Insider Threat
Executive Order 13587 and the National Insider Threat Policy mandate all United States Government departments and agencies to implement insider threat programs that monitor user activity on all classified networks and provide an insider threat analytical and response capability. The Counter Insider Threat Capability (CITC) is the Department of the Navy's implementation of this requirement. CITC's mission is to prevent, deter, detect, and respond to the threat from witting and unwitting insiders. The Platform for Risk Evaluation and Engagement to Neutralize Threat (PREVENT) is the materiel solution required to support the CITC mission and consists of two parts: (1) User Activity Monitoring (UAM), which monitors user activity on classified Navy networks, and (2) an Integrated Tool Suite (ITS), which provides the Information Technology platform for the analytic and response capabilities. The PREVENT system provides the technology required by the Navy Insider Threat Analytic Hub to comply with the National mandates and to protect Navy data, equipment, and personnel from insider threats. RDT&E,N funding is required to develop future, long-term, capability; integrate; and perform testing and evaluation of this capability.
FY2027 planned work - Continue testing of Integrated Tool Suite (ITS) major upgrades to current ITS solution. - Continue testing and evaluation of UAM and ITS capability on JWICS and SIPRNet. - Continue assessment and accreditation efforts of Platform for Risk Evaluation and Engagement to Neutralize Threat (PREVENT) capability in on NCE cloud broker environment. - Continue testing of User Activity Monitoring (UAM) major upgrades to current UAM solution including testing across multiple networks with existing UAM capabilities and cloud environment. - Continue testing, evaluation, and integration efforts on Secret Internet Protocol Router Network (SIPRNet) afloat networks (CANES). - Continue research…
FY2026 to FY2027 change Funding: The FY27 budget control decrease of $0.439M is attributed to efficiencies realized following the identification of essential Cloud environment services for FY27.
FY2026 plans — current year - Continue testing of Integrated Tool Suite (ITS) major upgrades to current ITS solution. - Continue testing and evaluation of UAM and ITS capability on JWICS and SIPRNet. - Continue assessment and accreditation efforts of Platform for Risk Evaluation and Engagement to Neutralize Threat (PREVENT) capability in on NCE cloud broker environment. - Continue testing of User Activity Monitoring (UAM) major upgrades to current UAM solution including testing across multiple networks with existing UAM capabilities and cloud environment. - Continue testing, evaluation, and integration efforts on Secret Internet Protocol Router Network (SIPRNet) afloat networks (CANES). - Continue research…