organization, but for understanding the broader landscape of cyber risk. DHS analyzes
cybersecurity information from sensors deployed across the Federal Government and
from incidents reported by Federal agencies and the private sector. With this
information, DHS is able to identify when adversaries appear to be targeting particular
sectors or types of organizations and share the information proactively, helping agencies
understand emerging risks and develop effective protective measures to block threats
before incidents occur.
i. One primary barrier to effective information sharing is a lack of operational
speed. Information sharing must be sufficiently rapid to detect and block threats
before targeted networks are adversely impacted. The DHS National
Cybersecurity and Communications Integration Center (NCCIC) has developed
an automated system to share cyber threat indicators in near real-time and is
working aggressively to build this capability across government and out to the
private sector. The CSIP directs all CFO Act agencies to work with DHS to
implement automated indicator sharing by developing their own capability,
procuring commercially available solutions, or participating in a shared service,
once available, within 12 months.
d. Beginning in FY 2016, GSA will develop a Business Due Diligence Information Service
that will provide agencies with a common government-wide capability for identifying,
assessing, and managing cyber and supply chain risk throughout the acquisition process.
Respond
The Sprint Team identified several common challenges during the Cybersecurity Sprint and
determined that Federal Civilian Government cyber incident response procedures and practices
are not consistently documented or implemented. As instances of cyber incidents simultaneously
affecting multiple Federal agencies are likely to increase, the Federal Government requires
streamlined response efforts and enhanced procedures for communication and coordination. The
CSIP aims to address these challenges through the creation of incident response best practices for
Federal civilian agencies. This new guidance will help set expectations across all involved
parties and ensure consistency across incident response efforts while remaining flexible enough
to guide activities under various conditions and situations.
The CSIP addresses this challenge by initiating the following actions:
a. OMB, in coordination with NSC and DHS, will provide Federal civilian agencies with
incident response best practices along with the FY 2016 FISMA Guidance, which will be
issued concurrent with the CSIP, to provide a reference guide for responding to major
incidents 11 affecting Federal civilian agencies. The best practices will address several
common challenges identified during the Sprint by formalizing the role of an on-scene
coordinator, assigning incident response work streams, and establishing entry and exit
criteria for the response phase. Furthermore, the best practices will clarify existing
requirements for agencies to notify US-CERT, Congress, and victims of a cyber incident;
11
For a definition of major incidents, please see the FISMA FY 2016 Guidance.
Page 15 of 21