The Office of Management and Budget is working on several policy directives around cybersecurity, including guidance on the 2014 update to the Federal Information Security Management Act (FISMA). But the agency is also looking to take a more active role in securing the nation’s networks.
More: 2014 FISMA reduces paperwork, codifies management structure
The newly established E-Government Cyber Unit — part of the Office of E-Government and Information Technology — was created to lead OMB’s cybersecurity initiatives.
President Obama’s 2016 budget proposal includes an additional $15 million (total $35 million) for OMB’s Information Technology Oversight and Reform (ITOR) to support the new cyber unit.
Deputy Federal CIO Lisa Schlosser said the new unit will focus on three core areas: encouraging data-driven, risk-based decisions, primarily using the CyberStat reporting program; issuing guidance on new legislation, as well as emerging technologies and threats; and coordinating agency response to cyber incidents and vulnerabilities.
While much of OMB and the new cyber unit’s mission is focused on more passive tasks — issuing policy guidance and reporting mandates — the unit will be more of an active participant in the last focus area, working directly with the Department of Homeland Security to assess agencies’ cybersecurity postures.
Homeland Security was tasked in October with scanning all civilian agency systems on a regular basis. That role was codified in December’s FISMA update but OMB plans to work closely with DHS on security reviews, Schlosser said.
More: New policy requires DHS to scan civilian systems
DHS is collecting data from agencies on a quarterly basis and, along with OMB, drilling down into specific agency issues as needed.
Currently, the agencies are doing a “deep dive” into about one department a month, Schlosser said, focusing on areas showing the highest risk.
“We go in with DHS and do thorough reviews of agency programs from top to bottom — everything from the people they have staffing their program to the processes they have in place to the technology and architecture,” she explained. From there, the cyber unit “works with DHS to come up with action plans where we see gaps in their protection strategy.”
For now, these deep dives are limited to agencies that show “a lot of potential problems or gaps in the way they’re executing and putting in place their programs and solutions,” Schlosser said, though she declined to name which agencies made that list.
As the government’s cybersecurity posture evolves, Schlosser said she will be following the development of three cybersecurity initiatives particularly closely over the next year:
- Continuous Diagnostics and Mitigation (CDM), which will give each agency a real-time view of its networks and vulnerabilities;
- Multifactor identification, specifically with common access cards (CAC) and personal identity verification (PIV) cards; and
- The Federal Risk and Authorization Management Program (FedRAMP), which certifies security levels for third-party cloud service providers.




