Introduction
Strengthening the cybersecurity of Federal networks, systems, and data is one of the most
important challenges we face as a Nation. Every day, the Federal Government experiences
increasingly sophisticated and persistent cyber threats. While the Federal Government has
prioritized its efforts to address these threats, several fundamental challenges exist which hinder
progress in eliminating cybersecurity risks. Among these challenges is a broad surface area of
legacy systems with thousands of different hardware and software configurations across the
Federal Government, which introduces significant vulnerabilities and opportunities for
exploitation. Additionally, each agency is responsible for managing its own information
technology systems, which, due to varying levels of cybersecurity expertise and capacity,
generates inconsistencies in capability across government.
The Federal Government is bringing significant resources to bear to ensure cybersecurity
remains a top priority and agencies are held accountable for improving their performance in this
critical area. These efforts include strengthening government-wide processes for developing,
implementing, and institutionalizing best practices; developing and retaining the cybersecurity
workforce; and working with public and private sector research and development communities to
leverage the best of existing, new, and emerging technology.
To ensure that Federal agencies are dedicating appropriate attention and resources to address
these critical and pressing challenges, the FCIO initiated a Cybersecurity Sprint on June 12,
2015. The Cybersecurity Sprint required agencies to take immediate steps to further protect
Federal information and assets and improve the resilience of Federal networks. These actions
included implementing strong user identity verification and authentication, patching critical
vulnerabilities, scanning for cyber threat indicators, identifying critical information assets, and
reviewing and reducing the number of privileged user accounts. In addition to providing
direction to agencies, the FCIO established a Sprint Team to lead a 30-day review of the Federal
Government’s cybersecurity policies, procedures, and practices. Accordingly, the FCIO tasked
the Sprint Team with creating and operationalizing a set of action plans and strategies to further
address critical cybersecurity priorities and recommend a Federal civilian cybersecurity strategy.
The result of those recommendations is the CSIP.
The CSIP directs a series of actions to improve capabilities for identifying and detecting
vulnerabilities and threats, enhance protections of government assets and information, and
further develop robust response and recovery capabilities to ensure readiness and resilience when
incidents inevitably occur. The CSIP is part of a broader series of actions to bolster Federal
civilian cybersecurity, which includes the issuance of updated guidance under the Federal
Information Security Modernization Act of 2014 (P.L. 113-283) (FISMA); revisions to the
Federal Government’s governing document establishing policies for the management of Federal
information resources: Circular A-130, Managing Information as a Strategic Resource; new
guidance on implementing cybersecurity contracting language; cyber incident response best
practices for use by Federal civilian agencies; the issuance of a blanket purchase agreement for
Identity Protection Services designed to give Federal agencies ready access to best-in-class
solutions and reduce wasteful and inefficient duplicative contracts for common-use services; and
an updated Cybersecurity Cross-Agency Priority (CAP) Goal to improve Federal cybersecurity
performance.
Page 5 of 21