# Information Systems Security Program Plans and Accomplishments

**R-2A activity** of project 140 — Information Systems Security Program (ISSP)  
**Program element:** 0303140D8Z — Information Systems Security Program  
**Component:** Defense-Wide · **Budget Activity:** 7  
**Vintage:** President's Budget PB2027  
**Canonical URL:** https://hitchintel.com/programs/0303140D8Z/140/a0  
**Parent:** https://hitchintel.com/programs/0303140D8Z

## Summary

This activity requests $35.2M in FY2027, 100% of project 140, up 44% on FY2026. The R-2A exhibit describes it across FY2025–FY2027, including what the FY2027 money is planned to buy.

## What the FY2027 request buys

**FY2027 planned work.** Continue to collaborate with industry to develop new cybersecurity technologies for legacy network upgrades, evolving into new cybersecurity architectures and command and control capabilities. Continue tactical networks, coalition, and mission partner networks development and engineering support. Develop and implement strategies to defend against sophisticated cyber adversaries and large-scale incidents, including threat-based system security engineering and developing critical design artifacts. Continue improving built-in cybersecurity, mission assurance, mitigation analyses, and vulnerability detection (hardware and software testing) in acquisition programs. Deploy Microsoft 365 E5 licenses across DoWIN​. • Automate the implementation plans. • Post quantum cryptography strategy. • Streamline the risk assessment and authorization processes for software-enabled products and services. • Standardize systems modeling language v2 use to support enterprise modeling. • Continuing with cyber scholarship program.

**FY2026 to FY2027 change.** FY 2027 increase due to Post quantum requirements

## Before the request year

**FY2026 plans — current year.** Collaborate with industry to develop new cybersecurity technologies for legacy network upgrades, evolving into new cybersecurity architectures and command and control capabilities. Develop and refine policies for acquisition program protection strategies and oversight. Develop strategies, standards, and tools for supply chain risk management, collaborating with industry on global sourcing standards. Evaluate cyber activities to efficiently mitigate investment decisions using cybersecurity metrics, supporting policy development, refinement, and oversight. Formulate programmatic advice and participate in advisory and governance bodies. Accelerate cloud security guidance and procedures by commercial cloud service providers. Refine and oversee comprehensive secure mobility processes, policies, and cybersecurity capabilities. Continue tactical networks, coalition, and mission partner networks development and engineering support. Develop and implement strategies to defend against sophisticated cyber adversaries and large-scale incidents, including threat-based system security engineering and developing critical design artifacts. Support analyses on DoW cloud-based computing cybersecurity, risk factors, and mitigation controls refinement, as part of the Risk Management Framework (RMF) to accelerate DoW cloud adoption. Refine and integrate policies with the RMF, supportive standards, guidance, efficiencies, and web-based processes to strengthen information system controls and protections. Continue improving built-in cybersecurity, mission assurance, mitigation analyses, and vulnerability detection (hardware and software testing) in acquisition programs. Deploy Microsoft 365 E5 licenses across DoWIN​. • Automate the implementation plans. • Post quantum cryptography strategy. • Streamline the risk assessment and authorization processes for software-enabled products and services. • Standardize systems modeling language v2 use to support enterprise modeling. • Continuing with cyber scholarship program.

**FY2025 accomplishments.** $19.124 million: • Continue base program initiatives in prior budget year. $7.500 million: • To accelerate Zero Trust (ZT) adoption and achieve target level ZT by the end of FY27, this effort will collaborate with Joint Warfighting Cloud Cabiliity (JWCC) cloud service providers and industry partners to develop and execute ZT pilot activities and proof-of-concept evaluations, including cloud prototypes $9.503 million: • Support returning DoD Cyber Service Academy (DoD CSA) recruitment scholars

## Funding

| Fiscal Year | Estimate Type | Amount ($M) |
|---|---|---|
| FY2025 | Actual | 29.8 |
| FY2026 | Enacted | 24.5 |
| FY2027 | Request | 35.2 |

> Prior, current and budget year only — an R-2A activity carries no five-year plan. It sums exactly into its project in the request year and not necessarily in any other.

## Source & machine access

- **Source:** FY2027 Office of the Secretary of Defense RDT&E Budget Justification, Exhibit R-2A, PE 0303140D8Z project 140 (PB PB2027). Narrative is the government's own text.
- **No marks, no contractors at this grain** — congressional marks land on the program element and R-3 performers on the project.
- **MCP:** `mcp.hitchintel.com` — `budget_get_activity`.

*HitchAI is an independent intelligence service, not affiliated with the U.S. Department of Defense. Budget figures are requests/estimates, not obligations.*