4. Unity of Governmental Effort. Various government entities possess different
roles, responsibilities, authorities, and capabilities that can all be brought to bear on
cyber incidents. These efforts must be coordinated to achieve optimal results.
Whichever Federal agency first becomes aware of a cyber incident will rapidly notify
other relevant Federal agencies in order to facilitate a unified Federal response and
ensure that the right combination of agencies responds to a particular incident.
State, local, tribal, and territorial (SLTT) governments also have responsibilities,
authorities, capabilities, and resources that can be used to respond to a cyber
incident; therefore, the Federal Government must be prepared to partner with SLTT
governments in its cyber incident response efforts. The transnational nature of the
Internet and communications infrastructure requires the United States to
coordinate with international partners, as appropriate, in managing cyber incidents.
5. Enabling Restoration and Recovery. Federal response activities will be
conducted in a manner to facilitate restoration and recovery of an entity that has
experienced a cyber incident, balancing investigative and national security
requirements, public health and safety, and the need to return to normal operations
as quickly as possible.
IV. Concurrent Lines of Effort
In responding to any cyber incident, Federal agencies shall undertake three concurrent
lines of effort: threat response; asset response; and intelligence support and related
activities. In addition, when a Federal agency is an affected entity, it shall undertake a
fourth concurrent line of effort to manage the effects of the cyber incident on its
operations, customers, and workforce.
1. Threat response activities include conducting appropriate law enforcement and
national security investigative activity at the affected entity’s site; collecting
evidence and gathering intelligence; providing attribution; linking related incidents;
identifying additional affected entities; identifying threat pursuit and disruption
opportunities; developing and executing courses of action to mitigate the immediate
threat; and facilitating information sharing and operational coordination with asset
response.
3/8