 In July 2023, ONCD invited public responses to a Request for Information on opportunities for, and obstacles to, harmonizing baseline cybersecurity requirements for critical infrastructure and related assessments and audits. Respondents stressed the importance of leveraging existing frameworks and best practices, such as the National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF), to facilitate reciprocity, and recommended that ONCD work with the federal regulatory agencies to deconflict current and emerging cybersecurity requirements to drive harmonization. Requirements are most often effective when they align with existing cybersecurity frameworks, voluntary consensus standards, and other technical guidance. In March 2023, CISA updated its Cybersecurity Performance Goals (CPGs) based on stakeholder input and engaged SRMAs to begin to develop sector-specific goals through a phased approach. In February 2024, NIST published version 2.0 of its CSF, which provides updated guidance on managing an evolving cybersecurity risk landscape, implementation, and measuring effectiveness. In the energy sector, the Department of Energy (DOE) partnered with the National Association of Regulatory Utility Commissioners (NARUC) to develop cybersecurity baselines for electric distribution systems and distributed energy resources. In February 2024, NARUC and DOE publicly released the baselines and kicked off phase two to develop implementation strategies and adoption guidelines with state regulatory bodies and industry. Enhancing Federal Coordination and Partnerships The Federal Government is modernizing its critical infrastructure protection policies to ensure that Federal cyber capabilities are exercised in a clear, coordinated, and effective manner. In April 2024, the Administration issued NSM-22 on Critical Infrastructure Security and Resilience, replacing Presidential Policy Directive 21 (PPD-21) as the Federal Government’s primary policy document governing critical infrastructure security and resilience. Released more than 10 years ago, PPD-21 defined 16 critical sectors and assigned responsibility for identifying and managing cyber and other all-hazards risks. NSM-22 strengthens the Federal Government’s ability to enable cross-sector cyber defense; clarifies CISA’s role as the National Coordinator for the Security and Resilience of Critical Infrastructure; improves connectivity with other Federal agencies serving as SRMAs; and enhances integration and information sharing with law enforcement, the intelligence community, and critical infrastructure owners and operators. NSM-22 also better positions the Federal Government to balance collaboration with regulation, directing SRMAs and sector-specific regulators to develop minimum security requirements. CISA, as the National Coordinator, will engage with SRMAs to develop updated risk assessments and the National Infrastructure Risk Management Plan. CISA plays a central role in enabling critical infrastructure owners and operators to defend themselves. In 2023, CISA’s Joint Cyber Defense Collaborative (JCDC) completed three joint cyber defense plans to enhance the cybersecurity and resilience of critical infrastructure partners. JCDC’s remote monitoring and management (RMM) and open-source software (OSS) plans manage cross sector risk by addressing the exploitation of RMM software and producing best practice guidance for the secure use of OSS in operational technology, respectively. JCDC also published an incident response guide for the water and wastewater sector to support small- and 2024 REPORT ON THE CYBERSECURITY OF THE UNITED STATES POSTURE 11

Select target paragraph3