V. Objective 5: Efficient and Effective Acquisition and Deployment of Existing and Emerging Technology Existing/Emerging Technology As stated above, the CSIP acknowledges the need for a defense in depth approach, or a layering of people, processes, procedures, and tools, to achieve a more secure Federal landscape. This section describes the steps the Federal Government must take to provide agencies with the appropriate technological toolset to adequately secure the functions, systems, and information enabling their missions. The Cybersecurity Sprint Team observed that the Federal Government has made strides in the incubation and adoption of emerging technology for cybersecurity purposes through innovation and incubator programs, to include the Defense Advanced Research Projects Agency’s Information Innovation Office (I2O), the DHS Homeland Security Advanced Research Projects Agency (HSARPA), in particular the Transition to Practice (TTP) program, and the NSF Secure and Trustworthy Cyberspace (SaTC) Transition to Practice (TTP) program. Furthermore, Federal agencies have adopted existing commercially available off-the-shelf (COTS) technology through programs like EINSTEIN and CDM. In addition to these incubators, the NIST National Cybersecurity Center of Excellence (NCCoE) is a public-private partnership that fosters innovation and accelerates the adoption of secure technologies for the public and private sectors. However, the connection between these programs and the agencies in need of existing and emerging technology must be strengthened. The Cybersecurity Sprint identified a need for a Federal-wide technology assessment followed by a comprehensive program to assist agencies with the procurement, assessment, certification and accreditation of existing and emerging technology. The CSIP initiates the following actions to address the challenge of acquisition and deployment of existing and emerging technology: a. OMB, in coordination with NSC, and OSTP, will convene a working group comprising representatives, as appropriate, from DHS, GSA, NIST, DOD, and the CIO Council, to develop recommendations for strengthening and better coordinating the collective ability of Federal civilian departments and agencies to identify, acquire, and rapidly implement innovative commercially-available cybersecurity products and services. The working group will deliver its recommendations to the Federal CIO and NSC Coordinator for Cybersecurity by March 31, 2016. b. The CSIP directs GSA to develop a procurement capability to allow Federal agencies to access the technology at any known Federal technology incubator, to include, but not limited to, the NCCoE, I2O, and DHS HSARPA by December 31, 2015. c. The CSIP directs the Federal CIO Council to create an Emerging Technology SubCommittee under the ISIMC by December 31, 2015 that will be responsible for facilitating efforts to expediently deploy emerging technologies at Federal agencies. This group will provide requirements, challenges, and feedback to both incubators and agencies. Page 20 of 21

Select target paragraph3