PURPOSE This Strategic Plan communicates the Cybersecurity and Infrastructure Security Agency’s (CISA) mission and vision, promotes unity of effort across the agency and our partners, and defines success for CISA as an agency. It describes the stakeholder, policy, and operational context in which we must perform and presents the strategic changes CISA will make to better execute our vital mission over the next three years. It builds on and aligns with the United States Department of Homeland Security Strategic Plan for Fiscal Years 2020 – 2024. CISA will implement the Strategic Plan through the agency’s division and office-level Annual Operating Plans (AOP). ABOUT CISA Established by the Cybersecurity and Infrastructure Security Agency Act of 2018, CISA serves as both America’s cyber defense agency and as the national coordinator for critical infrastructure security and resilience. This vast mission space necessitates engagements and partnerships with stakeholders worldwide as well as a strong domestic, regional presence. The threats we face — digital and physical, human-made, technological, and natural — are more complex, and the threat actors more diverse, than at any point in our history. CISA is at the center of mobilizing a collective defense as we lead the nation’s efforts to understand, manage, and reduce risk to our critical infrastructure. Through all our efforts, we will remain vigilant about preserving the American people’s privacy, civil rights, and civil liberties. C I S A ST R AT EG I C PL A N We count among our stakeholders the Federal Civilian Executive Branch (FCEB); state, local, tribal, and territorial (SLTT) governments; the private sector; Sector Risk Management Agencies (SRMAs); non-governmental organizations; non-profits; the American public; international partners; and academia. 3

Select target paragraph3