https://www.millabs.net/blog/niprnet-siprnet-jwics-names/

Two questions arrive from vendors with working software and government demand. The first is do we need SIPR or JWICS? The second is sharper: when you deploy software to JWICS, is that a JWICS deployment or a TS/SCI deployment?

Both are reasonable. This series answers the first one below, and takes all four posts to answer the second, because it turns out to depend on several vocabularies, each maintained by a different authority.

Neither can be answered before clearing up something that trips up almost everyone approaching this from outside: each of these networks has more than one current, correct name, depending on whether you are reading a service catalog, an acquisition document, or listening to someone who works on it. The names are not interchangeable, none of them is wrong, and one of them uses a term for the data that policy retired sixteen years ago.

This post covers the networks and the markings on the data they carry. It deliberately sticks to DISA and government-wide terminology. Individual departments and services maintain their own names for their own instantiations, and those add confusion without adding understanding.

The three services

The DISN Connection Process Guide — the document that governs how anything gets connected to the Defense Information Systems Network — lists three IP data services. These are the official names.

Official DISN service Legacy name Carries Marking on the data
Sensitive but Unclassified IP Data Service NIPRNet Unclassified, including controlled unclassified CUI
Secret IP Data Service SIPRNet Secret and below SECRET
Top Secret/SCI IP Data Service JWICS Top Secret, including SCI TS//SCI

Read the left column and the right column together and the pattern is clear: DISA names each transport service after the sensitivity of the data it carries. That is a sensible convention. It is also the source of the confusion, because it means the name of a network and the name of a classification are sometimes the same words — and people reasonably conclude that the network and the classification are the same kind of thing. They are not. One is a pipe. The other is a property of what goes through it.

The legacy names in the second column are not deprecated in practice. They are what people say, what job descriptions ask for, and what you will hear in every meeting. Expect to use both sets.

The name that outlived its own vocabulary

The first row is where this gets genuinely strange, and it is worth understanding because it is the clearest illustration of why this subject resists self-teaching.

"Sensitive But Unclassified" was the government's umbrella name for unclassified information that still needed protection — and by 2009 the umbrella covered a mess. The Presidential Task Force on Controlled Unclassified Information reported that "there are more than 100 different SBU markings and handling procedures currently in use across the federal government."

Executive Order 13556, signed on November 4, 2010, called that situation "this inefficient, confusing patchwork" and replaced it with a single category — Controlled Unclassified Information, or CUI — whose categories "shall serve as exclusive designations" across the executive branch, with the National Archives as executive agent. DoD implemented it through DoDI 5200.48, dated March 6, 2020, which canceled the prior DoD guidance authorizing "For Official Use Only" as a marking.

So the marking changed. New documents that would once have been stamped FOUO are marked CUI instead, where the information qualifies. Old documents do not convert on their own. The instruction says legacy information "does not automatically become CUI" and must be reviewed by the owner of the information first — and that "the CUI Program does not require the redacting or re-marking of documents bearing legacy markings" at all. FOUO-stamped material keeps circulating, legitimately.

The transport service is still officially called Sensitive but Unclassified IP Data Service.

Nothing is wrong here. The network service name and the information marking are maintained by different authorities for different purposes, and the network's name was never a marking in the first place. But the practical result is that the data is CUI and the pipe is still named for the umbrella category CUI replaced, and a newcomer who tries to reconcile those two facts will assume they have misunderstood something. They have not. The vocabulary simply drifted on one layer and not the other.

It is not only newcomers, either. On September 23, 2021, the DoD Inspector General issued a management advisory on "the continued use of unauthorized 'For Official Use Only' (FOUO) markings on new DoD documents" and the ineffective implementation of CUI. The detail worth knowing is in the body. Because Components would not tell the IG whether their information qualified as CUI, the Inspector General's own reports had carried the canceled marking since March 2020 — "in violation of the Executive Order, DoDI 5200.48, and other authorities." If the office responsible for oversight could not get the old word out of its own publications, a vendor reading a mix of current and decade-old documents has no chance of inferring which term is live.

The lesson generalizes. When two authoritative sources use different words for what looks like the same thing, the default assumption should be that both are correct at different layers, not that one is out of date.

What each service actually carries

Three points that matter more than the names.

The classification is a ceiling, not a description. DISA's cloud security requirements describe SIPRNet as the "DISN SECRET network service," and limit the classified cloud reached through it to "SECRET or below." So it carries Secret and everything below it, which means "the system is on SIPR" does not tell you the data is Secret — only that it is no higher than Secret. This matters when you are scoping work, because the protection requirements follow the actual classification of the information and the rules about what may sit alongside what, not the ceiling of the network it happens to traverse.

Secret and compartmented are different problems. Sensitive Compartmented Information is governed by its own control systems and access rules, and the TS/SCI service is named for it. This is why the answer to "do we need SIPR or JWICS" is not simply a matter of how sensitive the data feels. Look closely at that service's name: it joins a classification level to a control system, which are two separate things. The next post takes them apart.

Transport is not hosting. All three of these are transport services: they move packets between authorized places. None of them is a place to put your application. Your software runs somewhere — in a data center, in a cloud region, in an enclave — and that somewhere has its own authorization, its own controls, and its own name. Confusing the network with the hosting environment is the most expensive version of this mistake, because it leads vendors to plan for a connection when what they need is a home. The journey from a Docker image to an operational classified deployment is mostly about the home, not the pipe.

What the network name does not tell you

If you know which of the three services your system will reach, you know something real. Here is what you still do not know, and each of these has cost a program more than the network question ever did.

You do not know the classification of your data. Only the ceiling. See above.

You do not know where the software runs. Transport is not hosting, and the hosting decision determines most of your work.

You do not know whether the information is compartmented. The classification level is only one axis. Whether the material sits inside a control system like SCI is a second, independent axis, and it determines who may be granted access at all — including whether your own cleared staff can do the work. That is the next post in this series.

You do not know which cloud framework applies, or whether one applies at all. If your software is going into a commercial or government cloud rather than onto iron in a facility, there is an entirely separate vocabulary of impact levels governing what may be hosted where. It has its own numbering, its own recent changes, and a ceiling of its own. That is the third post.

You do not know what gets authorized, or by whom. This is the one that surprises people most. The network name does not name an approval. Connecting to a DISN service and being authorized to operate are two different decisions, made by two different authorities, on two different documents — and one is contingent on the other. That is the last post in this series.

You do not know what you inherit. Whatever environment hosts your software already implements a large number of security controls. Which ones you inherit, and which ones remain yours, is the single biggest variable in what a classified deployment costs. It is determined by the hosting environment, not by the network.

The short answer

For the vendor who asked whether they need SIPR or JWICS: the network follows from the data, and the data follows from the mission. If the customer's information is Secret and not compartmented, it is the Secret IP Data Service. If the mission involves compartmented intelligence, it is the TS/SCI service and a different community with different authorities. If it is controlled unclassified, it is the SBU service — and a much larger range of hosting options, including commercial cloud, opens up. Anything outside those three cases, such as Top Secret information that is not compartmented, needs the second axis the next post explains before the network question has an answer.

But the network is the easiest decision in the sequence and usually the one already made for you by the customer. The decisions that determine your schedule are where the software runs, what it inherits, and who signs. The rest of this series works through them, starting with the vocabulary that decides who may touch the data at all.


Robert Burckner is the founder of Millabs Corporation, a Service-Disabled Veteran-Owned Small Business. He has served as ISSM and ISSE for legacy weapon systems at the Air Force Lifecycle Management Center and as Division Chief at the Space Warfighting Analysis Center (USSF/NRO). Millabs has deployed commercial software to IL-4 and TOP SECRET environments operational on JWICS.

If you have government demand and are working out what deploying into a classified environment actually requires, an enclave fit study answers the hosting, inheritance and authorization questions before you commit to a schedule. Contact Millabs.

Share this post
Email LinkedIn
GET IN TOUCH WITH US

Find out what the gap between your product and an authorized environment actually looks like.