III. Objective 3: Rapid Recovery From Incidents When They Occur and Accelerated Adoption of Lessons Learned From The Sprint Assessment Recovery The CSIP defines “recover” as the development and implementation of plans, processes, and procedures for recovery and full restoration, in a timely manner, of any capabilities or services that are impaired due to a cyber event. The Cybersecurity Sprint identified that Federal-wide and agency-specific policies and practices for recovering from cyber events are inconsistent and vary in degree of maturity. In recent years, the Federal Government has prioritized protecting its assets and detecting threats. As an increasing number of threats are detected, the Federal Government must begin to improve both its response and recovery capabilities. Recent events have demonstrated the need for policies or plans related to recovery from cyber events to remain flexible to better allow agencies to respond to and recover from evolving and sophisticated threats. To date, there have been a number of Federal-wide policies and standards that provide guidance as to how agencies should recover from cyber events. For example, the NIST Cybersecurity Framework for Critical Infrastructure Cybersecurity identifies “Recover”, which includes the sub-categories of Recovery Planning, Improvements, and Communications, as one of its primary Functions. Additionally, numerous controls within NIST Special Publication 800-53 Revision 4 address elements of recovery controls and capabilities that agencies should address. OMB also published OMB M-07-16: Safeguarding Against and Responding to the Breach of Personally Identifiable Information, which provides guidance to agencies as to how they should protect against data breaches and respond and recover when one occurs. Despite the existence of available standards and guidance, there remains room for improvement. The CSIP initiates the following actions to help agencies rapidly recover from incidents when they occur and accelerate adoption of lessons learned from these events. a. The CSIP directs NIST to provide guidance to agencies by June 30, 2016, on how to recover from a cyber event, focusing on potential scenarios to include, but not limited to, a data breach or a destructive malware campaign. b. The CSIP directs OMB to update OMB M-07-16 by March 31, 2016, to reflect current best practices and recent lessons learned regarding privacy protections and data breach standards. This updated guidance regarding the collection and disposal of PII will help agencies ensure compliance with relevant laws and regulations for the protection of this sensitive information. c. To complement these efforts, the CSIP also directs OPM within 3 months to review options and develop and deliver to OMB recommendations for making Identity Protection Services a standard Federal employee benefit. Page 17 of 21

Select target paragraph3