a. Tighten privileged user policies, practices, and procedures.
i. The Cybersecurity Sprint Team required agencies to immediately review policies
and practices for privileged users. Agencies should continue to:
x inventory and validate privileged account scope and numbers;
x minimize the number of privileged users;
x limit functions that can be performed when using privileged accounts;
x limit the duration that privileged users can be logged in;
x limit the privileged functions that can be performed using remote access; and
x ensure that privileged user activities are logged and regularly reviewed.
b. Complete PIV implementation for all employees and contractors 6 required to obtain a
PIV.
i. The Cybersecurity Sprint directed agencies to immediately implement PIV for the
following targets:
x 100% of privileged users. 7
x 75% of non-privileged users. 8
a. The CAP Goal for FY 2016 Q1 is 85% of non-privileged users.
ii. To facilitate this process, the Cybersecurity Sprint Team developed a compilation
of best practices for PIV implementation and posted the collection on the CIO
Council’s Knowledge Portal.
iii. Where necessary, GSA, in coordination with OMB, DHS, and DOD, and in
consultation with NIST, will deploy technical resources for defined periods to
assist agencies with remaining PIV implementation challenges.
iv. The CSIP directs NIST to publish best practices for privileged user PIV
implementation based on lessons learned from the Sprint within 30 days. 9
v. OPM, in coordination with NIST, OMB, and GSA, will update guidance on
foreign nationals with regards to HSPD-12 applicability by December 31, 2015.
c. Address all critical vulnerabilities 10 and scan for Indicators of Compromise.
i. Moving forward and on a rolling basis, the CSIP requires agencies to scan for
indicators of compromise within 24 hours of receipt of the indicators from DHS.
6
As defined by OMB Memorandum M-05-24: Implementation of Homeland Security Presidential Directive (HSPD)
12 – Policy for Common Identification Standards for Federal Employees and Contractors.
7
A network account with elevated privileges which is typically allocated to system administrators, network
administrators, DBAs, and others who are responsible for system/application control, monitoring, or administration
functions. – 2015 FISMA Metrics
8
An unprivileged network account is any account that is not a privileged network account. – 2015 FISMA Metrics
9
All instances of “within X days” in the CSIP means the deadline for the action is “within X days of the CSIP’s
issuance.”
10
The DHS National Cybersecurity Assessments and Technical Services (NCATS) team identifies critical
vulnerabilities at agencies and assigns a severity score based on an industry-standard scoring model. For further
questions contact ncats_info@hq.dhs.gov.
Page 11 of 21