Skip to content
Fiscal Receipts

Information Systems Security Program

NRDT&EPartial Reconciliation0303140N
What it is
Information Systems Security Program — a research & development program run by Navy.
What changed
+$28.8M FY25→26
Who gets it
No award linkage at high confidence.

Budget Figures

FY24 Actuals
$31.5M
FY25 Total
$35.3M
FY26 Request
$64.1M
FY25→26 Change
$28.8M

FY2026 award data is a partial year — USASpending awards are reported on a rolling basis and the fiscal year does not close until September 30. why partial FY2026 data? →

Budget Trajectory
FY24: $31.5MFY25: $35.3MFY26: $64.1MFY24FY25FY26
FY24
$31.5M
FY25
$35.3M
FY26
$64.1M
Decade view — each figure cites its own President's Budget edition
FY2015 actuals — PB2017 editionFY2016 actuals — PB2018 editionFY2017 actuals — PB2019 editionFY2018 actuals — PB2020 editionFY2019 actuals — PB2021 editionFY2020 actuals — PB2022 editionFY2021 actuals — PB2023 editionFY2022 actuals — PB2024 editionFY2023 actuals — PB2025 editionFY2024 actuals — PB2026 editionFY2016 enacted — PB2017 editionFY2017 enacted — PB2018 editionFY2018 enacted — PB2019 editionFY2019 enacted — PB2020 editionFY2020 enacted — PB2021 editionFY2021 enacted — PB2022 editionFY2022 enacted — PB2023 editionFY2023 enacted — PB2024 editionFY2024 enacted — PB2025 editionFY2025 enacted — PB2026 editionFY2017 request — PB2017 editionFY2018 request — PB2018 editionFY2019 request — PB2019 editionFY2020 request — PB2020 editionFY2021 request — PB2021 editionFY2022 request — PB2022 editionFY2023 request — PB2023 editionFY2024 request — PB2024 editionFY2025 request — PB2025 editionFY2026 request — PB2026 editionFY15FY26

● actuals (line)  ·  ○ enacted  ·  ◇ request — gaps are editions the program is absent from, never interpolated.

SeriesFY15FY16FY17FY18FY19FY20FY21FY22FY23FY24FY25FY26
Actuals$22.7M$29.5M$32.7M$49.3M$43.3M$43.9M$38.1M$32.6M$33.0M$31.5M
Enacted$28.1M$38.5M$50.3M$44.2M$44.9M$38.8M$33.3M$33.8M$33.4M$35.3M
Request$38.5M$50.3M$44.2M$41.9M$39.1M$33.3M$33.8M$33.4M$35.3M$64.1M

blank = series not published for this year; – = absent from that edition.

Asked vs spent: the PB2017 book requested $38.5M for FY2017; the PB2019 book reports $32.7M actually spent — $5.80M below the request.

Program Lineage

No predecessor/successor lineage was recorded for this program element — no FY-to-FY transfer into or out of this line was stated in the ingested J-books, and none was inferred from the program structure.

Description

Mission Cybersecurity Engineering

This effort funds a continuing cybersecurity program, Situational Awareness Boundary Enforcement and Response (SABER), and a maturing Cybersecurity project, High Availability Virtual Environment (HAVEN). SABER is the research, design, development, testing, and installation of Cybersecurity solutions for installed integrated computer networks to include shipboard Hull Mechanical and Electrical (HM&E), Navigation Systems, Combat Systems, Fire Control, Sonar, Radar, Communications, and other shipboard computerized control systems for all afloat U.S. Navy platforms. SABER provides network boundary defense and situational awareness to protect and detect against external and internal cybersecurity-threats. HAVEN is a secure operating environment that provides a resilient and redundant infrastructure platform for rapid software deployment and system restoration. HAVEN provides the secure operating environment for SABER and a secure hosting environment. HAVEN has been considered a part of SABER and continued HAVEN development has led the Navy to understand that this capability may have use beyond hosting SABER.

Mission Information Sys Security Program

The Information Systems Security Program (ISSP) ensures the protection of Navy and Navy hosted joint telecommunication and Information Technology (IT) systems from cyber exploitation and attack. The ISSP extends cybersecurity to ensure confidentiality, integrity, and availability of these systems and content processed, stored, or transmitted therein by performing the acquisition, modernization and sustainment of cybersecurity platforms and systems; cyberspace operations include both defensive and offensive measures, which preserve the ability to protect data, networks, net-centric capabilities, and other designated systems while projecting power by the application of force in or through cyberspace. The ISSP includes the protection of the Navy's National Security Systems (NSS). The ISSP must be rapid, predictive, adaptive, and tightly coupled to cyberspace technology. The ISSP provides cybersecurity systems and infrastructure based on mission impacts, cybersecurity threats, information criticality, vulnerabilities, and required defensive countermeasure capabilities. The ISSP focuses on efforts that address the risk management of cyberspace, which provides capabilities to protect, detect, restore and respond. The ISSP provides the Navy with the following cybersecurity elements: (1) defense of NSS, including other mission requirements (details held at a higher classification), naval weapons systems, critical naval infrastructure for Command, Control, Communications, Computers, & Intelligence (C4I) afloat and ashore networks, joint time and navigation systems, and industrial control systems, using modern cryptographic solutions and cyber security tools; (2) technologies for the Navy's Computer Network Defense (CND) service provider that accelerates the Navy's ability to prevent, constrain, and mitigate cyber attacks and critical vulnerabilities; (3) Navy Cyber Situational Awareness (NCSA) technologies that provides the operational context for cyber threat intelligence and Situational Awareness (SA), from external boundaries to tactical edge infrastructures; (4) assurance of the Navy's Cryptography (Crypto) telecommunications infrastructure and the wireless spectrum; (5) sensing cyber threats across all Navy ashore and afloat networks to expand the capabilities of monitoring, assessing, and detecting adversary activities across multiple enclaves through the collection of tools in SHARKCAGE; (6) assurance of joint-user cyberspace domains, using a Defense-In-Depth (DiD) security architecture and its alignment with the Joint Information Environment (JIE)/Joint Regional Security Stack (JRSS); (7) assurance technologies, including Key Management (KM) and Public Key Infrastructure (PKI). The Cybersecurity Engineering effort funds a continuing cybersecurity program, Situational Awareness Boundary Enforcement and Response (SABER), and a maturing Cybersecurity project, High Availability Virtual Environment (HAVEN). SABER is the research, design, development, testing, and installation of Cybersecurity solutions for installed integrated computer networks to include shipboard Hull Mechanical and Electrical (HM&E), Navigation Systems, Combat Systems, Fire Control, Sonar, Radar, Communications, and other shipboard computerized control systems for all afloat U.S. Navy platforms. SABER provides network boundary defense and situational awareness to protect and detect against external and internal cybersecurity-threats. HAVEN is a secure operating environment that provides a resilient and redundant infrastructure platform for rapid software deployment and system restoration. HAVEN provides the secure operating environment for SABER and a secure hosting environment. HAVEN has been considered a part of SABER and continued HAVEN development has led the Navy to understand that this capability may have use beyond hosting SABER.

Mission Communications Security R&D

The Information Systems Security Program (ISSP) Research Development Test & Evaluation (RDT&E) efforts extend our cybersecurity and resiliency, provide Defensive Cyberspace Operations (DCO), and cross domain solutions to protect data, Department of Defense (DoD) Information Networks (DoDIN), net-centric operations, the forward deployed, and other designated systems to protect cyberspace and critical warfighting capabilities. This project includes a rapidly evolving development, design and application integration effort to modernize cryptographic equipment and ancillaries with state-of-the-art replacements to counter evolving and increasingly sophisticated threats. Communications Security (COMSEC) and Transmission Security (TRANSEC) are evolving from stand-alone, dedicated devices to embedded modules incorporating National Security Agency (NSA) approved cryptographic engines, loaded with the certified algorithms and keys, and interconnected via industry-defined interfaces. This includes the DoDIN capability requirements document for the development of Content Based Encryption (CBE). Computer Network Defense (CND): The CND program provides cyberspace capabilities to secure the Cyber Domain. CND is a combination of hardware, software, sets of processes and protective measures that use computer networks to detect, monitor, protect, analyze and defend against network infiltrations resulting in service/network denial, degradation and disruptions. CND enables a government or military institute/organization to defend against network attacks perpetrated by malicious or adversarial computer systems or networks. Navy Cryptography (Crypto): Navy Crypto modernizes legacy cryptographic equipment which includes families of COMSEC and TRANSEC devices that are divided into crypto voice, crypto data, crypto products and associated ancillary devices. These devices provide modern cryptographic solutions to replace obsolete, legacy devices within the crypto categories to meet mandated National Security Agency (NSA) cease key dates for modernized encryption. Advanced Cryptographic Capabilities (ACC) will provide NSA mandated cryptographic security software modernization of various communications security devices by cease key dates (details held at a higher classification). Key Management (KM): KM monitors and tracks capability verification testing, designs, and tests capabilities to provide a net-centric web-based architecture, for the ordering, management, and distribution of all cryptographic key material to support Navy users. Public Key Infrastructure (PKI): The DoD PKI program, under the authority of the Under Secretary of Defense (USD) for Acquisition & Sustainment (USD(A&S)) develops and tests PKI equipment and is responsible for meeting statutory and regulatory requirements for the DoD PKI program. The Navy PKI program tests and implements products for afloat networks and ashore non-Navy Marine Corps Intranet (NMCI) networks and institutionalizes DoD PKI Increment 2 capabilities so that person and non-person entities can securely access all authorized DoD resources. SHARKCAGE: SHARKCAGE is the U.S. Navy's Defensive Cyberspace Operations (DCO) analysis enclave and means to achieve cyberspace detection-in-depth for maritime forces afloat and ashore. SHARKCAGE is the mechanism by which units, groups, and fleets will gain an Attack Sensing and Warning (AS&W) capability and how Commander, Task Force 1020/Navy Cyber Defense Operations Command (NCDOC) will achieve unity of effort and economy of force across the Navy's DCO forces. SHARKCAGE is a Navy-specific platform to complement where existing and future theater, joint, and national capabilities are insufficient for detection of adversary activities onboard maritime warfighting platforms that are located at the tactical-edge and distributed across the globe. Navy Cyber Situational Awareness (NCSA): NCSA is a command and control infrastructure that provides Navy commanders with timely, trusted, and comprehensive Situational Awareness (SA) of the cyberspace domain to include tailored, near real-time visualization of network health, vulnerabilities, and operational readiness through the correlation of data from multiple sources. NCSA combines asset data, baseline configuration data, and real-time threat data which is critical for defending a fully interconnected network infrastructure. NCSA enables early threat detection and timely decision making. The NCSA software suite includes the Navy Commander's Cyber Dashboard (NCCD), a single view into the platform's cyber readiness, providing better visibility into Information Warfare readiness trends and drivers, as well as current cyber risk to mission; this view is provided by the Readiness Analytics and Visualization Environment (RAVEN) capability. RAVEN is a visualization capability that ingests a variety of readiness and cybersecurity inputs to create visual dashboards. NCSA implements hybrid cloud based modernized Navy Big Data Platform (BDP) instances, including pre-production development and operational instances, that enable data sharing between Navy Defensive Cyberspace Operations (DCO) data and analytics fabric and joint DCO and cyber situational awareness systems as described in the Joint Cyber Warfighting Architecture (JCWA). FY26 will focus on efforts that address the risk management of cyberspace, which provides capabilities to identify, protect, detect, restore and respond. The Information Systems Security Program (ISSP) provides the Navy with the following cybersecurity elements: (1) defense of National Security Systems (NSS), including other mission requirements (details held at a higher classification), naval weapons systems, critical naval infrastructure for Command, Control, Communications, Computers, & Intelligence (C4I) afloat and ashore networks, joint time and navigation systems, and industrial control systems, using modern cryptographic solutions and cyber security tools; (2) technologies supporting the Navy's Computer Network Defense (CND) service provider that will help the Navy's ability to prevent, constrain, and mitigate cyber-attacks and critical vulnerabilities; (3) Navy Cyber Situational Awareness (NCSA) technologies that provide the operational context for cyber threat intelligence and Situational Awareness (SA), from external boundaries to tactical edge infrastructures; (4) assurance of the Navy's Crypto telecommunications infrastructure and the wireless spectrum; (5) sensing cyber threats across all Navy ashore and afloat networks to expand the capabilities of monitoring, assessing, and detecting adversary activities across multiple enclaves through the collection of tools in SHARKCAGE; (6) assurance of joint-user cyberspace domains, using a Defense-In-Depth (DiD) security architecture and its alignment with the Joint Information Environment (JIE)/Joint Regional Security Stack (JRSS), the Integrated Navy Operations Command and Control System (INOCCS), and Zero Trust Architecture (ZTA) concepts; (7) assurance technologies, including Key Management (KM) and Public Key Infrastructure (PKI).

Mission Information Assurance

The goal of the Information Systems Security Program (ISSP) is to ensure the continued protection of Navy and joint information and information systems from hostile exploitation and attack. The ISSP activities address the triad of Defense Information Operations: protection, detection, and reaction. Evolving attack sensing (detection), warning, and response (reaction) responsibilities extend far beyond the traditional ISSP role in the protection of Information Systems, including weapons systems. Focused on the highly mobile forward deployed subscriber, the Navy's adoption of Network-Centric Warfare (NCW) places demands upon the ISSP, as the number of users expands significantly and the criticality of their use escalates. Today, the ISSP protects an expanding core of services critical to the effective performance of the Navy's mission, as well as developing information assurance technology and systems that are resilient and survivable in the face of adversarial attacks. Features that are critical in supporting the Navy's concept of Distributed Maritime Operations (DMO). The rapid rate of change in the underlying commercial and government information infrastructures makes the provision of security an increasingly complex and dynamic problem. Information Assurance (IA) technology mix and deployment strategies must evolve quickly to meet rapidly evolving threats and vulnerabilities. No longer can information security be divorced from the information infrastructure. The ISSP enables the Navy's war fighter to trust in the availability, integrity, authentication, privacy, and non-repudiation of information. This project includes funds for advanced technology development, test and evaluation of naval information systems security based on leading edge technologies that will improve information assurance (e.g., situational awareness and information infrastructure protection) across all command echelons to tactical units afloat and war fighters ashore. This effort will provide the research to develop a secure seamless interoperable, common operational environment of networked information systems in the battle space and for monitoring and protecting the information infrastructure from malicious activities. This effort will provide naval forces a secure capability and basis in its achievement of protection from unauthorized access and misuse, and optimized IA resource allocations in the information battle space. This program will also develop core technology to: (1) improve network infrastructure resistance and resiliency to attacks; (2) enable the rapid development and certification of security-aware applications and information technologies in accordance with the common criteria for IA and IA-enabled information technology products by the National Security Telecommunications and Information Systems Security Committee; and (3) measure the effectiveness and efficiency of IA defensive capabilities under naval environments. The program will develop common architectural frameworks that facilitate integration of network security capabilities, enable effective seamless interoperation, and contribute to a common consistent picture of the networked environment with respect to information assurance and security. This effort will address the need for a common operational picture for IA, as well as assessment of security technology critical to the success of the mission. This effort will also initiate requirements definition for situational awareness capabilities to support computer network defense in a highly-distributed, homogeneous, and heterogeneous networks including mobile and embedded networked devices. This effort also includes the architectural definition of situational awareness and visualization capabilities to support active computer network defense and support underlying data mining and correlation tools. This includes addressing the capability to remotely manage and securely control the configurations of network security components to implement changes in real time or near real time. This program will also initiate requirements definition for secure coalition data exchange and interoperation among security levels and classifications, and ensure approaches address various security level technologies as well as emerging architectural methods of providing interoperability across different security levels. IA will examine multi-level aware applications and technologies including databases, web browsers, routers/switches, etc. Efforts will also initiate infrastructure protection efforts as the Navy develops network centric architectures and warfare concepts, ensuring an evolutionary development of security architectures and products for Information Assurance (IA) that addresses Navy infrastructure requirements. IA will ensure the architectures evolve to provide proper protection as technology, Department of Defense (DoD) missions, and threats continuously evolve. IA includes defensive protections as well as intrusion monitoring (sensors), warning mechanisms, and response capabilities in the architecture. Ensure the unique security and performance requirements of tactical systems, including those operating various security levels are addressed. Also, the program will initiate the efforts to conceptualize new network centric warfare technology to protect our assets, such as secure network gateways, routers, components and tools that improve the survivability of Navy networks. Additionally, IA will provide systems security engineering, certification and accreditation support for high-confidence naval information systems and ensure certification and accreditation approaches are consistent with Navy and DoD requirements.

Justification

No accomplishments or planned-program narratives in this line's J-book detail — some exhibits carry figures without per-project prose.

Budget Line Items(workbook-cited)

Exhibit R-1

AccountOrgTypeAmount
Research, Development, Test and Evaluation, NavyNFY24 Actuals$31.5M
Research, Development, Test and Evaluation, NavyNFY25 Enacted$35.3M
Research, Development, Test and Evaluation, NavyNFY25 Total$35.3M
Research, Development, Test and Evaluation, NavyNFY26 Disc. Request$64.1M
Research, Development, Test and Evaluation, NavyNFY26 Total$64.1M

Budget Details(R-2/P-40 facts)

ProjectAll Prior YearsFY24 ActualsFY25 TotalFY26 BaseFY26 Request
3244: Cybersecurity Engineering$0$0$0$30.2M$30.2M
3230: Information Assurance$31.2M$2.23M$2.23M$2.39M$2.39M
0734: Communications Security R&D$661.4M$29.2M$33.1M$31.5M$31.5M
Program Element$692.7M$31.5M$35.3M$64.1M$64.1M

No follow-the-dollar view — this program's awards haven't been crosswalked at high confidence (flows cover 17 of 1741 programs). why coverage is partial? →

Awards

No awards are linked to this program element at high confidence — the budget→award crosswalk only asserts links it can defend, and this line has none yet.

Lobbying Mentions

No Senate LDA lobbying filing in the tracked data mentions this program element by code or alias.

No research dossier for this program — dossiers cover 50 of 1741 programs, the largest fully J-book-detailed lines by FY2026 requested dollars. why no dossier here? →