<?xml version="1.0" encoding="UTF-8"?>
<PerformancePlanOrReport xmlns="urn:ISO:std:iso:17469:tech:xsd:PerformancePlanOrReport" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"

 xsi:schemaLocation="urn:ISO:std:iso:17469:tech:xsd:PerformancePlanOrReport http://stratml.us/references/PerformancePlanOrReport20160216.xsd" Type="Strategic_Plan"><Name>Trusted Internet Connections 3.0 -- Vol. 3: Security Capabilities Handbook</Name><Description>The Security Capabilities Handbook provides a list of deployable security controls, security capabilities,
and best practices. The handbook is intended to guide secure implementation and satisfy program
requirements within discrete networking environments. The Security Capabilities Handbook offers
actionable guidance for employing the principles articulated in the TIC 3.0 Program Guidebook, as well
as the secure architecture and components outlined in the TIC 3.0 Reference Architecture. Additionally,
the capabilities included in this document can be aligned with service provider overlays to enable
deployment of existing and future TIC Use Cases.</Description><OtherInformation>Universal Security Capabilities -- Universal capabilities are enterprise-level capabilities that outline guiding principles for TIC Use Cases
and apply across use cases. Agencies have the discretion to determine the level of rigor necessary for
applying universal capabilities based on federal guidelines and risk tolerance. The table below provides:
(1) a list of the universal security capabilities, (2) a description of each capability, and (3) a mapping of
each capability to relevant NIST Cybersecurity Framework (CSF) categories. While universal capabilities
are broadly applicable, certain use cases may provide unique guidance on specific capabilities where
necessary.  [In this StratML rendition, the universal capabilities are documented as objectives under the broader goals.]</OtherInformation><StrategicPlanCore><Organization><Name>Cybersecurity and Infrastructure Security Agency</Name><Acronym>CISA</Acronym><Identifier>_b6ee542c-9a4e-11ea-824e-10e01783ea00</Identifier><Description>Cybersecurity Division</Description><Stakeholder><Name/><Description/></Stakeholder></Organization><Vision><Description/><Identifier>_b6ee5580-9a4e-11ea-824e-10e01783ea00</Identifier></Vision><Mission><Description>To provide a list of deployable security controls, security capabilities, and best practices. </Description><Identifier>_b6ee565c-9a4e-11ea-824e-10e01783ea00</Identifier></Mission><Value><Name>Connection</Name><Description/></Value><Value><Name>Security</Name><Description/></Value><Value><Name>Agility</Name><Description>The Security Capabilities Handbook is intended to keep pace with the evolution of policy and technology.</Description></Value><Value><Name>Responsiveness</Name><Description>Consequently, this document will be updated periodically to assess existing TIC capabilities against changes in business mission needs, market trends, and the threat landscape. </Description></Value><Goal><Name>Traffic</Name><Description>Manage Traffic</Description><Identifier>_b6ee577e-9a4e-11ea-824e-10e01783ea00</Identifier><SequenceIndicator>1</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Observe, validate, and filter data connections to align with authorized activities; least privilege and default deny</OtherInformation><Objective><Name>Configuration</Name><Description>Implement a formal plan for
documenting, and managing changes to
the environment, and monitoring for
deviations.</Description><Identifier>_b6ee5846-9a4e-11ea-824e-10e01783ea00</Identifier><SequenceIndicator>1.1</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Configuration Management</OtherInformation></Objective><Objective><Name>Inventory</Name><Description>Develop, document, and
maintain a current inventory of all
systems, networks, and components so
that only authorized devices are given
access, and unauthorized and unmanaged
devices are found and prevented from
gaining access.</Description><Identifier>_0b48c46a-9aba-11ea-96ad-8e802d83ea00</Identifier><SequenceIndicator>1.2</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Privilege</Name><Description>Design the security architecture such
that each entity is granted the minimum
system resources and authorizations that
the entity needs to perform its function.
</Description><Identifier>_0b48c636-9aba-11ea-96ad-8e802d83ea00</Identifier><SequenceIndicator>1.3</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Least Privilege</OtherInformation></Objective><Objective><Name>Synchronization </Name><Description>Coordinate clocks on all systems (e.g.
servers, workstations, network devices) to
enable accurate comparison of timestamps
between systems.</Description><Identifier>_0b48c730-9aba-11ea-96ad-8e802d83ea00</Identifier><SequenceIndicator>1.4</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Time Synchronization </OtherInformation></Objective><Objective><Name>Parity</Name><Description>Consistently apply security protections
and other policies, independent of the
conveyance mechanism used.</Description><Identifier>_0b48c816-9aba-11ea-96ad-8e802d83ea00</Identifier><SequenceIndicator>1.5</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Policy Enforcement Parity</OtherInformation></Objective><Objective><Name>Integration</Name><Description>Defining polices such that they apply to a
given agency entity no matter its location.</Description><Identifier>_0b48c8fc-9aba-11ea-96ad-8e802d83ea00</Identifier><SequenceIndicator>1.6</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Integrated Desktop, Mobile, and Remote Policies</OtherInformation></Objective></Goal><Goal><Name>Confidentiality</Name><Description>Protect Traffic Confidentiality</Description><Identifier>_583d46f6-9aa6-11ea-8379-9d1b2983ea00</Identifier><SequenceIndicator>2</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Ensure only authorized parties can discern the contents of data in transit;
sender and receiver identification and enforcement</OtherInformation><Objective><Name>Authentication</Name><Description>Verify the identity of users, devices or
other entities through rigorous means (e.g.
multi-factor authentication) before
granting access.</Description><Identifier>_583d47fa-9aa6-11ea-8379-9d1b2983ea00</Identifier><SequenceIndicator>2.1</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Strong Authentication</OtherInformation></Objective></Goal><Goal><Name>Integrity</Name><Description>Protect Traffic Integrity</Description><Identifier>_583d489a-9aa6-11ea-8379-9d1b2983ea00</Identifier><SequenceIndicator>3</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Prevent alteration of data in transit; detect altered data in transit</OtherInformation><Objective><Name>Administration</Name><Description>Perform administrative tasks in a
secure manner, using secure protocols.</Description><Identifier>_583d49da-9aa6-11ea-8379-9d1b2983ea00</Identifier><SequenceIndicator>3.1</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Secure Administration</OtherInformation></Objective><Objective><Name>Vulnerability</Name><Description>Proactively work to discover
vulnerabilities, including the use of both
active and passive means of discovery,
and taking action to mitigate discovered
vulnerabilities.</Description><Identifier>_0b48c9e2-9aba-11ea-96ad-8e802d83ea00</Identifier><SequenceIndicator>3.2</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Vulnerability Assessment</OtherInformation></Objective><Objective><Name>Auditing &amp; Accounting</Name><Description>Capture business records, including
logs and other telemetry, and making
them available for auditing and
accounting as required.</Description><Identifier>_0b48caf0-9aba-11ea-96ad-8e802d83ea00</Identifier><SequenceIndicator>3.3</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Situational Awareness</Name><Description>Maintain effective awareness, both
current and historical, across all
components.</Description><Identifier>_0b48cbe0-9aba-11ea-96ad-8e802d83ea00</Identifier><SequenceIndicator>3.4</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective></Goal><Goal><Name>Resiliency</Name><Description>Ensure Service Resiliency</Description><Identifier>_583d4ab6-9aa6-11ea-8379-9d1b2983ea00</Identifier><SequenceIndicator>4</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Promote resilient application and security services for continuous operation
as the technology and threat landscape evolve</OtherInformation><Objective><Name>Performance</Name><Description>Ensure that systems, services, and
protections maintain acceptable
performance under adverse conditions</Description><Identifier>_583d4b42-9aa6-11ea-8379-9d1b2983ea00</Identifier><SequenceIndicator>4.1</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Resilience</OtherInformation></Objective><Objective><Name>Threats</Name><Description>Obtain threat intelligence from private
and government sources, and
implementing mitigations for the
identified risks.</Description><Identifier>_0b48ccbc-9aba-11ea-96ad-8e802d83ea00</Identifier><SequenceIndicator>4.2</SequenceIndicator><Stakeholder StakeholderTypeType="Generic_Group"><Name>Private Sources</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>Government Sources</Name><Description/></Stakeholder><OtherInformation>Enterprise Threat Intelligence</OtherInformation></Objective><Objective><Name>Shared Services</Name><Description>Employ shared services, where
applicable, that can be individually
tailored, measured to independently
validate service conformance, and offer
effective protections for tenants against
malicious actors, both external as well as
internal to the service provider.</Description><Identifier>_0b48cdac-9aba-11ea-96ad-8e802d83ea00</Identifier><SequenceIndicator>4.3</SequenceIndicator><Stakeholder StakeholderTypeType="Generic_Group"><Name/><Description/></Stakeholder><OtherInformation>Effective Use of Shared Services</OtherInformation></Objective></Goal><Goal><Name>Response</Name><Description>Ensure Effective Response</Description><Identifier>_583d4bd8-9aa6-11ea-8379-9d1b2983ea00</Identifier><SequenceIndicator>5</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Promote timely reaction and adapt future response to discovered threats;
policies defined and implemented; simplified adoption of new
countermeasures</OtherInformation><Objective><Name>Backup &amp; Recovery</Name><Description>Keep copies of configuration and data,
as needed, to allow for the quick
restoration of service in the event of
malicious incidents, system failures or
corruption.</Description><Identifier>_583d4c64-9aa6-11ea-8379-9d1b2983ea00</Identifier><SequenceIndicator>5.1</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Logs</Name><Description>Store telemetry needed to discover and
respond to malicious activity in a manner
that facilitates security analysis and data
fusion.</Description><Identifier>_0b48ce92-9aba-11ea-96ad-8e802d83ea00</Identifier><SequenceIndicator>5.2</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Central Log Management with Analysis</OtherInformation></Objective><Objective><Name>Incidents</Name><Description>Document and implement a set of
instructions or procedures to detect,
respond to, limit consequences of
malicious cyberattacks, and restore the
integrity of the network and systems.</Description><Identifier>_0b48cf82-9aba-11ea-96ad-8e802d83ea00</Identifier><SequenceIndicator>5.3</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Incident Response Plan and Incident Handling</OtherInformation></Objective><Objective><Name>Discovery</Name><Description>Use dynamic approaches (e.g.
heuristics, baselining, etc.) to discover
new malicious activity.</Description><Identifier>_0b48d086-9aba-11ea-96ad-8e802d83ea00</Identifier><SequenceIndicator>5.4</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Dynamic Threat Discovery</OtherInformation></Objective></Goal></StrategicPlanCore><AdministrativeInformation><StartDate>2019-12-31</StartDate><EndDate>2020-01-31</EndDate><PublicationDate>2020-05-20</PublicationDate><Source>https://www.cisa.gov/sites/default/files/publications/Draft%20TIC%203.0%20Vol.%203%20Security%20Capabilities%20Handbook.pdf</Source><Submitter><GivenName>Owen</GivenName><Surname>Ambur</Surname><PhoneNumber/><EmailAddress>Owen.Ambur@verizon.net</EmailAddress></Submitter></AdministrativeInformation></PerformancePlanOrReport>