Introduction Strengthening the cybersecurity of Federal networks, systems, and data is one of the most important challenges we face as a Nation. Every day, the Federal Government experiences increasingly sophisticated and persistent cyber threats. While the Federal Government has prioritized its efforts to address these threats, several fundamental challenges exist which hinder progress in eliminating cybersecurity risks. Among these challenges is a broad surface area of legacy systems with thousands of different hardware and software configurations across the Federal Government, which introduces significant vulnerabilities and opportunities for exploitation. Additionally, each agency is responsible for managing its own information technology systems, which, due to varying levels of cybersecurity expertise and capacity, generates inconsistencies in capability across government. The Federal Government is bringing significant resources to bear to ensure cybersecurity remains a top priority and agencies are held accountable for improving their performance in this critical area. These efforts include strengthening government-wide processes for developing, implementing, and institutionalizing best practices; developing and retaining the cybersecurity workforce; and working with public and private sector research and development communities to leverage the best of existing, new, and emerging technology. To ensure that Federal agencies are dedicating appropriate attention and resources to address these critical and pressing challenges, the FCIO initiated a Cybersecurity Sprint on June 12, 2015. The Cybersecurity Sprint required agencies to take immediate steps to further protect Federal information and assets and improve the resilience of Federal networks. These actions included implementing strong user identity verification and authentication, patching critical vulnerabilities, scanning for cyber threat indicators, identifying critical information assets, and reviewing and reducing the number of privileged user accounts. In addition to providing direction to agencies, the FCIO established a Sprint Team to lead a 30-day review of the Federal Government’s cybersecurity policies, procedures, and practices. Accordingly, the FCIO tasked the Sprint Team with creating and operationalizing a set of action plans and strategies to further address critical cybersecurity priorities and recommend a Federal civilian cybersecurity strategy. The result of those recommendations is the CSIP. The CSIP directs a series of actions to improve capabilities for identifying and detecting vulnerabilities and threats, enhance protections of government assets and information, and further develop robust response and recovery capabilities to ensure readiness and resilience when incidents inevitably occur. The CSIP is part of a broader series of actions to bolster Federal civilian cybersecurity, which includes the issuance of updated guidance under the Federal Information Security Modernization Act of 2014 (P.L. 113-283) (FISMA); revisions to the Federal Government’s governing document establishing policies for the management of Federal information resources: Circular A-130, Managing Information as a Strategic Resource; new guidance on implementing cybersecurity contracting language; cyber incident response best practices for use by Federal civilian agencies; the issuance of a blanket purchase agreement for Identity Protection Services designed to give Federal agencies ready access to best-in-class solutions and reduce wasteful and inefficient duplicative contracts for common-use services; and an updated Cybersecurity Cross-Agency Priority (CAP) Goal to improve Federal cybersecurity performance. Page 5 of 21

Select target paragraph3