Administrator of General Services acting through FedRAMP, shall develop a Federal
cloud-security strategy and provide guidance to agencies accordingly. Such guidance
shall seek to ensure that risks to the FCEB from using cloud-based services are broadly
understood and effectively addressed, and that FCEB Agencies move closer to Zero Trust
Architecture.
(ii) Within 90 days of the date of this order, the Secretary of Homeland Security
acting through the Director of CISA, in consultation with the Director of OMB and the
Administrator of General Services acting through FedRAMP, shall develop and issue, for
the FCEB, cloud-security technical reference architecture documentation that illustrates
recommended approaches to cloud migration and data protection for agency data
collection and reporting.
(iii) Within 60 days of the date of this order, the Secretary of Homeland Security
acting through the Director of CISA shall develop and issue, for FCEB Agencies, a cloudservice governance framework. That framework shall identify a range of services and
protections available to agencies based on incident severity. That framework shall also
identify data and processing activities associated with those services and protections.
(iv) Within 90 days of the date of this order, the heads of FCEB Agencies, in
consultation with the Secretary of Homeland Security acting through the Director of
CISA, shall evaluate the types and sensitivity of their respective agency’s unclassified data,
and shall provide to the Secretary of Homeland Security through the Director of CISA and
to the Director of OMB a report based on such evaluation. The evaluation shall prioritize
identification of the unclassified data considered by the agency to be the most sensitive
and under the greatest threat, and appropriate processing and storage solutions for
those data.
(d) Within 180 days of the date of this order, agencies shall adopt multi-factor
authentication and encryption for data at rest and in transit, to the maximum extent
consistent with Federal records laws and other applicable laws. To that end:
(i) Heads of FCEB Agencies shall provide reports to the Secretary of Homeland
Security through the Director of CISA, the Director of OMB, and the APNSA on their
respective agency’s progress in adopting multifactor authentication and encryption of
data at rest and in transit. Such agencies shall provide such reports every 60 days after
the date of this order until the agency has fully adopted, agency-wide, multi-factor
authentication and data encryption.
(ii) Based on identified gaps in agency implementation, CISA shall take all
appropriate steps to maximize adoption by FCEB Agencies of technologies and processes
to implement multifactor authentication and encryption for data at rest and in transit.
(iii) Heads of FCEB Agencies that are unable to fully adopt multi-factor
authentication and data encryption within 180 days of the date of this order shall, at the
end of the 180-day period, provide a written rationale to the Secretary of Homeland
Security through the Director of CISA, the Director of OMB, and the APNSA.
(e) Within 90 days of the date of this order, the Secretary of Homeland Security acting
through the Director of CISA, in consultation with the Attorney General, the Director
of the FBI, and the Administrator of General Services acting through the Director of
FedRAMP, shall establish a framework to collaborate on cybersecurity and incident
response activities related to FCEB cloud technology, in order to ensure effective
5/18