ii. Consistent with DHS’s Binding Operational Directive 15-01, Critical
Vulnerability Mitigation Requirements for Federal Civilian Executive Branch
Departments’ and Agencies’ Internet-Accessible Systems, the CSIP directs
agencies to patch all critical vulnerabilities immediately or, at a minimum, within
30 days of patch release. Vulnerabilities existing longer than 30 days will be
included in agency PMC reports.
d. NSC and OMB will release the EO 13681, Improving the Security of Consumer Financial
Transactions Implementation Plan by December 31, 2015, to require implementation of
strong authentication and effective identity proofing for government digital services that
make personal data accessible to citizens online.
e. Drawing on the work of the Sprint Team, OMB will release a plan for implementing new
cybersecurity shared services within 3 months. These services will augment or
supplement existing agency services, while providing new services for agencies without
existing capabilities. Potential service offerings could include, but are not limited to:
i. Identity, Authentication, and Authorization Services:
x Agencies’ ability to further their mission and achieve efficiencies by placing
high value services online requires them to be able to have confidence in the
identities of users accessing these services. This set of shared identity
services could enable agencies to access digital credentials based on effective
identity proofing methodologies and user-friendly strong authentication
technologies. In addition, agencies can obtain validated information to
support authorization decisions so that appropriate users can access their
resources or benefits.
ii. Mobile Security Services:
x Mobile devices have become as powerful and connected as desktop and laptop
computers, requiring the same level of attention to cybersecurity. Mobile
security has unique challenges that require different solutions than existing
programs offer. This service (or services) could address authentication,
application management, device management, and encryption, and may
include approved tools, best practices, and implementation support.
iii. Network Segmentation Services:
x Effective network segmentation management requires consistent application
of best practices to limit lateral movement across networks. This shared
service could provide network segmentation shared service capabilities across
the Federal Government to help ensure that agencies consistently apply best
practices to this complex management task. If operationalized, all Federal
organizations would be asked to provide recommendations to the network
segmentation services management offering to guide the proper
implementation of network segmentation within an organization.
iv. Digital Rights Management:
x A digital rights management (DRM) shared service capability could enable a
systematic approach to data-level protection across the Federal Government
Page 12 of 21