Cyber Resiliency & Cybersecurity Policy
The Cyber Resiliency & Cybersecurity Policy (CR&CP) program supports the efforts of the Office of the Under Secretary of War, Acquisition and Sustainment (OUSW A&S) to cyber harden priority Department of War (DoW) missions and enhance the cyber lethality of the Joint Force. The CR&CP program enables the Cyber Warfare Directorate (CWD) to conduct Capability Portfolio Management to enhance the Department’s capability to cyber harden priority DoW missions, enabling weapon systems, supporting DoW Installation Critical Infrastructure (ICI) and defend supporting Commercial Critical Infrastructure (CCI) from cyber-attack. The CR&CP program funds Cybersecurity Supply Chain Risk Management (C-SCRM) efforts that implement DoW priorities and Congressional direction aligned with enhancing C-SCRM. In addition, this program funds initiatives that enhance the security of the Department’s sensitive unclassified information residing within the Defense Industrial Base (DIB) and enhance the cybersecurity of priority DoW production lines. The CR&CP program also funds Capability Portfolio Management for Joint Cyber Capabilities used by the Cyber Mission Force. This program funds the following critical efforts: 1) Cybersecurity for Weapon Systems and Critical Infrastructure: Conduct Capability Portfolio Management and lead the Department’s Strategic Cybersecurity Program (SCP) to continue critical weapon systems and ICI cybersecurity assessments and mitigations and cyber harden priority Department of War (DoW) missions. Office of Assistant Secretary of War for Acquisition (ASW(A))/Cyber Warfare Directorate (CWD) Cyber Resiliency efforts are aligned with the following initiatives: Assess: - Conduct mission level cyber risk assessments for priority Defense Missions in support of Combatant Commands (CCMDs). Conduct enhanced mission level cyber risk assessments/wargames for the Missile Defense Mission and key supporting missions in support of Golden Dome for America. Conduct supporting tabletop exercises (TTXs). - Conduct Cyber Risk Assessments for ICI and CCI in support of CCMDs and asset owners. - Conduct Integrated Sensing Monitoring Experiments (ISMX)and Sensing and Monitoring Pilots to assess the performance of Cybersecurity Sensing and Monitoring capabilities for WS and ICI.
Assess: Conduct Cyber Risk Assessments in support of CCMDs: - Mission Resilience (MR) Games: Complete MR V with a Focus on Missile Defense in support of Golden Dome for America. Develop enhanced Cyber Attack/Cyber Defense Scenarios for Golden Dome. Prepare for MR VI with CCMDs. - Cyber Risk Assessments (CRAs): Perform multiple CRAs for…
Read the FY2027 plan →