An official website of the United States government
A .gov website belongs to an official government organization in the United States.
A lock (lock ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

In the News

News | Sept. 24, 2025

Department of War Announces New Cybersecurity Risk Management Construct

The Department of War (DoW) today announced the implementation of a groundbreaking Cybersecurity Risk Management Construct (CSRMC), a transformative framework to deliver real-time cyber defense at operational speed. This five-phase construct ensures a hardened, verifiable, continuously monitored, and actively defended environment to ensure that U.S. warfighters maintain technological superiority against rapidly evolving and emerging cyber threats.

Addressing Legacy Shortcomings

The previous Risk Management Framework was overly reliant on static checklists and manual processes that failed to account for operational needs and cyber survivability requirements. These limitations left defense systems vulnerable to sophisticated adversaries and slowed the delivery of secure capabilities to the field.

The CSRMC addresses these gaps by shifting from "snapshot in time" assessments to dynamic, automated, and continuous risk management, enabling cyber defense at the speed of relevance required for modern warfare.

The construct is composed of a five-phase lifecycle and ten foundational tenets.

The Five-Phase Lifecycle

The new construct organizes cybersecurity into five phases aligned to system development and operations:

  1. Design Phase – Security is embedded at the outset, ensuring resilience is built into system architecture.
  2. Build Phase – Secure designs are implemented as systems achieve Initial Operating Capability (IOC).
  3. Test Phase – Comprehensive validation and stress testing are performed prior to Full Operating Capability (FOC).
  4. Onboard Phase – Automated continuous monitoring is activated at deployment to sustain system visibility.
  5. Operations Phase – Real-time dashboards and alerting mechanisms provide immediate threat detection and rapid response.

Ten Foundational Tenets

The CSRMC is grounded in ten core principles:

  • Automation – driving efficiency and scale
  • Critical Controls – identifying and tracking the controls that matter most to cybersecurity
  • Continuous Monitoring and ATO – enabling real-time situational awareness to achieve constant ATO posture
  • DevSecOps – supporting secure, agile development and deployment
  • Cyber Survivability – enabling operations in contested environments
  • Training – upskilling personnel to meet evolving challenges
  • Enterprise Services & Inheritance – reducing duplication and compliance burdens
  • Operationalization – ensuring stakeholders near real-time visibility of cybersecurity risk posture
  • Reciprocity – reuse assessments across systems
  • Cybersecurity Assessments – integrating threat-informed testing to validate security

Delivering Cybersecurity at the Speed of War

By institutionalizing this construct across the Department, the DoW is ensuring cyber survivability and mission assurance in every domain: air, land, sea, space, and cyberspace.

"This construct represents a cultural shift in how the Department approaches cybersecurity," said Katie Arrington, performing the duties of the DoW CIO. "With automation, continuous monitoring, and resilience at its core, the CSRMC empowers the DoW to defend against today's adversaries while preparing for tomorrow's challenges."

For more information on the Cyber Security Risk Management Construct, click here.

For more information on the CSRMC Strategic Tenets, click here.

Social Media Feed

Twitter
@DeptofWar is implementing a new, fully automated Identity, #ICAM workflow to streamline how personnel gain access to mission-critical systems. This new process replaces the decades old paper-based DD Form 2875, which is now being retired. More info at: https://t.co/l0Cnq5ABDb
Twitter
The Cyber Workforce Summit 2.0 will launch 24MAR-26MAR26. The Summit will take place at @NDU_EDU & feature speakers including Hon. Davies, DoW CIO, workshops, & networking opportunities. Register via the following link: https://t.co/7VccjEYYOC https://t.co/TSiVrL7ozy The Cyber Workforce Summit 2.0 will launch 24MAR-26MAR26. The Summit will take place at @NDU_EDU & feature speakers including Hon. Davies, DoW CIO, workshops, & networking opportunities.
Register via the following link: https://t.co/7VccjEYYOC https://t.co/TSiVrL7ozy
Twitter
"To build an information enterprise that is resilient, modern, secure and agile – one that is worthy of the Warfighters we serve." This is my commitment. I've challenged the DoW team to ruthlessly prioritize our mission and support our Warfighters at speed. - Hon. Kirsten Davies https://t.co/fzTvBgST5Y "To build an information enterprise that is resilient, modern, secure and agile – one that is worthy of the Warfighters we serve." This is my commitment. I've challenged the DoW team to ruthlessly prioritize our mission and support our Warfighters at speed. - Hon. Kirsten Davies https://t.co/fzTvBgST5Y
Twitter
The deadline for RETURNING scholars applying for additional Cyber Service Academy funding for the Fall 2026/Spring 2027 academic term is officially one month away – Friday, February 20, 2026 (at noon). Apply at: https://t.co/jrTqPgVoU6 https://t.co/bZy1O4MfRZ The deadline for RETURNING scholars applying for additional Cyber Service Academy funding for the Fall 2026/Spring 2027 academic term is officially one month away – Friday, February 20, 2026 (at noon). Apply at: https://t.co/jrTqPgVoU6 https://t.co/bZy1O4MfRZ
Twitter
@DeptofWar welcomes Hon @_KirstenDavies_ confirmed by @SenateFloor & sworn in as @POTUS pick for CIO. With decades of leadership in digital transformation & defending freedom in the cyber domain, she'll serve under @SecWar to digitize & modernize warfighter readiness & lethality.
Twitter
@DeptofWar welcomes Hon @_KirstenDavies_ confirmed by @SenateFloor & sworn in as @POTUS pick for CIO. With decades of leadership in digital transformation & defending freedom in the cyber domain, she'll serve under @SecWar to digitize & modernize warfighter readiness & lethality.
Twitter
The DoW CSA is excited to announce that the application portal is now open to current DoW CSA Scholars returning for the upcoming Fall 2026/Spring 2027 academic year! RETURNING SCHOLAR APPLICATION LINK (Part 1/1) – https://t.co/15Cc0lRrSa
X
6,754
Follow Us