Defending Federal systems at speed and scale requires the government to advance an enterpriselevel view of risk across departments and agencies. Through the adoption of shared services,
agencies have bolstered their capabilities, reduced their attack surfaces, and improved visibility
across Federal networks. In October 2023, OMB and ONCD convened an interagency working
group that explored the deployment and use of cybersecurity shared services across the Federal
Government, interviewed providers and customers, and identified gaps and challenges in getting
shared services to small and micro agencies.
CISA has equipped agencies with greater capabilities to identify, prioritize, and mitigate
cybersecurity risks while enabling them to understand and manage critical threats through its
Continuous Diagnostics and Mitigation (CDM) program, which is aligned to government-wide
documents such as the Known Exploited Vulnerabilities catalog. In 2023, CISA helped enable
the shift toward shared services by expanding its CDM program to all 23 civilian CFO Act
agencies and 69 non-CFO Act agencies, and by onboarding 97 agencies onto their Protective
Domain Name System service.
CISA, OMB, and ONCD have engaged with industry to determine the feasibility of providing
enhanced logging capabilities to Federal civilian executive branch agencies. In February 2024,
these engagements resulted in the rollout of expanded logs to all agencies and the extension of
the default log retention period from 90 to 180 days. This major step forward is in line with
CISA’s Secure by Design guidance, which calls for technology providers to furnish “highquality audit logs to customers at no extra charge.”
The Director of NSA, as the National Manager for NSS, continues to enhance cyber coordination
and alignment across over 70 Federal departments and agencies through greater centralized
accountability, alignment of policy processes, and formalization of standards for NSS across
Federal owners and operators.
ONCD, in collaboration with interagency partners, developed a plan to drive improvements in
Internet routing security, focusing on addressing vulnerabilities in the BGP. These
vulnerabilities can be addressed by solutions such as Resource Public Key Infrastructure Route
Origin Authorizations (RPKI ROA). The Federal Government has developed a Legacy
Registration Services Agreement template for Federal agency use, and is developing a playbook
to facilitate adoption of RPKI ROA. This solution removes a significant barrier to adoption and
will facilitate government-wide implementation of RPKI ROA.
Efforts are also underway to improve collective operational defense so that breaches are isolated
and remediated rapidly. CISA’s Persistent Access Capability, made possible through the widely
adopted EDR initiative born out of Executive Order 14028, facilitates real-time threat
intelligence sharing. The Federal Government's deliberate shift toward ZTA, the expansion of
shared services, and the maturation of collective operational defense reflects a concerted effort to
address the current cyber threat landscape and prepare for future challenges.
2024 REPORT
18
ON THE CYBERSECURITY
OF THE UNITED STATES
POSTURE