Protect Over the course of the Cybersecurity Sprint, Federal civilian agencies increased their overall use of strong authentication from 42 percent to 72 percent. Specifically, Federal civilian agencies increased use of strong authentication for privileged users from 33 percent to nearly 75 percent. Although there is no single method by which all cyber incidents can be prevented, improving the access management of user accounts on Federal information systems could drastically reduce current vulnerabilities. Privileged user accounts are a known target for malicious actors but can be protected by an existing, strong authentication solution: Personal Identity Verification (PIV) credentials. Implementing strong authentication PIV credentials, as directed in Homeland Security Presidential Directive 12: Policy for a Common Identification Standard for Federal Employees and Contractors (HSPD-12) and Federal Information Processing Standard (FIPS) 201-2: Personal Identity Verification (PIV) of Federal Employees and Contractors, is a cost-effective and immediate action that agencies should take to drastically reduce their risk profiles. PIV credentials efficiently authenticate an employee’s identity and reduce the risk of identity fraud, tampering, counterfeiting, and exploitation. To build on the strong authentication progress made during the Cybersecurity Sprint, in FY 2016 Federal agencies should continue to target the Administration Cybersecurity CAP goal of 100% strong authentication for all privileged users and 85% strong authentication for unprivileged users. While impressive strides have been made in areas such as strong authentication implementation, there is still more work to do. For example, once agencies have identified and inventoried their HVAs and high value information technology systems, they must protect them with a variety of policies, processes, and tools, consistent with applicable OMB guidance and NIST standards. Effective protection activities can include reducing the attack surface and complexity of IT infrastructure; minimizing the use of administrative privileges; utilizing strong authentication credentials; safeguarding data at rest and in-transit; training personnel; ensuring repeatable processes and procedures; adopting innovative and modern technology; ensuring strict domain separation of critical/sensitive information and information systems; and ensuring a current inventory of hardware and software components. Furthermore, the employment of shared services is a proven approach for providing agencies with access to robust capabilities and can result in improved consistency and security across the Federal Government. They can also encourage the common application of standardized best practices, reduce costs and increases efficiencies. The Cybersecurity Sprint Team performed a Federal-wide inventory and assessment of current cyber-focused shared services. The Sprint Team assessed the maturity and effectiveness of these offerings, identified service gaps, and proposed additional offerings to address critical needs. The CSIP initiates the following protection activities to improve Federal cybersecurity. These actions are in addition to those already being undertaken by Federal agencies and do not preclude agencies from continuing complementary work to secure their systems. Page 10 of 21

Select target paragraph3