09e90f75dbfdd47e0d
- Child Cost Item: 59e95722add66333feae60d859f7ef2e
- Child Cost Item: 8229760fc8caf403d7f2dda579f4f022
- Child Cost Item: 0e0681cf8568de2487eee4de881ff209
- Child Cost Item: 70c7484b739e0c0850ef833c30821e65
- Child Cost Item: 46990121f26f6ab8783dc54019a1365e
- Child Cost Item: 091c9c2c01754a4c324d8a5b3796da9f
- Child Cost Item: 8551116a8eafbaf7a01900d72f9ebb3f
- Child Cost Item: 47da9322963adf1faece74dfdbb9104a
- Child Cost Item: dfb4fa981418850ce36590616937a7b6
- Child Cost Item: 31ad329956d610d191d535a2abcfb71a
- Child Project: Key Management Infrastructure (KMI)
- Child Accomplishment: Reprogrammable Cryptographic Chip Development and Evaluation
- Child Accomplishment: NGLD Medium Development and NSA Certification
- Child Accomplishment: Program Management Support
- Child Cost Item: 097d4a18a8335a9113bd9e300ba47cd3
- Child Cost Item: 265d7e1655f06dab082adefb67fff5f2
- Child Cost Item: b57d83593e85675c0ee87bcb93d7fc63
- Child Cost Item: b68b4464e21854e4203475691856b612
- Child Cost Item: e937c7d678145adc7137db1e87573e30
- Child Project: Crypto Modernization (Crypto Mod)
- Child Accomplishment: VINSON/ANDVT (Advanced Narrowband Digital Voice Terminal) Cryptograph Modernization (VACM) program
- Child Accomplishment: Cryptographic Systems Test and Evaluation
- Child Accomplishment: High Assurance Internet Protocol Encryption (HAIPE) extension manager
- Child Cost Item: 0477275da03100e96a2264fa7512a901
- Child Cost Item: 66562d92df3bd642155bfc38e9b5a9db
- Child Cost Item: 0e8739fa4719cc4915ae331f5016e76a
- Child Cost Item: ce50d18a87b05358d5681be21a6e4d22
- Child Cost Item: f17e5c96626830a66ef98ff554e179a2
- Child Cost Item: 9dd1854135d885ac2d3dc281737d55fb
- Child Cost Item: f67c25c6e7aba443a8fa31ed3a094341
- Child Cost Item: 96559c122829edf3f813371def4688f6
- Child Cost Item: f60597b3b1dec4fd383b1789289da544
- Child Cost Item: f40166cd6016e0170979612d63372f97