2. Asset response activities include furnishing technical assistance to affected entities
to protect their assets, mitigate vulnerabilities, and reduce impacts of cyber
incidents; identifying other entities that may be at risk and assessing their risk to
the same or similar vulnerabilities; assessing potential risks to the sector or region,
including potential cascading effects, and developing courses of action to mitigate
these risks; facilitating information sharing and operational coordination with
threat response; and providing guidance on how best to utilize Federal resources
and capabilities in a timely, effective manner to speed recovery.
Threat and asset responders will share some responsibilities and activities, which
may include communicating with affected entities to understand the nature of the
cyber incident; providing guidance to affected entities on available Federal
resources and capabilities; promptly disseminating through appropriate channels
intelligence and information learned in the course of the response; and facilitating
information sharing and operational coordination with other Federal Government
entities.
3. Intelligence support and related activities facilitate the building of situational threat
awareness and sharing of related intelligence; the integrated analysis of threat
trends and events; the identification of knowledge gaps; and the ability to degrade
or mitigate adversary threat capabilities.
4. An affected Federal agency shall engage in a variety of efforts to manage the impact
of a cyber incident, which may include maintaining business or operational
continuity; addressing adverse financial impacts; protection of privacy; managing
liability risks; complying with legal and regulatory requirements (including
disclosure and notification); engaging in communications with employees or other
affected individuals; and dealing with external affairs (e.g., media and congressional
inquiries). The affected Federal agency will have primary responsibility for this line
of effort.
When a cyber incident affects a private entity, the Federal Government typically will
not play a role in this line of effort, but it will remain cognizant of the affected
entity’s response activities, consistent with the principles above and in coordination
with the affected entity. The relevant sector-specific agency (SSA) will generally
coordinate the Federal Government’s efforts to understand the potential business or
operational impact of a cyber incident on private sector critical infrastructure.
V. Architecture of Federal Government Response Coordination for
Significant Cyber Incidents1
In order to respond effectively to significant cyber incidents, the Federal Government will
coordinate its activities in three ways:
4/8