to-hire and by ensuring cybersecurity job announcements contain clear, technical content.
DHS must also post their own internal Cyber Workforce Analysis results on the CIO
Council Knowledge Portal by November 30, 2015, as a best practice for other agencies
to leverage.
c. The CSIP directs OPM, DHS, and OMB, in coordination with NIST and other NICE
partner agencies, to map the entire cyber workforce landscape across all agencies using
the NICE National Cybersecurity Workforce Framework and identify cyber talent gaps
and recommendations for closing them within 6 months. The mapping exercise and
recommendation report should focus on:
i. Existing employees and open positions, starting with the civilian agencies, this
assessment should also consider contractor resources.
ii. Existing resources and open positions within the DoD and the IC, this assessment
should also consider contractor resources.
iii. Changes to human resources processes and systems that not only incorporate best
practices for retaining and incentivizing employees, but simplify and expedite the
hiring process.
iv. Capacity building actions to assist human resource professionals in their efforts to
implement CSIP recommendations.
v. Training and professional development opportunities for the existing workforce in
order to address critical needs.
vi. Leveraging the National Science Foundation CyberCorps® Scholarship for
Service and the Advanced Technological Education program to help inform
potential educational programs to help develop a pipeline of students from
colleges, universities, and other providers.
vii. Driving awareness of cybersecurity internship opportunities and programs that
establish the possibility of hiring participants into permanent positions.
viii. Creating and deploying “Tiger Teams” comprised of subject matter experts from
across the Government to address critical workforce needs.
d. The CSIP also directs OPM, DHS, and OMB, in coordination with NIST and other NICE
partner agencies, to develop recommendations for Federal workforce training and
professional development in functional areas outside of cybersecurity and information
technology that support cybersecurity efforts within 6 months. These recommendations
should address, at a minimum, the following functional areas: legal counsel, budget,
procurement, privacy, and civil rights and liberties.
Page 19 of 21