T h e Co m p r e h e n s i v e Nat i o na l C y b e r s e c u r i t y I n i t i at i v e
more effectively develop and more readily share security relevant information with network defenders
across the U.S. Government, as well as with security professionals in the private sector and the American
public. The Department of Homeland Security’s Privacy Office has conducted and published a Privacy
Impact Assessment for the EINSTEIN 2 program.
Initiative #3. Pursue deployment of intrusion prevention systems across the Federal enterprise.
This Initiative represents the next evolution of protection for civilian Departments and Agencies of
the Federal Executive Branch. This approach, called EINSTEIN 3, will draw on commercial technology
and specialized government technology to conduct real-time full packet inspection and threat-based
decision-making on network traffic entering or leaving these Executive Branch networks. The goal of
EINSTEIN 3 is to identify and characterize malicious network traffic to enhance cybersecurity analysis,
situational awareness and security response. It will have the ability to automatically detect and respond
appropriately to cyber threats before harm is done, providing an intrusion prevention system supporting
dynamic defense. EINSTEIN 3 will assist DHS US-CERT in defending, protecting and reducing vulnerabilities on Federal Executive Branch networks and systems. The EINSTEIN 3 system will also support
enhanced information sharing by US-CERT with Federal Departments and Agencies by giving DHS the
ability to automate alerting of detected network intrusion attempts and, when deemed necessary by
DHS, to send alerts that do not contain the content of communications to the National Security Agency
(NSA) so that DHS efforts may be supported by NSA exercising its lawfully authorized missions. This
initiative makes substantial and long-term investments to increase national intelligence capabilities
to discover critical information about foreign cyber threats and use this insight to inform EINSTEIN 3
systems in real time. DHS will be able to adapt threat signatures determined by NSA in the course of its
foreign intelligence and DoD information assurance missions for use in the EINSTEIN 3 system in support
of DHS’s federal system security mission. Information sharing on cyber intrusions will be conducted in
accordance with the laws and oversight for activities related to homeland security, intelligence, and
defense in order to protect the privacy and rights of U.S. citizens.
DHS is currently conducting a exercise to pilot the EINSTEIN 3 capabilities described in this initiative
based on technology developed by NSA and to solidify processes for managing and protecting information gleaned from observed cyber intrusions against civilian Executive Branch systems. Government
civil liberties and privacy officials are working closely with DHS and US-CERT to build appropriate and
necessary privacy protections into the design and operational deployment of EINSTEIN 3.
Initiative #4: Coordinate and redirect research and development (R&D) efforts. No single individual
or organization is aware of all of the cyber-related R&D activities being funded by the Government. This
initiative is developing strategies and structures for coordinating all cyber R&D sponsored or conducted
by the U.S. government, both classified and unclassified, and to redirect that R&D where needed. This
Initiative is critical to eliminate redundancies in federally funded cybersecurity research, and to identify
research gaps, prioritize R&D efforts, and ensure the taxpayers are getting full value for their money as
we shape our strategic investments.
Initiative #5. Connect current cyber ops centers to enhance situational awareness. There is a
pressing need to ensure that government information security offices and strategic operations centers
share data regarding malicious activities against federal systems, consistent with privacy protections
★
3
★