I.
Objective 1: Prioritized Identification and Protection of High Value Information and
Assets
Identify
To protect Federal Government information and assets, agencies must first identify the value
and impact of the information on their systems and networks. Agencies must also identify
the IT assets used to store, process, and transmit that information. Further, agencies must
identify those assets and capabilities that enable mission essential functions and ensure
delivery of critical services to the public.
Accordingly, OMB directed agencies to initiate processes to identify their High Value Assets
(HVAs) at the beginning of the Cybersecurity Sprint. Agencies were to review and improve
the security practices and controls around their HVAs. To assist agencies with this process,
the Sprint Team developed a working definition of “high value asset” 3 and a list of attributes
to consider when determining whether an asset, dataset, or repository is of high value.
Federal Information Processing Standard (FIPS) 199, Standards for Security Categorization
of Federal Information and Information Systems, also provides relevant guidance and
requires Federal agencies to categorize their information and information systems to
determine the worst-case adverse impact to operations and assets, individuals, other
organizations, and the Nation if their information or systems are compromised. 4 The effort
to identify HVAs builds on FIPS 199 and seeks to implement lessons learned from cyber
incidents involving personally identifiable information (PII), by asking agencies’ to give
special consideration to the capability, intent, and specific targeting of high value data
repositories by potential or actual adversaries.
Going forward, OMB is directing the following actions to prioritize the identification and
protection of high value information and assets:
a. The Director of National Intelligence (DNI) will identify the appropriate interagency
resources to lead a threat assessment of Federal HVAs that are at high-risk of targeting by
adversaries by December 31, 2015. DHS will simultaneously lead a team, augmented by
DoD, the Intelligence Community (IC), and other agency resources as needed, to
continuously diagnose and mitigate the cybersecurity protections around the HVAs
identified during the Cybersecurity Sprint. The DHS-led team will continue to conduct
proactive assessments on a rolling basis as the IC, law enforcement, and other Federal
entities identify new threats. DHS and DNI will share the results of these assessments
with the agencies, as necessary.
3
“High Value Assets” refer to those assets, systems, facilities, data and datasets that are of particular interest to
potential adversaries. These assets, systems, and datasets may contain sensitive controls, instructions or data used in
critical Federal operations, or house unique collections of data (by size or content) making them of particular interest
to criminal, politically-motivated, or state-sponsored actors for either direct exploitation of the data or to cause a loss
of confidence in the U.S. Government.
4
FIPS Publication 199 defines three levels of potential impact (i.e., low, moderate, and high) on organizations or
individuals should there be a breach of security (i.e., a loss of confidentiality, integrity, or availability).
Page 8 of 21