Showing posts with label Main Pages. Show all posts
Showing posts with label Main Pages. Show all posts

September 30, 2015

NSA's Legal Authorities

(Updated: May 22, 2026)

Since the start of the Snowden-revelations, we not only learned about the various collection programs and systems of the National Security Agency (NSA), but also about the various legal authorities under which the agency collects Signals Intelligence (SIGINT).

Bceause these rules are rather complex, the following overview will show which laws and regulations govern the operations of the NSA, showing what they are allowed to collect where and under which conditions. Also mentioned are various collection programs that run under these authorities.

The overview provides a general impression of the most important elements of the various laws and regulations and does not pretend to be complete in every detail. For example, provisions for emergency collection are not included. Also, some of these laws and regulations govern the work of other US intelligence agencies too, but here the focus is on the NSA.







Diagram with a decision tree showing the various legal authorities
under which NSA can collect Signals Intelligence (SIGINT)
(Click to enlarge)



 Inside the US - Targeted collection - US persons 
 

Section 105 FISA

- Effective since October 25, 1978.
- For communications of US citizens and foreigners, whether through a "facility" or individually, inside the US, for which there's a probable cause that they are agents of a foreign power or connected to an international terrorist group. Initially also for foreigners outside the US using an American webmail provider.
- Collection takes place at telephone and internet backbone switches, wireless networks, Internet Service Providers and data centers at over 70 locations inside the United States.
- Requires an individualized warrant from the FISA Court (which takes between four and six weeks), but if no US person will likely be overheard, only a certification by the Attorney General is required.
- Collection programs: BLARNEY, COWBOY (under FAIRVIEW), PERFECTSTORM (under STORMBREW)
 

Section 703 FISA Amendments Act (FAA)

- Effective since July 10, 2008; expired on December 31, 2017.
- For communications of a US person outside the US, when there is probable cause that this person is an officer, employee, or agent of a foreign power or related to an international terrorist group.
- Requires an individualized warrant from the FISA Court.
- Collection takes place inside the United States (see Section 105 FISA).
- In practice, NSA apparently uses section 704 instead of 703 for collection against US persons overseas.



 Inside the US - Targeted collection - Foreigners 
 

Transit Authority

- Effective since 1988.*
- Based upon an extra measure contained in EO 12333.
- For the content and metadata of communications with both ends foreign: originating and terminating in foreign countries, but transiting US territory.
- Collection takes place inside the US, at major fiber-optic cables and switches operated by American telecommunication providers.
- Data may apparently be shared with other US intelligence agencies.
- Collection programs: FAIRVIEW, STORMBREW, SILVERZEPHYR (under OAKSTAR), ORANGEBLOSSOM (under OAKSTAR)

 

Section 702 FISA Amendments Act (FAA)

- Effective since July 10, 2008; expired on December 31, 2017; reauthorized in January 2018 for 6 years; reauthorized by the RISAA in April 2024 for 2 years.
- For communications to or from foreigners who are reasonably believed to be outside the United States.
- Requires an annual certification by the Attorney General (AG) and the Director of National Intelligence (DNI), which has to be approved by the FISA Court. Certifications have been approved for:

A. Counter-Terrorism (CT, since 2007)
B. Foreign Government (FG, since 2008; including some cyber threats since 2012)
C. Counter-Proliferation (CP, since 2009)
D. Counternarcotics (since 2025)*
In 2012 a Cyber Threats certification was planned,* but now, cybersecurity-related targets may fall under any of these four certifications.*


- Companies get a directive ordering them to cooperate. In return they are granted legal immunity and are compensated for reasonable expenses.
- Dissemination rules differ slightly per certification. Ordinarily, US person identifiers have to be masked, but unevaluated data may be shared with FBI and CIA, and foreign data may be shared with the 5 Eyes partners.
- Unencrypted data may be retained for up to 5 years, or for a longer period in response to an authorized foreign intelligence or counterintelligence requirement, as determined by the NSA's SIGINT Director.

Section 702 FAA has two components, each with slightly different rules:
 

Downstream Collection (PRISM)
- Only internet communications "to" and "from" specific e-mail addresses or other types of identifiers. Filtering only allowed for selectors, not for keywords.
- Collection is done by the FBI's DITU, which acquires the data from at least 9 major American internet companies. This results in both stored and future communications.
- Raw (unminimized) data may be shared with FBI and CIA.
- Data are retained for a maximum of 5 years.
- NSA is permitted to use US person identifiers for querying already-collected data when there's a reasonable expectation that this will return foreign intelligence.*
- Collection program: PRISM

 
Upstream Collection
- Both internet and telephone communications. The internet communications may be "to", "from" and "about" specific e-mail addresses or other types of identifiers, including IP addresses and cyber threat signatures. The "about" collection of one end foreign e-mails and texts was halted on April 28, 2017 as this pulled in purely domestic e-mails as well.
- Collection takes place inside the US, at major telephone and internet backbone switches. This only results in future communications.
- Raw (unminimized) data may not be shared outside NSA.
- Data are retained for a maximum of 2 years.
- Collection programs: FAIRVIEW, STORMBREW



 Inside the US - Bulk collection - US persons 
 

Section 402 FISA (PR/TT)

- Effective since October 25, 1978.
- Since July 14, 2004, orders from the FISA Court allowed the NSA to collect domestic internet metadata in bulk under this authority. These metadata included the "to", "from", and "cc" lines of an e-mail, as well as the e-mail’s time and date.
- Only for Counter-Terrorism purposes.
- Collection took place inside the US, by acquiring the metadata from big American telecommunication providers.
- Query results could only be accessed by specially trained NSA analysts, and could only be shared for a counter-terrorism purpose.
- Data were being retained for a maximum of 5 years.
- Collection terminated in December 2011 for "operational and resource reasons" and all data were deleted, as the requirements could also be fulfilled under 702 FAA and SPCMA authorities.*
- Collection programs: FAIRVIEW

 

Section 215 USA PATRIOT Act (BR-FISA)

- Effective since October 26, 2001; expired as of May 31, 2015.
- Since 2006, orders from the FISA Court allowed the NSA to collect domestic telephone metadata in bulk under this authority. These metadata included the originating and receiving phone number, the date, time and duration of the call, and, since 2008, the IMEI and IMSI number.
- Only for Counter-Terrorism purposes: there must be a Reasonable and Articulable Suspicion (RAS) that the query term belongs to a foreign terrorist organization. The Emphatic Access Restriction (EAR) tool ensured that analysts only did queries on RAS-approved selectors.*
- Collection took place inside the US, by acquiring the metadata from big American telecommunication providers.
- Query results could only be accessed by specially trained NSA analysts, and could only be shared when a manager certifies the data are for a counter-terrorism purpose.
- Data were retained for a maximum of 5 years. Remaining data will be deleted after receiving direction from the appropriate court.
- Collection programs: FAIRVIEW, STORMBREW


During a 180-day transition period, the NSA continued the collection of bulk telephony metadata under section 215 USA PATRIOT Act, which was until November 29, 2015. In this period, telephony metadata could only be queried after a judicial finding that there is a Reasonable, Articulable Suspicion (RAS) that the selector is associated with an international terrorist group. The results had to be limited to metadata within 2 (instead of 3) hops of the seed term.
 

USA FREEDOM Act (USAFA or UFA)

- Effective since June 2, 2015, expired on March 15, 2020.
- Allows the NSA to request metadata from telephone companies based upon specific selection terms for which there's a Reasonable, Articulable Suspicion (RAS) that they are associated with a foreign power or an international terrorist group. These metadata may consist of "session-identifying information", like originating and receiving numbers, IMSI, IMEI and telephone calling card numbers, and the date, time and duration of the call. Collection of, and contact chaining on location data is prohibited.
- Requires a warrant from the FISA Court approving specific telephone numbers or other identifying selectors.
- NSA provides these selectors to the telecommunication providers, who have to produce the results of their queries (one or two hops from the initial selector) in a useful format, on a daily basis, and for a period of up to 180 days.
- Companies providing these data are granted legal immunity and will be compensated for reasonable expenses.
- All records that are not foreign intelligence information have to be destroyed promptly.
- Query results may be fully shared with CIA and FBI.
- Also, foreign terrorists may be tracked for up to 72 hours when they enter the US, with authorization by the Attorney General.
- In the Summer of 2019, the NSA suspended the program and subsequently deleted all the data collected under this authority.



 Outside the US - Targeted collection - US persons 
 

Section 704 & 705 FISA Amendments Act (FAA)

- Effective since July 10, 2008; expired on December 31, 2017.
- Collection takes place outside the United States.
- Data may be retained for up to 5 years, or for a longer period in response to an authorized foreign intelligence or counterintelligence requirement, as determined by the NSA's SIGINT Director. Inadvertent collection of US data has to be destroyed upon recognition, but the Attorny General can authorize exceptions.

The differences for these sections are:


Section 704 FAA
- For collection against a US person outside the US, when there is probable cause that this person is an officer, employee, or agent of a foreign power or related to an international terrorist group.
- Requires an individualized warrant from the FISA Court, for a period of up to 90 days.
 

Section 705(a) FAA
- For communications of a US person reasonably believed to be outside the United States.
- Requires an individualized warrant from the FISA Court.
- Collection may take place both inside and outside the United States.


Section 705(b) FAA
- For communications of a US person reasonably believed to be outside the US, when there is already an existing FISA Court order for collection against this person inside the US under section 105 FISA.
- Requires authorization by the Attorney General.



 Outside the US - Targeted & Bulk collection - Foreigners
 

Executive Order 12333

- Effective since December 4, 1981.
- For communications between foreigners outside the US.
- Requires no external approvals, except for fitting NSA's mission as set by the US government and prioritized by the National SIGINT Committee.
- Collection takes place outside the US and for all foreign intelligence purposes. However, Presidential Policy Directive 28 (PPD-28) from January 17, 2014, limits bulk collection to the following 6 purposes:
- Espionage and other threats by foreign powers
- Threats from terrorism
- Threats from weapons of mass destruction
- Cybersecurity threats
- Threats to US or allied armed forces
- Threats from transnational crime
- Data may be shared with other US intelligence agencies, as well as with foreign partner agencies.
- Dissemination of US person identifiers is only allowed when necessary and personal information should not be inappropriately included in intelligence reports.
- Unencrypted data from targeted collection are retained for up to 5 years, unless it is determined that continued retention is required; encrypted data are retained for an unlimited period of time.
- Any incidentally collected communications have to be deleted after five years, unless they meet a number of exceptions.*
- Collection programs: OAKSTAR, WINDSTOP (incl. INCENSER, MUSCULAR, etc), RAMPART-A (incl. SPINNERET, MOONLIGHTPATH, AZUREPHOENIX, etc), DANCINGOASIS, MYSTIC, and many more.

Under EO 12333, there are several additional authorizations:
 

Classified Annex Authority (CAA)
- Effective since 1988.
- For communications of US persons outside the US, for whom there's probable cause that they are agents of a foreign power or engaged in international terrorism.
- Requires prior approval by the Attorney General, limited to a period of time of up to 90 days.
- Also for communications of a US person who is held captive by a foreign power or a terrorist group, which requires approval of the Director of NSA.
 

Special Procedures governing Communications Metadata Analysis (SPCMA)
- Effective since January 2011
- Allows contact chaining and other analysis on metadata already-collected under EO 12333, regardless of nationality and location, including US person identifiers.
- For the purpose of following or discovering valid foreign intelligence targets (i.e. not restricted to counter-terrorism).
- Only covers analytic procedures and does not affect existing collection, retention or dissemination (including minimization) procedures for US person information.
- SPCMA-enabled tools: ICREACH, Synapse Workbench, CHALKFUN
 

Raw SIGINT Availability Procedures
- Effective since January 2017
- Allows other US intelligence agencies to request access to content and metadata of US persons from already-collected raw SIGINT data sets from the NSA.
- Only for foreign intelligence or counterintelligence purposes and the requesting agencies may not use selectors or key word queries that will result in domestic communications (contact-chaining is not limited).
- In general, raw SIGINT obtained in this way may be retained for up to 5 years, but foreign communications may be retained permanently if US person information is minimized. Domestic communications have to be destroyed promptly upon recognition, except when they provide significant intelligence value. Further dissemination is only allowed after approval by NSA.
- Sharing tools: ICREACH



                         Information Assurance                        


Besides collecting Signals Intelligence (SIGINT), the NSA is also responsible for Information Assurance (IA). The latter mission is conducted under the following legal authorities:

National Security Directive 42
("National Policy for the Security of National Security Telecommunications and Information Systems", 1990)

Executive Order 13587
("Structural Reforms to Improve the Security of Classified Networks and the Responsible Sharing and Safeguarding of Classified Information", 2011)




                  Computer Network Operations                   


The latest field in which the NSA is operating, Computer Network Operations (CNO), better known as hacking, is not governed by new legal authorities. Instead, the existing authorities for SIGINT and IA are used, ideally in a more effective way to "take advantage of the same expertise (analytical and technical) that is used to defend and exploit".*


- . - . - . - . - . - . - . - . -


Links and sources
- NSA OGC presentation: CNO Legal Authorities
- Paper by Mark M. Jaycox: No Oversight, No Limits, No Worries: A Primer on Presidential Spying and Executive Order 12,333 (2019)
- Emptywheel.net: 12333 info sharing working thread
- The New York Times: N.S.A. Gets More Latitude to Share Intercepted Communications
- Emptywheel.net: The Yahoo Scan: On Facilities and FISA
- Emptywheel.net: While It Is Reauthorizing FISA Amendments Act, Congress Should Reform Section 704
- IC on the Record: FACT SHEET: Implementation of the USA FREEDOM Act of 2015
- Emptywheel.net: Internet Dragnet Timeline - Phone Dragnet Timeline - 10 Goodies USA Freedom Act Gives the Intelligence Community
- Webpolicy.org: Executive Order 12333 on American Soil, and Other Tales from the FISA Frontier
- IC on the Record: Transition from the USA PATRIOT Act to the USA FREEDOM Act
- DNI.gov: Documents Regarding the Now-Discontinued NSA Bulk Electronic Communications Metadata
- Americanbar.org: Section 214 and Section 215 FISA
- National Research Council: Bulk Collection of Signals Intelligence: Technical Options (pdf) (2015)
- NSA Civil Liberties and Privacy Report about Targeted SIGINT Activities under EO 12333 (pdf) (2014)
- Privacy and Civil Liberties Oversight Board report about the Surveillance Program Operated Persuant to Section 702 FISA (pdf) (2014)
- Legal fact sheet: Executive Order 12333 (pdf) (2013)
- The Department of Defense Directive about NSA/CSS (pdf) (2010)
- NSA OGC: Course on legal compliance and minimization procedures (pdf)
- Memo about Reauthorization of the FISA Amendments Act (pdf)
- NSA OGC: FISA Amendments Act of 2008 - Section 702 - Summary Document (pdf)

March 11, 2015

US military and intelligence computer networks

(Updated: September 12, 2025)

From the Snowden revelations we learned not only about NSA data collection projects, but also about many software tools that are used to analyze and search those data. These programs run on secure computer networks, isolated from the public internet. Here we will provide an overview of these networks that are used by the US military and US intelligence agencies.

Besides computer networks, they also use a number of dedicated telephone networks, but gradually these are transferred from traditional circuit-switched networks to Voice over IP (VoIP). This makes it possible to have only one IP packet-switched network for both computer and phone services. It seems that for example NSA's NSTS phone system is now fully IP-based.




An old NSTS telephone and a KVM-switch which enables switching between physically
separated networks, in this case two Unclassified (green labels), one Secret
(red label) and one Top Secret/SCI (orange and yellow label) network
(National Security Operations Center, 2006 - Click to enlarge)


US national networks

The main US military and intelligence computer networks are (of course) only accessible for authorized personnel from the United States. Special security measures are in place to prevent interception by foreign intelligence agencies. Most of the tools and programs used by NSA run on JWICS and NSANet, but here we only mention them when this is confirmed by documents.



DNI-U (Director National Intelligence-Unclassified)

- Until 2006: Open Source Information System (OSIS)
- Classification level: Sensitive But Unclassified (SBU, color code: green)
- Access: US intelligence users
- Controlled by: DNI-CIO Intelligence Community Enterprise Services office (ICES)
- Purpose: Providing open source information; consists of a group of secure intranets used by the US Intelligence Community (IC)
- Computer applications: Intelink-U, Intellipedia-U, EViTAP, etc.



Page of the Unclassified version of Intellipedia
This one from the CIA's AIN network
(Click to enlarge)


NIPRNet (Non-secure Internet Protocol Router Network)

- Classification level: Sensitive But Unclassified (SBU, color code: green)
- Secured by: Network traffic monitored by the TUTELAGE program and QUANTUM-DNS at the 18 gateways to the public internet *
- Address format: http://subdomains.domain.mil
- E-mail format: john.doe@mail.mil
- Access: US military users, via Common Access Card smart card *
- Number of users: ca. 4,000,000
- Controlled by: STRATCOM
- Purpose: Combat support applications for the US Department of Defense (DoD), Joint Chiefs of Staff (JCS), Military Departments (MILDEPS), Combatant Commands (COCOM), and senior leadership; composed of the unclassified networks of the DoD; provides protected access to the public internet.
- Computer applications: E-mail, file transfer and web services like the Joint Deployable Intelligence Support System (JDISS)
- Video Teleconferencing (VTC)



Cyber security officers in an operations center room at Barksdale Air Force Base
There are screens connected to NIPRNet (green background/border)
and SIPRNet (red background/border)
(Photo: U.S. Air Force/Tech. Sgt. Cecilio Ricardo - Click to enlarge)
More about this photo on SecurityCritics.org



SIPRNet (Secret Internet Protocol Router Network)

- Classification level: SECRET (color code: red)
- Secured by: TACLANE (KG-175A/D) network encryptors
- Address format: http://subdomains.domain.smil.mil
- E-mail format: john.doe@mail.smil.mil
- Access: users from multiple US intelligence agencies and government departments (and some foreign partners)*, via SIPRNet Token smart card
- Number of users: ca. 500,000 *
- Controlled by: STRATCOM (or JCS, NSA, DIA and DISA *)
- Purpose: Communications backbone for passing tactical and operational information, supporting the Global Command and Control System (GCCS), the Defense Message System (DMS), collaborative planning and numerous other classified warfighter applications, and as such DoD's largest interoperable command and control data network.
- Computer applications: Intelink-S, Intellipedia-S, TREASUREMAP, Joint Deployable Intelligence Support System (JDISS), Defense Knowledge Online, Army Knowledge Online, InfoWorkSpace (IWS), etc.
- Phone service: VoSIP (Voice over Secure IP) as an adjunct to the DRSN for users that do not require the full command and control and conferencing capabilities.
- Secure Video Teleconferencing (VTC)



Computers in the White House Situation Room, with a yellow screensaver,
indicating they are connected to a TOP SECRET/SCI computer network
(Screenshot from a White House video)


JWICS (Joint Worldwide Intelligence Communications System)

- Classification level: TOP SECRET/SCI (color code: yellow)
- Secured by: TACLANE (KG-175A/D) network encryptors *
- Address format: http://subdomains.domain.ic.gov
- E-mail format: john.doe@agency.ic.gov
- Access: users from multiple US intelligence agencies and government departments, for intelligence users via an IC PKI certificatie and for military users via a DoD PKI certificate.*
- Number of users: ca. 200,000 *
- Controlled by: DIA, with management delegated to AFISR
- Purpose: Collaboration and sharing of intelligence data within the US Intelligence Community (IC)
- Computer applications: ICE-mail, Intelink-TS, Intellipedia-TS, GHOSTMACHINE, ROYALNET, TREASUREMAP, ICREACH, Joint Deployable Intelligence Support System (JDISS), etc.
- Phone Service: DoD Intelligence Information System (DoDIIS) VoIP telephone system
- Secure Video Teleconferencing (VTC)



Web-browser with a JWICS address for the ROYALNET tool


These various military and intelligence networks run on a world-wide physical infrastructure that is called the Defense Information Systems Network (DISN), which is maintained by the Defense Information Systems Agency (DISA) and consists of landline, mobile, radio and satellite communication links.

Most of these communication links are not connected to the public internet, but because radio and satellite transmissions can easily be intercepted by foreign countries, the security of these networks is assured by encryption. This encryption can also be used to run higher classified traffic over communication links with a lower classification level through Virtual Private Network (VPN) tunnels.

Classified communications have to be protected by Suite A Cryptography, which contains very strong and classified encryption algorithms. On most networks this is implemented by using Type 1 certified TACLANE (KG-175A/D) in-line network encryptors made by General Dynamics:



(Diagram: General Dynamics)


As long there's the appropriate strong link encryption, only the end points with the computer terminals (where data are processed before they are encrypted) need strict physical and digital security requirements in order to prevent any kind of eavesdropping or interception by foreign adversaries.

Most American military bases are connected to the SIPRNET backbone, but for tactical users in the field, the SIPRNet and JWICS networks can extend to mobile sites through Satellite Communications (SATCOM) links, like for example TROJAN SPIRIT and TROJAN SPIRIT LITE, which consist of a satellite terminal that can be on a pallet, in a shelter, on a trailer or even connected to a transit case.


Other US goverment departments and intelligence agencies also have their own computer networks at different classification levels:


White House
- TNet (the main platform for White House aides to do their jobs; Top Secret; connected to JWICS)
- NICE (NSC Intelligence Collaboration Environment, a subdomain of TNet, managed by the Directorate for Intelligence Programs of the National Security Council; Top Secret/SCI)


FBI
- LEO (Law Enforcement Online; Unclassified, for law enforcement communications)
- FBINet (Federal Bureau of Investigation Network; Secret)
- SCION (Sensitive Compartmented Information Operational Network; FBI designation for Intelink-TS, Top Secret/SCI)


DHS
- HSIN (Homeland Security Information Network; Unclassified)
- HSDN (Homeland Secure Data Network; Secret)


State Department
- OpenNet (Unclassified)
- ClassNet (Secret; address format: http://subdomain.state.sgov.gov)
- INRISS (INR Intelligence Support System; Top Secret/SCI)


Department of Energy
- DOENet (DOE Corporate Network; Unclassified)
- ECN/U (Emergency Communications Network/Unclassified)
- ECN/C (Emergency Communications Network/Classified)


CIA
- AIN (Agency InterNet; Unclassified)
- CWE (Common Work Environment; Top Secret/SCI)
- ADN (Agency Data Network?; Top Secret/SCI)
- RDINet (Rendition, Detention, and Interrogation Network; for sharing classified information with SSCI staffers, est. 2009) *


NRO
- GWAN (Government Wide Area Network, also known as NRO Management Information System (NMIS); Top Secret)
- CWAN (Contractor Wide Area Network; Top Secret)


NGA
- NGANet (National Geospational intelligence Agency Network; Top Secret/SCI)


Finally, there's the Capitol Network (CapNet, formerly known as Intelink-P, with P for PolicyNet), which provides Congressional intelligence consumers with connectivity to Intelink-TS and CIASource, the latter being the CIA's primary dissemination vehicle for both finished and unfinished intelligence reports.


Overview of major Homeland Security computer networks
From a briefing for Congress, July 2004


US multinational networks

Besides the aforementioned networks that are only accessible for authorized military and intelligence personnel from the United States, there are also computer networks set up by the US for multinational coalitions, and which therefore can also be used by officials from partner countries.

The group of countries that have access to such coalition networks is often denoted by a number of "Eyes" corresponding with the number of countries that participate.



NSANet (National Security Agency Network)

- Classification level: TOP SECRET/SCI (color code: yellow)
- Secured by: TACLANE network encryptors *
- Address format: http://subdomain.domain.nsa (since 2007 replaced by nsa.ic.gov)*
- E-mail format: john.doe@nsa (see above)
- Access: US, UK, CAN, AUS, NZL signals intelligence users, requires polygraph examination *
- Number of users: ca. 30,000 *
- Controlled by: NSA, with management delegated to CSS Texas
- Purpose: Sharing intelligence among the Five Eyes partners
- Computer applications: InfoWorkSpace (IWS), WikiInfo, Tapioca, JournalNSA, SpySpace, Giggleloop, RoundTable, Pidgin, SIDToday, TREASUREMAP, MAILORDER, MARINA, TURBINE, PRESSUREWAVE, INTERQUAKE, CATAPULT, Cellular Information Service (WCIS), GATC Opportunity Volume Analytic, etc.
- Phone service: NSTS (National Secure Telephone System); newer NSTS phones are connected by fiber optic modems to a fiber backplane that interfaces with the NSANet service delivery point router.* In 2006, 45 NSTS phones were installed at the Department of Justice.



Web-browser with NSANet address for the INTERQUAKE tool, used by NSA's
Special Collection Service (SCS, organizational code: F6) units
(Click for the full presentation)


Besides NSANet as its general purpose intranet, NSA also operates several other computer networks, for example for hacking operations conducted by the TAO-division. We can see some of these networks in the following diagram, which shows how data go (counter-clockwise) from a bot in a victim's computer on the internet, through a network codenamed WAITAUTO to TAONet and from there through a TAONet/NSANet DeMilitarized Zone (DMZ) to data repositories and analysing tools on NSANet:



Diagram showing the data flow for TAO botnet hacking operations
(Source: NSA presentation - Click to enlarge)



PEGASUS

- Until 2010: GRIFFIN (Globally Reaching Interconnected Fully Functional Information Network)
- Classification level: SECRET//REL FVEY
- Access: US, UK, CAN, AUS, NZL military users
- Controlled by: DIA(?)
- Purpose: Information sharing and supporting command and control systems
- Applications: Secure e-mail, chat and VoSIP communications


STONEGHOST (also: Quad-Link or Q-Lat)

- Classification level: TOP SECRET//SCI
- Access: US, UK, CAN, AUS, NZL(?) military intelligence users, planned to be expandable to other coalition countries by 2024.
- Controlled by: DIA
- Purpose: Sharing of military intelligence information
- Applications: Intelink-C, etc.


SIGDASYS (Signals Intelligence Data System)

- Classification level:
- Access: SIGINT Seniors Europe (SSEUR/14-Eyes) members and their SISECT counterterrorism Analytic Working Group (AWG)
- Controlled by: SIGDASYS Committee
- Purpose: Shared communications system for
- Applications: Exchange of SIGINT information, including call chaining diagrams* and language files*


LOCE (Linked Operational-Intelligence Centers Europe)

- Classification level: SECRET//REL NATO
- Access: US and NATO forces and other national allied military organizations, with ca. 400 remote sites in the year 2000.
- Controlled by: European Command (EUCOM)
- Purpose: Sharing near-real-time, all-source, correlated situation and order of battle information in support of theater operations.
- Applications: Database and repository services, automatic sensor report correlation, electronic mail, imagery dissemination, graphical situation displays, and secure voice communications, but with limited bandwidth capability in the late 1990s.
- Initially named as Limited Operational Capability Europe.*


COSMOS (Coalition Secure Management and Operations System)

- Classification level:
- Access: US, Australia, Canada, Great Britain and Singapore members
- Controlled by: European Command (EUCOM) and Pacific Command (PACOM).
- Purpose: Set up around 2008 during Operation Iraqi Freedom (OIF) for rapid, secure release and protection of critical command and control (C2) information to and among coalition partners on a single and secure integrated coalition network to reduce confusion, uncertainty and delay in combat and crisis operations.*
- Applications:


CENTER ICE (since 2005)

- Classification level: TOP SECRET/SI
- Access: Afghanistan SIGINT Coalition (AFSC) members
- Controlled by:
- Purpose: Exchange of tactical intelligence, as well as tipping and threat information related to the war in Afghanistan *
- Applications:


CRUSHED ICE (since 2007)

- Classification level: SECRET
- Access: SIGINT Seniors Pacific (SSPAC) members
- Controlled by:
- Purpose: Exchange of counter-terrorism related information primarily derived from SIGINT
- Applications: Voice, binary-file/email exchanges, analysis and reporting, graphics and mapping, communities of interest, collection management, and other applications as needed.*


CFBLNet (Combined Federated Battle Laboratories Network)

- Classification level: Unclassified and SECRET
- Access: US, UK, CAN, AUS, NZL, and at least nine European countries Research & Development institutions
- Controlled by: MultiNational Information Sharing (MNIS) Program Management Office
- Purpose: Supporting research, development and testing on command, control, communication, computer, intelligence, surveillance and reconnaissance (C4ISR) systems.
- Applications: Communications, analytic tools, and other applications



The CFBLNet countries in 2009, with three of the Five Eyes countries (yellow line),
six European NATO countries and the NATO organization (black line),
six NATO guest nations (dotted line) and two non-NATO countries.
(source: NATO Education and Training Network (pdf), 2012)


CENTRIXS

For communications among the members of multinational coalitions, the United States provides computer networks called Combined Enterprise Regional Information eXchange System (CENTRIXS). These are secure wide area network (WAN) architectures which are established according to the specific demands of a particular coalition exercise or operation.

CENTRIXS enables the secure sharing of intelligence and operational information at the level of "SECRET REL TO [country/coalition designator]" and also provides selected centralized services, like Active Directory/DNS Roots, VoIP telephony, Windows Server Update Services (WSUS) and Anti-Virus Definitions.

There are more than 40 CENTRIXS networks and communities of interest (COIs) in which the 28 NATO members and some 80 other countries participate. The best-known CENTRIXS networks are:


CENTRIXS Four Eyes (CFE or X-Net)

- Classification level: TOP SECRET//ACGU
- Secured by: TACLANE network encryptors *
- Address format: http://subdomains.domain.xnet.mnf
- Access: US, UK, CAN, AUS military users
- Controlled by: DIA
- Purpose: Operational coordination through sharing and exchange of intelligence products
- Applications: Various services


CENTRIXS-ISAF (CX-I)

- Classification level: TOP SECRET//ISAF
- Secured by: TACLANE network encryptors *
- Access: ca. 50 coalition partners
- Controlled by: ?
- Purpose: Sharing critical battlefield information; US component of the Afghan Mission Network (AMN).
- Computer applications: Web services, instant messaging, Common Operational Picture (COP), etc.
- Voice over IP


CENTRIXS-M (Maritime)

- Classification level: SECRET ?
- Purpose: Supporting multinational information exchange among the ships of coalition partners of the US Navy to provide access to critical, time-sensitive planning and support data necessary to carry out the mission
- Computer applications: E-mail, Chat messaging, Webpages, etc.



Report from the Afghanistan Regional Command Southwest (RC(SW))
with a SIPRNet and a CENTRIXS e-mail address and webpage
(Full document in pdf format - Click to enlarge)


Some other CENTRIXS networks are:


CENTRIXS-GCTF
- Classification level: SECRET/REL TO [...]
- Secured by: TACLANE network encryptors *
- Address format: http://subdomains.domain.gctf.cmil.mil
- For the ca. 80 Troop Contributing Nations of the Global Counter-Terrorism Force (GCTF)

CENTRIXS-CMFC
- Classification level: SECRET/REL TO [...]
- For the Combined Maritime Forces, Central Command (CMFC)

CENTRIXS-CMFP
- Classification level: SECRET/REL TO [...]
- For the Combined Maritime Forces, Pacific (CMFP)

CENTRIXS-J
- Classification level: SECRET/REL TO [...]
- For the United States and Japan

CENTRIXS-K
- Classification level: SECRET/REL TO [...]
- For the United States and South-Korea


These CENTRIXS networks are part of a Mission Partner Environment (MPE), which is provided by the US Department of Defense to enable Mission Partners to share their command & control as well as operational information with all participants within a specific partnership or coalition.


INDOPACOM Mission Network (IMN)
- Classification level:
- Number of users: ca. 29,000 *
- Purpose: Initiated in 2023 for hosting command & control and mission applications to support joint, multi-domain operations with missions partners and allies. The first network with a native zero trust architecture (NZTA) and data centric security.*
- Controlled by: US Indo-Pacific Command (INDOPACOM)
- Applications: Email, Active Directory, web browsing, voice-over IP, video teleconferencing, real-time command and control, Palantir Mission Data Platform, Maven Smart System (MSS).*


The planned Mission Partner Environment (MPE) architecture for 2021
(source - click to enlarge)



Links and Sources
- Sofrep.com: Computers with Access to Classified Material Stolen from Capitol (2021)
- Department of Defense: Mission Partner Environment - LEXICON (2016)
- US National Intelligence: A Consumer's Guide (2009)
- Paper about How to Use FASTLANEs to Protect IP Networks (pdf) (2006)
- A NATO perspective on CENTRIXS (2005)

January 10, 2014

NSA's organizational designations

(Updated: September 15, 2026)

After providing lists of NSA-related codenames, abbreviations and SIGADs, we now publish a list of the designations of the numerous divisions and units of the NSA organization itself.

Unlike other intelligence agencies such as CIA or DIA, NSA never disclosed its internal organizational structure. The following overview has been reconstructed based upon information which over the years became available from various sources, including many documents from the Snowden-leaks.

This list only gives the alphanumeric designations, the official name and, if available, the logo of NSA branches. For a description of what the most important divisions do, click the links in the list or visit the websites mentioned under Links and Sources.

In 2007, the NSA had a workforce of 36,371:
- 18,849 of which were NSA civilians
- 17,522 of which were Service military/civilians*

In 2013, the following numbers of people worked for NSA/CSS:
- NSA: ca. 21,500 civilian personnel and ca. 13,500 military personnel
- CSS (tactical SIGINT collection units): ca. 12,000 military personnel

Update:
Internal reorganizations of the NSA were performed in 2016 and 2026. Below is the organizational structure which emerged from the reorganization of the year 2000 and shows the situation which is found in the Snowden documents.


► Go to the directorate designated by: D E F I K L M Q R S T V X
► Go to the directorate designated by:

D E F I K L M Q R S T V X



The NSA headquarters buildings at Fort Meade, Maryland
(Photo: AFP/Paul J. Richards)

NATIONAL SECURITY AGENCY (NSA)


D: Office of the Director
D0: Director's Staff
D01: Director’s Operation Group (DOG)
D05: Director’s Secretariat
D07: Office of Protocol
D08: Homeland Security Support Office (HSSO)
D1: Office of the Inspector General (OIG)
D11: Assistant Inspector General (AIG) *
...
D14: Office of Investigations

D2: Office of the General Counsel (OGC)
D21: Intelligence Law
D22: Legislation
D23: Administrative Law and Ethics
D24: ?
...
D28: Litigation and Management
D4: Office of the Director of Compliance (ODOC)

D5: Corporate Assessments Office
D5T: Technology Test and Evaluation
D6: Office of Equal Employment Oppertunity
D7: Central Security Service (CSS)
D709: CSS Staff and Resources
D7D: Cryptologic Doctrine Office
D7P: Office of Military Personnel
D7R: Director's Reserve Forces Advisor
D8: Community ELINT Management Office (CEMO)

D9 : ?

DA: Directorate of Acquisition
Senior Acquisition Executive (SAE)
DB: Corporate Strategy

DC: Director’s Chief of Staff
DC0: Support
DC3: Policy
DC31: Corporate Policy
DC32: Information Policy
DC321: Freedom of Information Act and Privacy Act (FOIA/PA)
DC322: Information Security and Records Management
DC3221: Information Security Policy
DC3223: Records Management Policy
DC323: Automated Declassification Services
DC33: Technology Security, Export, and Encryption Policy
...
DC36 Vital Records Program
DC4: Corporate Strategic Planning and Performance
DC6: External Relations & Communications
DC6C2: NSA Internal Communications *
DC8: Corporate Management Services
DE: Unified Cryptologic Architecture Office (OCAO)

DF: Chief Financial Manager (CFM)

DJ: (Community Integration) Policy and Records Office (CIPR)*
Associate Director for (Community Integration) Policy and Records (ADPR)
DJ1/DJP1: ?
DJ2/DJP2: Information Security Policy
DJ4: Freedom of Information and Privacy Office
...
DJ6/DJP6: Records Management Policy Office
DK: Chief Information Officer (CIO)

DL: Legislative Affairs Office (LAO)

DN: NSA Public Affairs Office (PAO)
DN1: ?
DN2: Multimedia Solutions
DP: Foreign Affairs Directorate (FAD)
DP0: ?
DP09: FAD Staff
DP1: Special Advisor for Foreign Partner Strategies
DP11: Second Party Affairs office
DP12: India office
DP13: Central/Eastern Europe office
DP14: Multinational, Military, NATO and Coalition Affairs office
DP15: Office of Russian Affairs *
DP16: Multinational/Second Party Office
DP2: ?
DP21: Information Assurance?
DP3: Technical Services Group *
DT: Office of the Chief Technical Officer (CTO)



E: Associate Directorate for Education and Training (ADET)
E1: Educational Services and Staff
E2: Educational Technology Integration
E3: NCS Center for Language *
E4: Intelligence Analysis and Information Assurance
E5: Signals Analysis, Cryptanalysis, and Math
E6: ?
E63: ?
E9: ?
E92: National Cryptologic School *
EL: Center for Leadership and Professional Development
EL3: Intelligence Analysis Skill Community *



F: Field sites
F1: Cryptologic Services Groups (CSGs)
F1A2: Office of the NSA Representative of US Diplomatic Missions
...
F1C: ?
F1CA: Cryptologic Services Group USSTRATCOM
F1CD: Life Cycle Logistics
F1CD1: Technical Services Group
F1I: ?
F1I2: Joint Interagency Task Force South
F1T: Liaison Office for USSOCOM *
F1T1: Cryptologic Services Group USSOCOM
F1Z: Cryptologic Services Group CENTCOM
F1Z2: Deputy Chief, CSG CENTCOM


F2: NSA/CSS Europe and Africa (NCEUR)
F20: ?
F202: NSA unit in Stuttgart Vaihingen, Germany
F204: Support to Military Operations for AFRICOM
F22: European Cryptologic Center (ECC) near Darmstadt, Germany
F23: NCER Mons, Belgium

F25: European Technical Center (ETC) in Wiesbaden, Germany

F28: Special US Liaison Activity Germany (SUSLAG) in Bad Aibling, Germany
F3: ?
F313: Combined Group Germany (CGG) in Augsburg, Germany
F32: ?
F321: Liaison Officer at Digby SIGINT Operations Centre
F33: SUSLO Canberra

F4: ?
F406: NCPAC (NSA/CSS Pacific) SIGINT Operations Division *

F41: ?
F411: Military Operations Branch

F412: ?
F41221: NSA/CSS Representative Japan (NCRJ)

F5: Liaison Support Groups
F51: Liaison Support Group at CIA

F6: Special Collection Service (SCS)
F61: Field Operations Office/SCS
...
F66: ?
F666E: (SCS unit in the US embassy in Berlin?)

F7: ?
F71: Operations Center Georgia
...
F74: Meade Operations Center (MOC)
F741: Deployments & Training Division
F74?: Special Operations Readiness Cell (SORC)
F77: Menwith Hill Station (MHS)
F77F: Menwith Hill unit
F78: Australian Mission Ground Station (AMGS, Pine Gap)
F79: Misawa Security Operations Center (MSOC)
F79F: Misawa unit
F7A: Alaska Mission Operations Center (AMOC)

F7U: Utah Regional Operations Center (UROC)
F8: ?
F81: Bad Aibling Station, Germany (-2004)

F83: RAF Menwith Hill (1966-present)
F9: ?
F91: ?

F92: Yakima Research Station (YRS)
F921: YRS Operations Division *
FC: NSA/CSS Colorado (NSAC)
FCS: Signals Intelligence Department, Colorado

FG: NSA/CSS Georgia (NSAG)
FGD: Director, Georgia
FGS: Signals Intelligence Department, Georgia
FGS2F: SW Asia Narcotics
FGS3: Transnational issues group
FG32: ?
FG3223: Media Exploitation & Analysis

FGS2E3: Middle East/North Africa shop

FGT3322: ISR Support Team

FGT342: ISR Support Team
FGV: Threat Operations Center, Georgia
FH: NSA/CSS Hawaii (NSAH)
FHQ: Security Department, Hawaii

FHS: Signals Intelligence Department, Hawaii
FHS2I: Counter-Terrorism (CT) Product Line
FHS2I2: Sunni Extremism
FHS32: Network Development Department

FHT: Technology Department, Hawaii
FHT322: Office of Information Sharing
FHT332: IT Customer Solutions

FHV: Threat Operations Center, Hawaii

FHX: ?
FHX4: ?
FT: NSA/CSS Texas (NSAT)
FTS: Signals Intelligence Department, Texas
FTS2: Analysis and Production
FTS2F1: "Southern Arc"
FTS2F2: Transnational Crime and Narcotics (TCN)
FTS3: Data Acquisition
FTS32: Tailored Access Operations
FTS327: Requirements & targeting
FTV: Threat Operations Center, Texas



I: INFORMATION ASSURANCE DIRECTORATE (IAD)
(ca. 3000 employees)
I0: Chief of Staff
I01: Office of Policy

I01C: Committee on National Security Systems (CNSS)

I2: Trusted Engineering Solutions
I209: Support Staff
I21: Architecture
I22: Engineering
I23: ?
I231: HAIPE Program Management Office (PMO)
I2N: National Nuclear Command Capabilities (N2C2) Mission
I3: Operations
I31: Current Operations
I33: Remote & Deployed Operations
I3?: Mission Integration Office
I3?: Technical Security Evaluations
I3?: Red Cell
I3?: Blue Cell
I3?: Advanced Adversary Network Penetration Cell
I4: Fusion, Analysis and Mitigation
I4 ?
I412: ?

I422: Joint COMSEC Monitoring Activity (JCMA)

I5: ?
I54: ?
I542: ?
I543: ?
I7: ?
I73: ?
I735: ?
I8: ?
I82: ?
I823: ?
I8231: Microelectronics Anti-Tamper Solutions
I85: ?
I853: Cryptographic Engines, Modules, and Tokens
IE: Engagement
IS: Strategy
IC: Cyber Integration
IV: Oversight and Compliance




K: National Security Operations Center (NSOC)
K?: SIGINT Mission Management (SMM)
K??: [...] SIGINT Mission Management (APSMM)
K??: [...] SIGINT Mission Management (CRSMM)
K?: Counter-Terrorism Mission Management Center (CTMMC)
K9: Capabilities and Sustaining Systems (CASS)
K92: Current Capabilities for Mission Management (C2M2)




L: Associate Directorate for Installations and Logistics (ADIL)
L0: I&L Staff
LF: Facilities Services
LFl: Space Management and Facilities Planning
LF2: ?
LF3: Operations, Maintenance and Utilities
LF4: ?
LF5: Program Management
LL: Logistics Services
LL1: Material Management
LL2: Transportation, Asset, and Disposition Services
LL22: Passport Services Team
LL23: ?
LL234M: Property Support
LL24: Material Disposition Services (MDS)
LL241: Secure Collection Services
LL242: Chemical Excess Center
LL243: Secure Paper Conversion and Precious Metals Reclamation
LL244: CLEANSWEEP/Warehouse
LL3: Employee Morale Services
LL4: ?
LL42: Corporate Travel Services



M: Associate Directorate for Human Resource Services (ADHRS)
MA: Office of Workforce Strategies
MB: Office of Recruitment and Staffing
MC: Office of Diversity Management (ODM)
MD: Office of Human Resource Program Management & Service
MD6: SID Human Resources Service Center *
ME: Office of Occupational Health, Environmental & Safety Services (OHESS)
MG: Office of Global Human Resource Services
M2: Office of Military Personnel
M3: Office of Civilian Personnel
M4: ?
M43: Information Policy Division
MJ: ?
MJ1: HR operations/global personnel SA



Q: Associate Directorate for Security and Counterintelligence (ADS&CI)
Q0: Staff
Q05: Security Operations Center (SOC)
Q07: NSA Counterintelligence Center (NSACC)
Q09: Security Support Staff
Q1: Office of Physical Security
Q123: ?
Q2: Office of Personnel Security
Q223: Counterintelligence Awareness Office
...
Q242: Special Actions
Q3: Investigations Division
Q31: ?
Q311: Counterintelligence Investigations
Q312: Compromise Investigations Branch
Q5: Office of Security
Q509: Security Policy Staff
Q51: Physical Security Division
Q52: Field Security Division
Q55: NSA CCAO
Q56: Security Awareness
Q57: Polygraph
Q7: Counterintelligence

QJ: Joint Program Security Office



R: Research Associate Directorate (RAD or RD)
R1: Mathematics Research Group *
R2: Trusted Systems Research
R21: Cryptographic IA Research
R211: ?
...
R213: High Confidence Software and Systems (HCSS)?
R22: IA Engineering Research
R222: ?
R223: Research Integration
R224: ?
R225: ?
R23: Defense Computing Research
R3: Laboratory for Physical Sciences (LPS)
R4: Laboratory for Telecom Services (LTS)
R5: Language Studies
R6: Computer Information and Science
R63: Innovative Exploration Techniques
R64: ?
R65: ?
R66: ?
R66E: Human Language Technology Research
R66F: JHU
R67: Human Language Technology
R6?: Coping with Information Overload Office
R6?: Disruptive Technologies Office (DTO)
RX: Special Access Research
RV: Oversight and Compliance



S: SIGNALS INTELLIGENCE DIRECTORATE (SID)
(ca. 24.000 employees)
S0: SID Staff
S01: Deputy for Integrated Planning
S012: ?
S0121: SID Communications
S01R: SIGINT Acquisition and Capabilities *
...
S01X: SIGINT Planning, Programming and Execution

S01X1: Technical Support Program Management Office (TSPMO)
S02: Communications and Support Operations
S0231: SID Policy Staff
...
S024: Cover, Control, and Special Access Programs
S0242: ?
S02C: SIGINT Communications *

S02L: ?
S02L1: SIGINT Policy
...
S02L3: SID Intelligence Security Issues *
...
S02S1: SID Property Office *
S02S2: SID Travel Office *
S02O: SIGINT Operations Staff *
S1: CUSTOMER RELATIONSHIPS
S11: Customer Gateway
S111: (Desk for coordinating RFIs and responses)
S112: Customer Account Management (for NATO/DEA/DoJ/DoC/etc.)
S12: Information Sharing Services Branch
S12A: Reporting Board *
S12B: ?
S12C: Consumer Services Unit *
S12C1: Intelink and Interface Services
S12?: Partnership Dissemination Cell (PDC)
S1213: SIGINT Post-Publication Services
S124: Staff Services Division
...
S12M2: Marketing and Communications Branch
S12R: SID Reporting Board
S12T: Technology Services *
S13: Military Integration Office *
S1311: Blue Force Cell
...
S132: Plans & Exercises (PLEX) Division *
S14: National Tactical Integration Office (NTIO)*
S14R: Expeditionairy Requirements Division
S14R2: External Programs Branch
S17: Strategic Intelligence/Economic and Global Issues
S1E: Electromagnetic Space Program Management Office
S1N: ?
S1N2: ?
S1N3: ?
S1P: Plans & Exercises Division
S1P2: EUCOM/NATO/SOUTHCOM/AFRICOM Branch

S2: ANALYSIS and PRODUCTION (A & P)
S20: A&P Staff
S202A4: Center for Digital Content
S202B: Analytic Technologies for the Enterprise
S202B11: Operational Technologies
...
S203A: Access Interface Portfolio
S21: ?
S211: ?
S211A: Advanced Analysis Lab *
S212: ?
S21212: Content Analysis Services
S214: Center for Executive Protection
S215: Advanced Analysis Division (AAD)
...
S21T: TRAILBLAZER Mission Element
S22: ?
S23: Human Language Technology (HLT)
S24: Analytic Services and Technology (AS&T)*
S241: Advanced Intelligence Research Services (AIRS)
S2413: Center for Time-Sensitive Information
S242: Analytic Technologies for the Enterprise
S243: Technology Management Services
S2A: South Asia Product Line
...
S2A21: Sudan/North Africa team
S2A4: Pakistan
S2A5: (South-Asia)
S2A51: S-A Language Analysis Branch
S2A52: S-A Reporting Branch
S2B: China, Korea, Taiwan Product Line
S2B33: Office of China and Korea
S2C: International Security Issues (ISI) Product Line
S2C13: Strategic Partnerships & Energy SIGDEV
...
S2C21: ?
...
S2C22: Targeting Office of Primary Interest (TOPI) *
...
S2C32: European States Branch
...
S2C41: Mexico Leadership Team
S2C42: Brazilian Leadership Team
...
S2C51: ?
S2C52: (United Nations?)*
S2C53: Greece and Ukraine *
S2D: Counter Intelligence and HUMINT Support
S2D1: Central Eurasia Division
...
S2D31: Support to HUMINT operations
S2D32: Follow-the-People branch
S2E: Middle East and Africa (MEA) Product Line
S2E22: Iraq branch
...
S2E3: Near East Division
S2E32: North African Branch
S2E321: Egypt Team *
S2E33: LEVANT Internal Team *
S2E4: Iran? Division
S2E41: Iran Government Branch
S2E43: Iran Leadership Branch
S2F: International Crime & Narcotics (ICN) Product Line
S2F1: ("Southern Arc"?)
S2F21: Transnational Organized Crime *
S2F214: Money laundering?
S2G: Counter Proliferation (CP) Product Line
S2G21: Office of Proliferation and Arms Control
...
S2G6: Office of Combating Proliferation
S2H: Russia Product Line
S2H2: ?
S2H21: Russian Foreign Policy *

S2H3: Russian WMD and Defense Technologies *
S2H4: Russian Military *
S2H46: Technical Analysis Branch *

S2I: Counter-Terrorism (CT) Product Line
S2I02: Management Services *
S2I11: Al Qa'ida Senior Leadership Branch
S2I12: ?
S2I13: Global Jihad Support Network Branch
S2I2: Middle East and Iraq Division
S2I3: ?
S2I35: ? (related to RC-135U?)
S2I4: Homeland Security Analysis Center (HSAC)
S2I41: Branch Management
S2I42: Hezbollah Team
S2I43: NOM Team
S2I5: Advanced Analysis Division (AAD)
S2I51: ?
S2I?: Metadata Analysis Center (MAC)
S2IX: Special CT Operations
S2J: Weapons and Space Product Line
S2K: ?
S2K12: Target Behavior; and the Europe and Africa IMT *
S2L: Geospatial Exploitation Office (GEO)
S2L1: Operations Division
S2T: Current Threats
S2S: ?
S2S1: Metadata Analysis Center (MAC)
Communications Event Analysis Center (CEAC)

S3: DATA ACQUISITION
S31: Cryptanalysis and Exploitation Services (CES)
S310: ?
S31091: Military Operations Branch
S311: Office of Target Pursuit (OTP)
S31122: Unidentified Protocols team

S31131: Exploitation branche
S31133: Exploitation branche
S31142: Exploitation branche
S31143: Exploitation branche
S31153: Target Analysis Branch of Network Information Exploitation *
S3117: Cryptanalytic Exploitation & Discovery
S31171: PRC, N-Korea, SE Asia, Japan
S31172: Iran, Hamas, Iraq, Saudi Arabia
S31173: Africa, Levant, Latin America, India, Pakistan, Afghanistan
S31174: Russia, Counter-Intek, Europe, FTM
S31175: Cross-Target Support Branch
S31176: Custom Thread Development for Network Encryption
S31177: TRANSGRESSION Branch
S31??: Technical Exploitation Center (TEC)
...
S312: ?
S31213: Network Security Products
...
S31241: Attack Services
S31243: LONGHAUL/C2DP?
S31244: OTTERCREEK (VPN exploitation)

S313: Requirements and Thread Management (or Exploitation Solutions Office)
S3132: Protocol Exploitation and Dissemination
S31322: Digital Network Crypt Applications (DNCA)
S31323: ?
S314: ?

S316: Target Reconaissance and Survey
S3161: Special Deployments Division

S32: Tailored Access Operations (TAO)
S321: Remote Operations Center (ROC)
S321?: Network Ops Center (NOC)
S321?: Oper. Readiness Division (ORD)
S321?: Interactive Ops Division (IOD)
S321?: Production Ops Division (POD)
S321?: Access Ops Division (AOD)
S322: Advanced Network Technology (ANT)
S3221: (persistence software)
S3222: (software implants)
S32221: ?
S32222: (routers, servers, etc.)
S3223: (hardware implants)
S3224: ?
S32241: ?
S32242: (GSM cell)
S32243: (radar retro-refl.)
S323: Data Network Technologies (DNT)
S3231: Access Division
S32313: Application Vulnerabilities Branch
S3232: Cyber Networks Technology Division
S3234: Computer Technology Division
S3235: Network Technology Division
S32354: STDP (FASHIONCLEFT)
S324: Telecomm. Network Technologies (TNT)
S32423: ?
S325: Mission Infrastructure Technologies (MIT)
S327: Requirements & Targeting (R&T)
S326: Access Operations
S3261: Access and Target Development
S328: Access Technologies & Operations (ATO)
S3283: Expeditionary Access Operations (EAO)
...
S3285: Persistance POLITERAIN team

S32P: TAO Program Planning Integration
S32?: Network Warfare Team (NWT)
S32X: ?

S33: Global Access Operations (GAO) (or Link Access Programs)
S331: Radio Frequency Office
S3311: Radio Exploitation/Corporate HF Services (CHS)
S33113: HF Mission Management
S3312: FORNSAT
S33121: FORNSAT Planning *
S33123: FORNSAT Planning and Collection Management (FALLOWHAUNT)
...
S3314: Tactical Platforms Division *
S33141: Airborne Collection Management

S332: Terrestrial SIGINT
S3321: ?
S33221: ?
S33223: Processing Systems Engineering and Integration Sector
...
S3323: Global Operations Management Division
S333: Office of Overhead SIGINT
S333?: Overhead Collection Management Center (OCMC)
S3331: Spaceborne Planning *
S33P: Portfolio Management Office (PMO)
S33P1: ?
S33P2: Technology Integration Division
S33P3: Tactical SIGINT Technology Office
S33?: CROSSHAIR Network Management Center (CNMC)
S34: Target Strategies and Mission Integration (TSMI)
S342: Collection Coordination and Strategies
S3421: ?
S3422: Geographical Regions
S3423: Technical Services
S343: Targeting and Mission Management
S344: Partnership and Enterprise Management

S35: Special Source Operations (SSO)
S350: ?
S35093: Target Exploitation Program
S351: Program Management Division
S3511: Terrestrial RF Division
...
S3516: JUBILEECORONA?

S352: Engineering & Technical Services Division
S3520: Office of Target Reconaissance and Survey (OTRS)
S3521: Special Signal Collection unit (MUSKETEER)
S353: Operations & Discovery Division
S3531: Mission Management for PRISM and FAIRVIEW
S3532: Engineering & Technical Services Division
S35324: OAKSTAR Program Office
S3533: Operations & Discovery Division *
S35333: PRISM Collection Management
S35??: Environmental Analysis Branch
S35P: Portfolio Management Office
S35P2: Technical Integration Division
S35P3: Capabilities Integration Division
S3C: Collection Strategies and Requirements Center (CSRC)
S3C3: ?
S3C32: Collection Forwarding & Outages
S3C33: Initial Flow Management branch

S3M2: (Media Leaks Task Force?)

S3T: ?
S3T1: ?

S3W: Wireless Portfolio Management Office (WPMO)
S4: ?
S44: ?
S444: Special Operational Support

SSG: SIGDEV Strategy and Governance
SSG1: ?
SSG11: ?
...
SSG13: ?
SSG2: ?
SSG21: Net Pursuit Network Analysis Center
SSG22: Network Analysis Center (NAC)
...
SSG??: Target Analysis Center (TAC)
SSG4: Target Technology Trends Center (T3C)

SE: SIGINT & Electronic Warfare

SV: Oversight and Compliance
SV2: Training
SV21: Access Oversight Training and Strategic Guidance
SV3: Compliance Verification

SV4: FISA Authorities Division
SV41: ?
SV42: Special FISA Oversight and Processing
SV43: ?



T: TECHNOLOGY DIRECTORATE
TE: Enterprise Systems
TS: Information and Systems Security
TT: Independent Test and Evaluation

T1: Mission Capabilities
T1?: Strategic SATCOM Security Engineering Office
T11: ?
T111: TUTELAGE
T112: TURMOIL
T113: TUMULT
T12: Analytic Capabilities
T121: ?
T1211: ?
...
T122: Knowledge Services
T1221: Center for Content Extraction (CCE)
T1222: Enrichment Center/Operations
T13: ?
T132: Structured Repositories
T14: ?
T1412: (TURBINE team?)
...
T1422: Identifier Scoreboard
...
T1442: ?
T163: Deployment & Infrastructure
T2: Business Capabilities

T3: Enterprise IT Services
T314: End User Solutions
T32: ?
T3212: Workflow, Standards and Support
...
T3221: Transport Field Services (TFS)
T332: Global Enterprise Command Center (GECC) *
T332?: Data and Network Operations
T332?: NSA Communications Center
T332?: NISIRT (contains CERT and CSIRT)
T33221: Transport Field Services
T333: ?
T3332: Data Operations Center (DOC)
T334: National Signals Processing Center (NSPC)
T335: Deployable Communications Operations (DCO)
T33?: National Intelligence and Tactical Operations (NITO)
T5: High Performance Computing (HPC) Center
T53: HPC Integration and Production
T532: Cryptanalytic (CA) Databases
T5323: LONGHAUL team
T6: Ground Systems Program Office

T9: ?
T99: ?

TV: Office of compliance



V: NSA/CSS Threat Operations Center (NTOC)
V07: ?
V2: Office of Analysis
V22: ?
V222: ?
V225: ?
V23: ?
V24: ?
V25: Malicious Activity Discovery-Characterization
V252: ?
V26: ?
V3: Office of Operations
V32: Defensive Network Operations
V33: ?
V34: Next Generation Wireless Exploitation Program
V35: ?
V4: Technology Development Support
V43: Cyber Profiling and Operations Support
...
V45: Office of Technology Development
V46: Technology Planning and Assessment
V47: Technology Development
VS: ?

VV: NTOC Oversight and Compliance (NOC)



X: ?
X3: ?
X31: ?
X312: Planning & Management *
X32: ?
X3224: ?


? NSA/CSS Commercial Solutions Center (NCSC)







The 2000 reorganization

In the year 2000, then director Michael Hayden reorganized much of NSA's organizational structure. For this the NSA Transformation Office (NTO) was established and the Directorate of Operations and the Directorate of Technology were merged into the Signals Intelligence Directorate (SID).

Also new officers were appointed, like a Chief Financial manager, a Chief Information Officer (CIO), a Senior Acquisition Executive (SAE) and a Transformation Officer. Around the same time, many NSA divisions and units got new designations.

Also in 2000, a Senior Leadership team was formed, consisting of the Director (DIRNSA), the Deputy Director and the Directors of the Signals Intelligence (SID), the Information Assurance (IAD) and the Technology Directorate (TD). The chiefs of other main NSA divisions became Associate Directors of the Senior Leadership team.


The 2016 reorganization

In 2016, NSA director Michael Rogers initiated a reorganization under the name NSA21, which has to prepare the agency for "cyber" challenges. One of the most important changes will be to replace the Signals Intelligence (SID) and Information Assurance (IAD) directorates by a new Directorate of Operations that combines the operational elements of each. The hacking division Tailored Access Operations (TAO) has been renamed into Computer Network Operations. NSA21 reached full operational capability in December 2017.

Also the other existing branches will be reorganized into the following 6 new directorates:
- Workforce and Support Activities
- Business Management and Acquisition
- Engagement and Policy
- Operations
- Capabilities
- Research

> See also: The NSA's new organizational designators





The 2026 reorganization

In September 2026, NSA director Joshua M. Rudd announced a new and extensive internal restructuring which creates five new departments inside the agency. Each of these departments will be led by a newly elevated "mission director" which will have the effective authorities of a deputy director. It's not yet clear whether the five new departments will replace the NSA's existing divisions or will be superimposed atop the agency’s existing structure.

The five new mission departments of the NSA will be:
- Artificial Intelligence
- China
- Cybersecurity
- Combat support or warfighting
- Global intelligence (Including TAO)



Links and Sources
- Observer.com: REORG: How Not to Fix American Intelligence
- NSA: NSA21: Facing Threats to the Nation and Future Challenges with Innovation, Integration, and a Focus on Talent
- Washington Post: National Security Agency plans major reorganization
- Cryptome.org: NSA Salaries 2014
- Marc Ambinder's The NSA's org chart
- TheWeek.com: The NSA's org chart
- MatthewAid.com: Updated NSA Order of Battle
- William M. Arkin Online: NSA Tailored Access Operations
- Independent.co.uk: Inside the NSA: Peeling back the curtain on America's intelligence agency
- TheAtlantic.com: An Educated Guess About How the NSA Is Structured
- GovernmentAttic.org: Extract of pages from the NSA's intranet, 2005 (pdf)
- Cryptome.org: NSA Overhauls Corporate Structure in Effort to Improve Operations (2000)
- FAS.org: National Security Agency - Organization and Functions (before 2000)
Some older articles on this weblog that are of current interest:
In Dutch: Volg de actuele ontwikkelingen rond de Wet op de inlichtingen- en veiligheidsdiensten via het Dossier herziening Wiv 2017