ii. Consistent with DHS’s Binding Operational Directive 15-01, Critical Vulnerability Mitigation Requirements for Federal Civilian Executive Branch Departments’ and Agencies’ Internet-Accessible Systems, the CSIP directs agencies to patch all critical vulnerabilities immediately or, at a minimum, within 30 days of patch release. Vulnerabilities existing longer than 30 days will be included in agency PMC reports. d. NSC and OMB will release the EO 13681, Improving the Security of Consumer Financial Transactions Implementation Plan by December 31, 2015, to require implementation of strong authentication and effective identity proofing for government digital services that make personal data accessible to citizens online. e. Drawing on the work of the Sprint Team, OMB will release a plan for implementing new cybersecurity shared services within 3 months. These services will augment or supplement existing agency services, while providing new services for agencies without existing capabilities. Potential service offerings could include, but are not limited to: i. Identity, Authentication, and Authorization Services: x Agencies’ ability to further their mission and achieve efficiencies by placing high value services online requires them to be able to have confidence in the identities of users accessing these services. This set of shared identity services could enable agencies to access digital credentials based on effective identity proofing methodologies and user-friendly strong authentication technologies. In addition, agencies can obtain validated information to support authorization decisions so that appropriate users can access their resources or benefits. ii. Mobile Security Services: x Mobile devices have become as powerful and connected as desktop and laptop computers, requiring the same level of attention to cybersecurity. Mobile security has unique challenges that require different solutions than existing programs offer. This service (or services) could address authentication, application management, device management, and encryption, and may include approved tools, best practices, and implementation support. iii. Network Segmentation Services: x Effective network segmentation management requires consistent application of best practices to limit lateral movement across networks. This shared service could provide network segmentation shared service capabilities across the Federal Government to help ensure that agencies consistently apply best practices to this complex management task. If operationalized, all Federal organizations would be asked to provide recommendations to the network segmentation services management offering to guide the proper implementation of network segmentation within an organization. iv. Digital Rights Management: x A digital rights management (DRM) shared service capability could enable a systematic approach to data-level protection across the Federal Government Page 12 of 21

Select target paragraph3