<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" href="stratmliso.xsl"?>
<StrategicPlan xmlns="urn:ISO:std:iso:17469:tech:xsd:stratml_core" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="urn:ISO:std:iso:17469:tech:xsd:stratml_core http://xml.govwebs.net/stratml/references/StrategicPlanISOVersion20140401.xsd"><Name>Cyber Information Sharing and Collaboration Program (CISCP)</Name><Description>Information shared via CISCP allows all participants to better secure their own networks and helps support the shared security of CISCP partners. Further, CISCP provides a collaborative environment where analysts learn from each other to better understand emerging cybersecurity risks and effective defenses. CISCP is based upon a community of trust in which all participants seek mutual benefit from robust information sharing and collaboration. CISCP is free of charge and provides value to all members. Therefore, all companies with an interest in multi-directional cybersecurity information sharing and robust analytic collaboration between the government and the private sector should consider joining CISCP.</Description><OtherInformation/><StrategicPlanCore><Organization><Name>National Cybersecurity and Communications Integration Center</Name><Acronym>NCCIC</Acronym><Identifier>_6651e044-bbca-11e6-a72d-d1d8f7e90587</Identifier><Description>The Department of Homeland Security's National Cybersecurity and Communications Integration Center (NCCIC) serves as the hub of information sharing activities for the Department to increase awareness of vulnerabilities, incidents, and mitigations.</Description><Stakeholder StakeholderTypeType="Organization"><Name>Department of Homeland Security</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>Cyber Information Sharing and Collaboration Program (CISCP)</Name><Description>Within the NCCIC, the Cyber Information Sharing and Collaboration Program (CISCP) is DHS's flagship program for public-private information sharing and complements ongoing DHS information sharing efforts.</Description></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>Companies</Name><Description>In CISCP, DHS and participating companies share information about cyber threats, incidents, and vulnerabilities.</Description></Stakeholder></Organization><Vision><Description>Networks are secure.</Description><Identifier>_6651e1ac-bbca-11e6-a72d-d1d8f7e90587</Identifier></Vision><Mission><Description>To share information about cyber threats, incidents, and vulnerabilities.</Description><Identifier>_6651e210-bbca-11e6-a72d-d1d8f7e90587</Identifier></Mission><Value><Name>Cybersecurity</Name><Description>Information sharing is a key pillar of effective cybersecurity.</Description></Value><Value><Name>Information Sharing</Name><Description/></Value><Value><Name>Speed</Name><Description>By sharing information rapidly between the government and the private sector, network defenders are able to block cyber threats before damaging compromises occur. </Description></Value><Value><Name>Empowerment</Name><Description>Information shared among CISCP partners is governed using the Traffic Light Protocol (TLP), which empowers the submitter to determine the handling and dissemination of their information. For more on TLP, visit http://us-cert.gov/tlp.</Description></Value><Value><Name>Information Protection</Name><Description>Protecting Shared Information and Privacy -- 

Data can be submitted to CISCP under Protected Critical Infrastructure Information (PCII) Program. Any PCII submissions are statutorily exempt from regulatory use or any disclosure under the Freedom of Information Act or state Sunshine Laws. However, PCII does not fulfill federal, state and local reporting requirements that may apply to specific organizations.</Description></Value><Value><Name>Privacy</Name><Description>DHS embeds privacy protections and provides transparency in all of its cyber activities. DHS uses the Fair Information Practice Principles (FIPPs) to assess and mitigate impacts on an individual's privacy. For more information, visit the DHS Cybersecurity and Privacy web page.</Description></Value><Value><Name>Transparency</Name><Description/></Value><Value><Name>Cooperation</Name><Description>To join CISCP, companies are required to sign a Cooperative Research and Development Agreement (CRADA). Along with governing participation in CISCP, a signed CRADA may permit access to the NCCIC watch floor and allows for company personnel to be eligible for security clearances to view classified threat information.</Description></Value><Goal><Name>Information Sharing</Name><Description>Share information bi-directionally.</Description><Identifier>_6651e29c-bbca-11e6-a72d-d1d8f7e90587</Identifier><SequenceIndicator>1</SequenceIndicator><Stakeholder StakeholderTypeType=""><Name/><Description/></Stakeholder><OtherInformation>A key aspect of CISCP is bi-directional information sharing: CISCP partners submit indicators of observed cyber threats and information about cyber incidents and identified vulnerabilities to DHS, which DHS then shares with other CISCP partners in an anonymized, aggregated fashion. Upon receiving a submission, CISCP analysts redact any personal or proprietary information and analyze the submission in collaboration with both government and industry partners to produce accurate, relevant, timely and actionable analytical products. Currently, those products take the form of:</OtherInformation><Objective><Name>Indicator Bulletins (IB)</Name><Description>Send short, timely bulletins regarding new threats and vulnerabilities. </Description><Identifier>_6651e33c-bbca-11e6-a72d-d1d8f7e90587</Identifier><SequenceIndicator>1.1</SequenceIndicator><Stakeholder StakeholderTypeType=""><Name/><Description/></Stakeholder><OtherInformation>These bulletins are sent several times a week in machine-readable formats. These formats enable faster parsing and analysis, resulting in faster action taken to thwart attacks and remediate vulnerabilities.</OtherInformation></Objective><Objective><Name>Analysis Report (AR)</Name><Description>Provide a more in-depth analytic product that ties together related threat and intruder activity, describing the activity, how to detect it, defensive measures and remediation advice.</Description><Identifier>_6651e3d2-bbca-11e6-a72d-d1d8f7e90587</Identifier><SequenceIndicator>1.2</SequenceIndicator><Stakeholder StakeholderTypeType=""><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Priority Alert (PA)</Name><Description>Provide early warning of a single specific threat or vulnerability expected to have significant and far-reaching impact.</Description><Identifier>_6651e468-bbca-11e6-a72d-d1d8f7e90587</Identifier><SequenceIndicator>1.3</SequenceIndicator><Stakeholder StakeholderTypeType=""><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Recommended Practices (RP)</Name><Description>Provide a method for collaboratively defining and documenting a series of "best practice" recommendations or strategies.</Description><Identifier>_6651e51c-bbca-11e6-a72d-d1d8f7e90587</Identifier><SequenceIndicator>1.4</SequenceIndicator><Stakeholder StakeholderTypeType=""><Name/><Description/></Stakeholder><OtherInformation/></Objective></Goal><Goal><Name>Events</Name><Description>Facilitate collaboration events with government and industry partners.</Description><Identifier>_6651e5c6-bbca-11e6-a72d-d1d8f7e90587</Identifier><SequenceIndicator>2</SequenceIndicator><Stakeholder StakeholderTypeType=""><Name/><Description/></Stakeholder><OtherInformation>As part of CISCP, DHS facilitates collaboration events with government and industry partners, which foster a trusted environment for sharing cyber threat information. These exchanges are unclassified and focus on current threats or recent activity. In addition, the team hosts analyst-to-analyst technical threat exchanges and analyst training events that allow for classified and unclassified briefings.</OtherInformation><Objective><Name>Threat Exchanges</Name><Description>Hosts analyst-to-analyst technical threat exchanges and analyst training events that allow for classified and unclassified briefings.</Description><Identifier>_6651e666-bbca-11e6-a72d-d1d8f7e90587</Identifier><SequenceIndicator>2.1</SequenceIndicator><Stakeholder StakeholderTypeType="Generic_Group"><Name>Network Security Analysts</Name><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Training Events</Name><Description>Host analyst training events that allow for classified and unclassified briefings.</Description><Identifier>_6651e710-bbca-11e6-a72d-d1d8f7e90587</Identifier><SequenceIndicator>2.2</SequenceIndicator><Stakeholder StakeholderTypeType="Generic_Group"><Name>Network Security Analysts</Name><Description/></Stakeholder><OtherInformation/></Objective></Goal></StrategicPlanCore><AdministrativeInformation><PublicationDate>2016-12-06</PublicationDate><Source>https://www.dhs.gov/ciscp</Source><Submitter><GivenName>Owen</GivenName><Surname>Ambur</Surname><PhoneNumber/><EmailAddress>Owen.Ambur@verizon.net</EmailAddress></Submitter></AdministrativeInformation></StrategicPlan>