I. Objective 1: Prioritized Identification and Protection of High Value Information and Assets Identify To protect Federal Government information and assets, agencies must first identify the value and impact of the information on their systems and networks. Agencies must also identify the IT assets used to store, process, and transmit that information. Further, agencies must identify those assets and capabilities that enable mission essential functions and ensure delivery of critical services to the public. Accordingly, OMB directed agencies to initiate processes to identify their High Value Assets (HVAs) at the beginning of the Cybersecurity Sprint. Agencies were to review and improve the security practices and controls around their HVAs. To assist agencies with this process, the Sprint Team developed a working definition of “high value asset” 3 and a list of attributes to consider when determining whether an asset, dataset, or repository is of high value. Federal Information Processing Standard (FIPS) 199, Standards for Security Categorization of Federal Information and Information Systems, also provides relevant guidance and requires Federal agencies to categorize their information and information systems to determine the worst-case adverse impact to operations and assets, individuals, other organizations, and the Nation if their information or systems are compromised. 4 The effort to identify HVAs builds on FIPS 199 and seeks to implement lessons learned from cyber incidents involving personally identifiable information (PII), by asking agencies’ to give special consideration to the capability, intent, and specific targeting of high value data repositories by potential or actual adversaries. Going forward, OMB is directing the following actions to prioritize the identification and protection of high value information and assets: a. The Director of National Intelligence (DNI) will identify the appropriate interagency resources to lead a threat assessment of Federal HVAs that are at high-risk of targeting by adversaries by December 31, 2015. DHS will simultaneously lead a team, augmented by DoD, the Intelligence Community (IC), and other agency resources as needed, to continuously diagnose and mitigate the cybersecurity protections around the HVAs identified during the Cybersecurity Sprint. The DHS-led team will continue to conduct proactive assessments on a rolling basis as the IC, law enforcement, and other Federal entities identify new threats. DHS and DNI will share the results of these assessments with the agencies, as necessary. 3 “High Value Assets” refer to those assets, systems, facilities, data and datasets that are of particular interest to potential adversaries. These assets, systems, and datasets may contain sensitive controls, instructions or data used in critical Federal operations, or house unique collections of data (by size or content) making them of particular interest to criminal, politically-motivated, or state-sponsored actors for either direct exploitation of the data or to cause a loss of confidence in the U.S. Government. 4 FIPS Publication 199 defines three levels of potential impact (i.e., low, moderate, and high) on organizations or individuals should there be a breach of security (i.e., a loss of confidentiality, integrity, or availability). Page 8 of 21

Select target paragraph3