Search IT Programs

Enterprise Security Services

Investment ID: 029-888888600


Program Title
Enterprise Security Services
This investment funds the Department of Veterans Affairs (VA) information security program providing enterprise-wide cybersecurity and privacy capabilities to protect and defend Veterans' information and VA information systems. The investment's mature programs are aligned to Federal Information Security Management Act of 2014 and enhance VA's management of information security risks through strategy, policy and governance. These investments facilitate the protection of VA and Veteran data on the VA network through the core functions of identify, protect, detect, respond and recover as outlined in the National Institute of Standards and Technology Cybersecurity Framework. These investments are also necessary to enable VA to provide immediate response and recovery when a cybersecurity incident or privacy breach may occur. VA information security investments enable mission owners to make informed risk decisions while delivering secure services to Veterans.
Type of Program
Standard IT Investments
Multi-Agency Category
Not Applicable
Associated Websites,,

Investment Detail

The Corporate IT Support Enterprise Cyber Security and Privacy program continuously ensures that Veteran Personal Health Information (PHI). Personally Identifiable Information (PII), and all other sensitive information that is processed or stored in VA IT systems remains safeguarded at all times. The return on investment is significant as the damage and harm that could result from a loss of sensitive Veteran and VA information is prevented by the effective implementation of the Enterprise Cyber Security and Privacy Program. Security of Veteran information is a top priority at the VA, and the Program benefits both internal and external organizations and individuals by ensuring that VA is fully compliant with Federal IT security and privacy laws and policies. This benefits all Veterans, and also the employees and staff that make use of the data and systems maintained and operated by the VA. VA applies a risk-based approach to security and implements a defense in depth strategy that and lowers risk of system vulnerability by defending protects and defends the Veterans Affairs enterprise systems, applications and services from both internal and external security threats, and which is accomplished by vulnerability scanning, penetration testing, firewall management, forensic analysis, and intrusion detection monitoring. The program includes information security officer (ISO) staff that are located at all VA Medical Centers, Data Centers, and other key locations that provide direct day-to-day security operations support to the medical staff located at our facilities. The program also ensures that Veteran information is disposed of properly and within the confines of appropriate legal authorities. It also ensures that information that is deemed beneficial is made available to the public with an emphasis on protecting all Veteran and other sensitive information.

IT Program Budget


Technology projects under the Enterprise Security Services program

Supporting IDVs

Example IDV awards for Enterprise Security Services

Supporting Contracts

Example prime contract awards for Enterprise Security Services