Protect
Over the course of the Cybersecurity Sprint, Federal civilian agencies increased their overall
use of strong authentication from 42 percent to 72 percent. Specifically, Federal civilian
agencies increased use of strong authentication for privileged users from 33 percent to nearly
75 percent. Although there is no single method by which all cyber incidents can be
prevented, improving the access management of user accounts on Federal information
systems could drastically reduce current vulnerabilities. Privileged user accounts are a
known target for malicious actors but can be protected by an existing, strong authentication
solution: Personal Identity Verification (PIV) credentials. Implementing strong
authentication PIV credentials, as directed in Homeland Security Presidential Directive 12:
Policy for a Common Identification Standard for Federal Employees and Contractors
(HSPD-12) and Federal Information Processing Standard (FIPS) 201-2: Personal Identity
Verification (PIV) of Federal Employees and Contractors, is a cost-effective and immediate
action that agencies should take to drastically reduce their risk profiles. PIV credentials
efficiently authenticate an employee’s identity and reduce the risk of identity fraud,
tampering, counterfeiting, and exploitation.
To build on the strong authentication progress made during the Cybersecurity Sprint, in FY
2016 Federal agencies should continue to target the Administration Cybersecurity CAP goal
of 100% strong authentication for all privileged users and 85% strong authentication for
unprivileged users. While impressive strides have been made in areas such as strong
authentication implementation, there is still more work to do. For example, once agencies
have identified and inventoried their HVAs and high value information technology systems,
they must protect them with a variety of policies, processes, and tools, consistent with
applicable OMB guidance and NIST standards. Effective protection activities can include
reducing the attack surface and complexity of IT infrastructure; minimizing the use of
administrative privileges; utilizing strong authentication credentials; safeguarding data at rest
and in-transit; training personnel; ensuring repeatable processes and procedures; adopting
innovative and modern technology; ensuring strict domain separation of critical/sensitive
information and information systems; and ensuring a current inventory of hardware and
software components.
Furthermore, the employment of shared services is a proven approach for providing agencies
with access to robust capabilities and can result in improved consistency and security across
the Federal Government. They can also encourage the common application of standardized
best practices, reduce costs and increases efficiencies. The Cybersecurity Sprint Team
performed a Federal-wide inventory and assessment of current cyber-focused shared
services. The Sprint Team assessed the maturity and effectiveness of these offerings,
identified service gaps, and proposed additional offerings to address critical needs.
The CSIP initiates the following protection activities to improve Federal cybersecurity.
These actions are in addition to those already being undertaken by Federal agencies and do
not preclude agencies from continuing complementary work to secure their systems.
Page 10 of 21