The CSIP emphasizes the need for a defense in depth 1 approach that relies on the layering of people, processes, technologies, and operations to achieve more secure Federal information systems. Inherent in a defense in depth approach is the recognition that all protection mechanisms have weaknesses that adversaries may exploit through several paths. Implementing the CSIP will not prevent every cyber incident. In fact, it is likely that agencies will discover additional and previously unknown malicious activity as they improve prevention and detection capabilities. Accordingly, the CSIP incorporates procedures to prepare agencies to respond to and recover from incidents, secure Federal information and assets, and ultimately strengthen their overall security posture. The CSIP incorporates feedback from public and private sector subject-matter experts as well as lessons learned from current cyber incident response and recovery efforts affecting the Federal Government. The CSIP builds on existing policy work, including the Comprehensive National Cybersecurity Initiative (CNCI); Presidential Policy Directives; Executive Orders; legislation such as FISMA; OMB guidance; agency performance and incident data; and Federal Continuity Directives. The CSIP emphasizes the government-wide adherence to NIST standards and guidelines and builds on the core concepts of the Framework for Improving Critical Infrastructure Cybersecurity, which NIST developed in accordance with Executive Order 13636, Improving Critical Infrastructure Cybersecurity. Oversight Responsibility for Federal Government cybersecurity is distributed and shared by all agencies; however, specific agencies have additional roles in supporting this mission and ensuring that the Federal Government has the tools, resources, and guidance necessary to make the risk-based decisions necessary to secure their systems. FISMA states that OMB oversees Federal agency information security policies and practices. The OMB Cyber and National Security Unit (OMB Cyber) was created at the beginning of FY 2015 2 to strengthen Federal cybersecurity through: 1) Data-driven, risk-based oversight of agency and government-wide cybersecurity programs; 2) Issuance and implementation of Federal policies to address emerging IT security risks; and 3) Oversight of the government-wide response to major incidents and vulnerabilities to reduce their impact on the Federal Government. Progress on CSIP implementation will be tracked through several mechanisms, to include the PMC, comprehensive reviews of agency-specific cybersecurity posture (CyberStats), the CIO Council and the ISIMC. The quarterly performance reviews will be used to identify major performance and policy gaps, which will be addressed through regular engagement with agency leadership and future FISMA guidance. Additionally, OMB and NSC will work within the 1 NIST Special Publication 800-53, Security and Privacy Controls for Federal Information Systems and Organizations, defines defense in depth as: “information security strategy integrating people, technology, and operations capabilities to establish variable barriers across multiple layers and missions of the organization.” 2 OMB launched this dedicated unit within the Office of E-Government & Information Technology, also referred to as the Office of the Federal Chief Information Officer, in the Fiscal Year 2014 Federal Information Security Management Act Report to Congress. Page 6 of 21

Select target paragraph3