II. Objective 2: Timely Detection of and Rapid Response to Cyber Incidents Detect The Sprint Team found that Federal civilian agency threat-detection capabilities have improved significantly in recent years. With DHS’s EINSTEIN program providing network perimeter protection and the CDM program providing ongoing awareness of assets and activities within the network, agencies deploying these capabilities are now in a stronger position. Agencies have also made great strides in their efforts to share and receive cyber threat information, both with other agencies and the private sector, which allows network defenders to detect and block cyber intrusions before they cause damage. This section of the CSIP identifies further improvements that OMB, DHS, and Federal agencies will take to enhance information sharing efforts, detect cyber threats in real time, and rapidly respond to cyber incidents. a. For agencies to deploy strong perimeter protections, DHS will build on the current EINSTEIN platform to implement advanced protections beyond the current signaturebased approach. DHS has initiated the following efforts to advance the EINSTEIN program: i. DHS is piloting behavioral-based analytics to extend beyond the current approach of using known signatures and begin identifying threat activity that takes advantage of zero-day cyber intrusion methods. DHS is examining technologies from the private sector to evolve to this next stage of network defense. DHS will share lessons learned from the pilot study and next steps with OMB by March 31, 2016. ii. DHS has issued a contract action that will provide EINSTEIN 3A protections to participating agencies that are not covered by the ISPs currently under contract. This contract will make certain EINSTEIN 3A protections (e-mail and domain name system) available to all Federal Civilian Government agencies by December 31, 2015. b. Agencies rely on protections deployed through their trusted internet connection (TIC) or Managed Trusted Internet Protocol Services (MTIPS) providers. OMB Cyber, in coordination with DHS, will initiate a 30-day review of current TIC architecture and baseline controls upon release of the CSIP with a focus on: i. Continuous agency review of their public-facing Internet connections for consolidation and reduction. ii. Ensuring all possible traffic, including mobile and cloud, goes through a TIC. iii. Options for where TICs can be hosted to improve bandwidth coverage. iv. Additional tools that can be implemented at a TIC location. v. How external vendors who store, process, and transmit agency data for or on behalf of the government can have their traffic securely encapsulated within the TIC connectivity. c. The CSIP emphasizes ways to advance Federal-wide information sharing on critical vulnerabilities and threats, indicators of compromise, and best practices. Information sharing is essential not only for detecting and blocking intrusions on a specific targeted Page 14 of 21

Select target paragraph3