Information Sys Security Program

Abstract

The Information Systems Security Program (ISSP) ensures the protection of Navy and Navy hosted joint telecommunication and Information Technology (IT) systems from cyber exploitation and attack. The ISSP extends cybersecurity to ensure confidentiality, integrity, and availability of these systems and content processed, stored, or transmitted therein by performing the acquisition, modernization and sustainment of cybersecurity platforms and systems; cyberspace operations include both defensive and offensive measures, which preserve the ability to protect data, networks, net-centric capabilities, and other designated systems while projecting power by the application of force in or through cyberspace. The ISSP includes the protection of the Navy's National Security Systems (NSS). The ISSP must be rapid, predictive, adaptive, and tightly coupled to cyberspace technology. The ISSP provides cybersecurity systems and infrastructure based on mission impacts, cybersecurity threats, information criticality, vulnerabilities, and required defensive countermeasure capabilities. The ISSP focuses on efforts that address the risk management of cyberspace, which provides capabilities to protect, detect, restore and respond. The ISSP provides the Navy with the following cybersecurity elements: (1) defense of National Security Systems (NSS), including the Nuclear Command, Control, and Communications, Navy (NC3-N) system, naval weapons systems, critical naval infrastructure for Command, Control, Communications, Computers, & Intelligence (C4I) afloat and shore networks, joint time and navigation systems, and industrial control systems, using modern cryptographic solutions and cyber security tools; (2) technologies for the Navy's Computer Network Defense (CND) service provider that accelerates the Navy's ability to prevent, constrain, and mitigate cyber attacks and critical vulnerabilities; (3) Navy Cyber Situational Awareness (NCSA) technologies that provides the operational context for cyber threat intelligence and Situational Awareness (SA), from external boundaries to tactical edge infrastructures; (4) assurance of the Navy's Cryptography (Crypto) telecommunications infrastructure and the wireless spectrum; (5) sensing cyber threats across all Navy shore and afloat networks to expand the capabilities of monitoring, assessing, and detecting adversary activities across multiple enclaves through the collection of tools in SHARKCAGE; (6) alignment to Navy's Insider Threat program; (7) assurance of joint-user cyberspace domains, using a Defense-In-Depth (DiD) security architecture and its alignment with the Joint Information Environment (JIE)/Joint Regional Security Stack (JRSS); (8) assurance technologies, including Key Management (KM) and Public Key Infrastructure (PKI).

Open PDF

Document Details

Document Type
R2 Budgetary Justification
Publication Date
Oct 01, 2019
Source ID
0303140N_7_1319_PB_2019
Change Summary Explanation
The FY 2019 funding request was reduced by $0.704 million to account for the availability of prior year execution balances. TECHNICAL: N/A SCHEDULE: Computer Network Defense (CND): - Added Build 14 Development milestone. Starts in 3QFY22. Navy Cryptography (Crypto): - VINSON/Advanced Narrowband Digital Voice Terminal (ANDVT) Cryptographic Modernization (VACM) deliveries shifted from 1QFY18 to 2QFY18 in accordance with the United States Air Force (USAF) schedule. - Advanced Cryptographic Capability (ACC) Fielding Decision added to Q4FY18 in accordance with the National Security Agency (NSA) schedule. - KGV-11M Preliminary Design Review (PDR) shifted from 4QFY18 to 1QFY19, in accordance with the schedule. - KGV-11M Development Test and Evaluation (DT&E) shifted from 2QFY20 to 1QFY20, in accordance with the schedule. Key Management (KM): - Capability Increment (CI)-2 Spiral 2 Spin 3 Development, Integration and Test shifted from Q1FY18 to Q3FY17. - CI-2 Spiral 2 Deliveries shifted from Q2FY18 to Q1FY18. SHARKCAGE & Navy Cyber Situational Awareness (NCSA): - SHARKCAGE and NCSA are Rapid Deployment Capability (RDC) efforts. An RDC is the Navy's implementation of the Department of Defense (DoD) 5000 defined "Accelerated Acquisition Program." It provides the ability to react immediately to a newly discovered enemy threat(s) or potential enemy threat(s) through tailored procedures, to allow for fielding of mature capabilities based on Commercial Off-The-Shelf (COTS) and Non-Developmental Item (NDI) products within a two year period. At the end of that period SHARKCAGE and NCSA are planned to transition to respective Acquisition Category (ACAT) programs. - SHARKCAHE & NCSA RDC Delivery completion shifted from 4QFY19 to 3QFY19. - SHARKCAGE & NCSA Transition Deliveries start shifted from 1QFY20 to 4QFY19. FUNDING: Navy Cryptography (Crypto): - FY19 increase is for continued development of Advanced Cryptographic Capabilities (ACC) security software of various Communications Security (COMSEC) devices and compatibility of cryptographic devices capable of receiving software updates. Key Management (KM): - FY19 decrease aligns to the completion of CI-2 Spiral 2/Spin 3. SHARKCAGE: - FY19 decrease reflects a realignment within SHARKCAGE from Research, Development, Test and Evaluation (RDTE) to Other Procurement, Navy (OPN) and Operations and Maintenance, Navy (OMN) based on program requirements shifting from development to procurement, integration and sustainment.
Service Agency Name
Navy

Entities

Organizations

  • United States Navy

Tags

Communities of Interest

  • Cyber

DTIC Thesaurus Topics

  • Command And Control
  • Computer Network Security
  • Computer Networks
  • Computer Security Techniques
  • Computers
  • Cross Domain
  • Cyber Defense Techniques
  • Cyber Protection
  • Cyberattacks
  • Cybersecurity
  • Cyberspace Operations
  • Information Systems
  • Risk Analysis
  • Situational Awareness
  • Systems Engineering
  • Test And Evaluation
  • Warfare

Fields of Study

  • Computer science

Readers

  • Cybersecurity.
  • Enterprise Information Systems Architecture and Joint Command Capability Interoperability Support.

Technology Areas

  • Cyber
  • Fully Networked C3
  • Fully Networked C3 - Command and Control

Related Documents