to-hire and by ensuring cybersecurity job announcements contain clear, technical content. DHS must also post their own internal Cyber Workforce Analysis results on the CIO Council Knowledge Portal by November 30, 2015, as a best practice for other agencies to leverage. c. The CSIP directs OPM, DHS, and OMB, in coordination with NIST and other NICE partner agencies, to map the entire cyber workforce landscape across all agencies using the NICE National Cybersecurity Workforce Framework and identify cyber talent gaps and recommendations for closing them within 6 months. The mapping exercise and recommendation report should focus on: i. Existing employees and open positions, starting with the civilian agencies, this assessment should also consider contractor resources. ii. Existing resources and open positions within the DoD and the IC, this assessment should also consider contractor resources. iii. Changes to human resources processes and systems that not only incorporate best practices for retaining and incentivizing employees, but simplify and expedite the hiring process. iv. Capacity building actions to assist human resource professionals in their efforts to implement CSIP recommendations. v. Training and professional development opportunities for the existing workforce in order to address critical needs. vi. Leveraging the National Science Foundation CyberCorps® Scholarship for Service and the Advanced Technological Education program to help inform potential educational programs to help develop a pipeline of students from colleges, universities, and other providers. vii. Driving awareness of cybersecurity internship opportunities and programs that establish the possibility of hiring participants into permanent positions. viii. Creating and deploying “Tiger Teams” comprised of subject matter experts from across the Government to address critical workforce needs. d. The CSIP also directs OPM, DHS, and OMB, in coordination with NIST and other NICE partner agencies, to develop recommendations for Federal workforce training and professional development in functional areas outside of cybersecurity and information technology that support cybersecurity efforts within 6 months. These recommendations should address, at a minimum, the following functional areas: legal counsel, budget, procurement, privacy, and civil rights and liberties. Page 19 of 21

Select target paragraph3