i. To facilitate this process, OMB will establish a requirement in the Fiscal Year 2015-2016 Guidance on Federal Information Security and Privacy Management Requirements 5 for civilian agencies to identify and submit their list of HVAs to DHS for assessment. ii. Agency leadership will direct their respective CIOs to engage and collaborate with DHS during these HVA assessments. iii. To identify HVAs containing PII, the Senior Agency Official for Privacy for each agency shall initiate a review of their information technology systems that maintain PII. The Senior Agency Official for Privacy shall evaluate the sensitivity and quantity of the PII and recommend to the CIO and agency head, as appropriate, whether a specific system or systems should be added to the agency’s list of HVAs. iv. In addition, for each HVA and information technology asset identified, the Senior Agency Official for Privacy shall review the processes for protecting PII on the systems and ensure that the applicable Privacy Act systems of records notice(s) and privacy impact assessment(s) that covers a given HVA or information technology asset is current, accurately addresses risks to PII, and includes any steps taken to mitigate those risks. b. Per OMB M-14-03, Enhancing the Security of Federal Information and Information Systems and OMB M-15-01, Fiscal Year 2014-2015 Guidance on Improving Federal Information Security and Privacy Management Practices, Federal agencies must accelerate the implementation of capabilities and tools to identify risks to their systems and networks, to include, but not limited to, DHS’s CDM program. CDM addresses parts of each stated objective of the CSIP, and its implementation is fundamental to helping agencies develop a better understanding of the risks to their IT systems and networks through improved identification and detection of cyber threats. Through CDM Phase 1, DHS is deploying sensors and tools at agencies that will provide a more accurate picture of: 1) the inventory of hardware and software assets under management, and 2) the ongoing security posture of each of those assets. DHS purchased CDM Phase 1 tools and integration services for all participating agencies in FY 2015. Implementation of these tools will result in coverage for all Chief Financial Officer (CFO) Act agencies and over 97% of the Federal Civilian Government. c. During the Cybersecurity Sprint, DHS identified the need to accelerate CDM implementation throughout Federal agencies and has since developed a plan to accelerate the deployment of CDM Phase 2. In the first quarter of FY 2016, DHS has begun purchasing tools to provide Phase 2 capabilities for participating agencies. This capability will help ensure all employees and contractors at covered agencies are using appropriately secure methods to access Federal systems. DHS is scheduled to provide Federal agencies with additional Phase 2 capabilities throughout FY 2016, with the full suite of CDM Phase 2 capabilities delivered by the end of FY 2016. 5 This guidance will be issued concurrent with the CSIP. The guidance is referred to as the “FY 2016 FISMA Guidance” hereafter in this document. Page 9 of 21

Select target paragraph3