The CSIP emphasizes the need for a defense in depth 1 approach that relies on the layering of
people, processes, technologies, and operations to achieve more secure Federal information
systems. Inherent in a defense in depth approach is the recognition that all protection
mechanisms have weaknesses that adversaries may exploit through several paths. Implementing
the CSIP will not prevent every cyber incident. In fact, it is likely that agencies will discover
additional and previously unknown malicious activity as they improve prevention and detection
capabilities. Accordingly, the CSIP incorporates procedures to prepare agencies to respond to
and recover from incidents, secure Federal information and assets, and ultimately strengthen
their overall security posture.
The CSIP incorporates feedback from public and private sector subject-matter experts as well as
lessons learned from current cyber incident response and recovery efforts affecting the Federal
Government. The CSIP builds on existing policy work, including the Comprehensive National
Cybersecurity Initiative (CNCI); Presidential Policy Directives; Executive Orders; legislation
such as FISMA; OMB guidance; agency performance and incident data; and Federal Continuity
Directives. The CSIP emphasizes the government-wide adherence to NIST standards and
guidelines and builds on the core concepts of the Framework for Improving Critical
Infrastructure Cybersecurity, which NIST developed in accordance with Executive Order 13636,
Improving Critical Infrastructure Cybersecurity.
Oversight
Responsibility for Federal Government cybersecurity is distributed and shared by all agencies;
however, specific agencies have additional roles in supporting this mission and ensuring that the
Federal Government has the tools, resources, and guidance necessary to make the risk-based
decisions necessary to secure their systems. FISMA states that OMB oversees Federal agency
information security policies and practices. The OMB Cyber and National Security Unit (OMB
Cyber) was created at the beginning of FY 2015 2 to strengthen Federal cybersecurity through:
1) Data-driven, risk-based oversight of agency and government-wide cybersecurity
programs;
2) Issuance and implementation of Federal policies to address emerging IT security risks;
and
3) Oversight of the government-wide response to major incidents and vulnerabilities to
reduce their impact on the Federal Government.
Progress on CSIP implementation will be tracked through several mechanisms, to include the
PMC, comprehensive reviews of agency-specific cybersecurity posture (CyberStats), the CIO
Council and the ISIMC. The quarterly performance reviews will be used to identify major
performance and policy gaps, which will be addressed through regular engagement with agency
leadership and future FISMA guidance. Additionally, OMB and NSC will work within the
1
NIST Special Publication 800-53, Security and Privacy Controls for Federal Information Systems and Organizations,
defines defense in depth as: “information security strategy integrating people, technology, and operations
capabilities to establish variable barriers across multiple layers and missions of the organization.”
2
OMB launched this dedicated unit within the Office of E-Government & Information Technology, also referred to
as the Office of the Federal Chief Information Officer, in the Fiscal Year 2014 Federal Information Security
Management Act Report to Congress.
Page 6 of 21