i. To facilitate this process, OMB will establish a requirement in the Fiscal Year
2015-2016 Guidance on Federal Information Security and Privacy Management
Requirements 5 for civilian agencies to identify and submit their list of HVAs to
DHS for assessment.
ii. Agency leadership will direct their respective CIOs to engage and collaborate
with DHS during these HVA assessments.
iii. To identify HVAs containing PII, the Senior Agency Official for Privacy for each
agency shall initiate a review of their information technology systems that
maintain PII. The Senior Agency Official for Privacy shall evaluate the
sensitivity and quantity of the PII and recommend to the CIO and agency head, as
appropriate, whether a specific system or systems should be added to the agency’s
list of HVAs.
iv. In addition, for each HVA and information technology asset identified, the Senior
Agency Official for Privacy shall review the processes for protecting PII on the
systems and ensure that the applicable Privacy Act systems of records notice(s)
and privacy impact assessment(s) that covers a given HVA or information
technology asset is current, accurately addresses risks to PII, and includes any
steps taken to mitigate those risks.
b. Per OMB M-14-03, Enhancing the Security of Federal Information and Information
Systems and OMB M-15-01, Fiscal Year 2014-2015 Guidance on Improving Federal
Information Security and Privacy Management Practices, Federal agencies must
accelerate the implementation of capabilities and tools to identify risks to their systems
and networks, to include, but not limited to, DHS’s CDM program. CDM addresses parts
of each stated objective of the CSIP, and its implementation is fundamental to helping
agencies develop a better understanding of the risks to their IT systems and networks
through improved identification and detection of cyber threats. Through CDM Phase 1,
DHS is deploying sensors and tools at agencies that will provide a more accurate picture
of: 1) the inventory of hardware and software assets under management, and 2) the
ongoing security posture of each of those assets. DHS purchased CDM Phase 1 tools and
integration services for all participating agencies in FY 2015. Implementation of these
tools will result in coverage for all Chief Financial Officer (CFO) Act agencies and over
97% of the Federal Civilian Government.
c. During the Cybersecurity Sprint, DHS identified the need to accelerate CDM
implementation throughout Federal agencies and has since developed a plan to accelerate
the deployment of CDM Phase 2. In the first quarter of FY 2016, DHS has begun
purchasing tools to provide Phase 2 capabilities for participating agencies. This
capability will help ensure all employees and contractors at covered agencies are using
appropriately secure methods to access Federal systems. DHS is scheduled to provide
Federal agencies with additional Phase 2 capabilities throughout FY 2016, with the full
suite of CDM Phase 2 capabilities delivered by the end of FY 2016.
5
This guidance will be issued concurrent with the CSIP. The guidance is referred to as the “FY 2016 FISMA
Guidance” hereafter in this document.
Page 9 of 21