On high value assets (HVA) and high impact systems in U.S. federal infosec
and not the post-quantum cryptography migration context they relate to
After POTUS issued the Executive Order Securing the Nation Against Advanced Cryptographic Attacks on June 22, I wanted to write a post to correct some misunderstandings that I read online, but Cloudflare beat me to it:
Still, having worked on critical assets definition and governance (the harder part), the notions of HVA and high impact system—which I wasn’t familiar with—piqued my interest. That’s what this post is about.
Disclaimers: I’m not an expert, this post is only the result of my research and reading that I’m sharing for anyone interested. Let me know what I missed or got wrong.
Context and scope
HVA and high impact system are not mutually exclusive. A system can qualify as both, as one of the two, or neither. Whereas a high impact system is… an information system (storing or processing information), and HVA can either be such a system or the information itself.
HVA and high impact system can in principle apply to both classified and unclassified systems. They are (mostly) applied to civilian, non-military, non-National Security agencies, and systems thereof—for example, about HVAs, OMB’s M-19-03 writes “agencies are only required to report their non-national security HVAs to DHS.”
High impact system
A high impact system is exactly what it says it is, as the EO defines:
The notion of high impact system is not new. You’ll find the term (also, and more correctly, spelled “high-impact system”) in other Federal government documents.
“High impact” refers to the impact defined in the FIPS 199 categorization (which doesn't apply to classified and NSS systems):
Doing more genealogical research, FIPS 199 (issued in 2004) can be traced back to FISMA 2002, the text signed into law by George W. Bush in December 2002, which tasked NIST with developing federal security standards and guidelines.
High value asset (HVA)
HVA is a less straightforward and more interesting notion than HIS. It's not unrelated to FISMA 2014, the update and modernization of its 2002 ancestor, through three iterations of OMB publications:
In October 2015, following FISMA 2014 (more precisely, its “Cybersecurity Sprint”), M-16-03 (where the M means memorandum) instructs agencies to “Immediately identify agency specific High Value Assets (HVAs) and assess the security protections around those HVAs,” without giving a clear definition of an HVA.
In December 2016, M-17-09 defines an HVA as follows:
Note that, as I wrote in introduction, an HVA can be a system (such as a web application) or data (like “list of users from agency XYZ”).
M-17-09 also gives guidelines for planning, identification, categorization, prioritization, remediation, and reporting of HVAs.
Like information classification level, this definition is mostly relative to the impact of a compromise, rather than to the nature of the system/data.
You’ll see that those memoranda are quite high-level, specifying the what rather than the how. That’s where DHS and CISA (created in 2018) come into play, via their binding operational directives (a BOD is “a compulsory direction to federal, executive branch, departments and agencies for purposes of safeguarding federal information and information systems.”). After the now-revoked BOD 16-01, the authoritative document is BOD 18-02: Securing High Value Assets. It’s a short piece that describes agencies’ responsibilities vis-à-vis DHS, such as submitting a point of contact to DHS and participating in DHS-led assessments (CISA is under DHS.)
In December 2018, M-19-03 (superseding M-17-09) providers further guidance on the HVA program, notably relative to
governance, where the head of agency is accountable for designating their HVAs and internal responsible parties/teams.
“designation” (though I think “definition and scope” would be a better term), broadening the scope to consider
the value of the data/system for adversaries (relative to confidentiality),
the mission criticality of the data/system (generally more relative to integrity and availability).
M-19-03 also provides a more extensive breakdown of responsibilities between agencies, DHS (oversight, requirements definition, etc.), and GSA (mostly bureaucracy).
Each agency’s Inspector General (IG), or an external auditor selected by the IG, performs the annual independent FISMA evaluation, including HVAs'. management; some IGs also conduct HVA-specific audits.
For example, DHS’ IG found that… CISA didn’t manage its HVAs properly, for a selected HVA system:
Finally, the last related development I’ve found is CISA's June 2026 BOD 26-04: Implementation Guidance for Prioritizing Security Updates Based on Risk, which defines prioritization guidance:






