 2.4.1 Publish a Notice of Proposed Rulemaking on requirements, standards, and procedures for Infrastructure-as-a-Service providers and resellers 2.5.1 Develop an action plan to disincentivize safe havens for ransomware criminals 2.5.2 Increase the speed and scale of operations to disrupt ransomware crimes 2.5.3 Improve investigation of ransomware crimes 3.2.1 Publish a Notice of Proposed Rulemaking to change the Federal Acquisition Regulation in line with the Internet of Things Cybersecurity Improvement Act of 2020 3.2.2 Initiate a U.S. Government Internet of Things security labeling program 3.3.1 Explore approaches to develop a long-term, flexible, and enduring software liability framework 3.4.1 Develop guidance for Federal agencies and grantees to better leverage Federal grants to improve infrastructure cybersecurity 3.4.2 Include cybersecurity as a priority for research funding 3.5.1* Publish a Notice of Proposed Rulemaking to change the Federal Acquisition Regulation to incorporate new requirements outlined in Executive Order 14028 3.6.1 Assess the need for a Federal insurance response to a catastrophic cyber event 4.1.1 Lead the adoption of network security best practices 4.1.2 Promote open-source software security and the adoption of memory safe programming languages 4.1.3 Reinvigorate interagency coordination on international cybersecurity standards 4.2.1 Publish an updated cybersecurity research and development strategy 4.4.1 Drive adoption of cyber secure-by-design principles by incorporating them into Federal projects 4.4.2 Develop a plan to ensure the digital ecosystem can support and deliver the U.S. Government’s decarbonization goals 4.6.1 Publish a National Cyber Workforce and Education Strategy and track its implementation 5.1.2 Publish an International Cyberspace and Digital Policy Strategy 5.2.1 Improve interagency coordination to strengthen international partners' cyber capacity 5.3.1 Establish flexible foreign assistance mechanisms to provide cyber incident response support quickly 5.5.1 Promote the development of secure and trustworthy information and communication technology (ICT) networks and services 5.5.2 Promote a more diverse and resilient supply chain of ICT vendors 5.5.3 Begin administering the Public Wireless Supply Chain Innovation Fund 6.1.2 Apply lessons learned to the National Cybersecurity Strategy implementation 6.1.3 Publish budgetary guidance aligned with National Cybersecurity Strategy implementation * indicates initiatives in-progress as of date of publication 2024 REPORT ON THE CYBERSECURITY OF THE UNITED STATES Commerce State FBI Justice OMB NSC ONCD ONCD OSTP OMB Treasury OMB ONCD NIST OSTP Energy ONCD ONCD State State State State State Commerce ONCD ONCD POSTURE 9

Select target paragraph3