II.
Objective 2: Timely Detection of and Rapid Response to Cyber Incidents
Detect
The Sprint Team found that Federal civilian agency threat-detection capabilities have
improved significantly in recent years. With DHS’s EINSTEIN program providing network
perimeter protection and the CDM program providing ongoing awareness of assets and
activities within the network, agencies deploying these capabilities are now in a stronger
position. Agencies have also made great strides in their efforts to share and receive cyber
threat information, both with other agencies and the private sector, which allows network
defenders to detect and block cyber intrusions before they cause damage. This section of the
CSIP identifies further improvements that OMB, DHS, and Federal agencies will take to
enhance information sharing efforts, detect cyber threats in real time, and rapidly respond to
cyber incidents.
a. For agencies to deploy strong perimeter protections, DHS will build on the current
EINSTEIN platform to implement advanced protections beyond the current signaturebased approach. DHS has initiated the following efforts to advance the EINSTEIN
program:
i. DHS is piloting behavioral-based analytics to extend beyond the current approach
of using known signatures and begin identifying threat activity that takes
advantage of zero-day cyber intrusion methods. DHS is examining technologies
from the private sector to evolve to this next stage of network defense. DHS will
share lessons learned from the pilot study and next steps with OMB by March
31, 2016.
ii. DHS has issued a contract action that will provide EINSTEIN 3A protections to
participating agencies that are not covered by the ISPs currently under contract.
This contract will make certain EINSTEIN 3A protections (e-mail and domain
name system) available to all Federal Civilian Government agencies by
December 31, 2015.
b. Agencies rely on protections deployed through their trusted internet connection (TIC) or
Managed Trusted Internet Protocol Services (MTIPS) providers. OMB Cyber, in
coordination with DHS, will initiate a 30-day review of current TIC architecture and
baseline controls upon release of the CSIP with a focus on:
i. Continuous agency review of their public-facing Internet connections for
consolidation and reduction.
ii. Ensuring all possible traffic, including mobile and cloud, goes through a TIC.
iii. Options for where TICs can be hosted to improve bandwidth coverage.
iv. Additional tools that can be implemented at a TIC location.
v. How external vendors who store, process, and transmit agency data for or on
behalf of the government can have their traffic securely encapsulated within the
TIC connectivity.
c. The CSIP emphasizes ways to advance Federal-wide information sharing on critical
vulnerabilities and threats, indicators of compromise, and best practices. Information
sharing is essential not only for detecting and blocking intrusions on a specific targeted
Page 14 of 21