V ISIO N Secure and resilient infrastructure for the American people. M ISSI O N Lead the national effort to understand, manage, and reduce risk to our cyber and physical infrastructure. G OA L 1 GOAL 2 GOAL 3 ADDR ESS IM M E DI ATE TH REAT S HARDEN TH E TE R R A I N D R IV E SE C UR IT Y AT SCA LE OBJECTIVE 1.1 OBJECTIVE 2.1 Increase visibility into, and ability to mitigate, cybersecurity threats and campaigns OBJECTIVE 1.2 Coordinate disclosure of, hunt for, and drive mitigation of critical and exploitable vulnerabilities OBJECTIVE 1.3 Plan for, exercise, and execute joint cyber defense operations and coordinate the response to significant cybersecurity incidents Understand how attacks really occur — and how to stop them OBJECTIVE 3.1 Drive development of trustworthy technology products OBJECTIVE 2.2 Drive implementation of measurably effective cybersecurity investments OBJECTIVE 3.2 Understand and reduce cybersecurity risks posed by emergent technologies OBJECTIVE 3.3 OBJECTIVE 2.3 Provide cybersecurity capabilities and services that fill gaps and help measure progress Contribute to efforts to build a national cyber workforce CISA C O R E PR IN C IPLE S People First • Do The Right Thing. Always • Lead With Empathy • Seek And Provide Honest Feedback • Communicate Transparently And Effectively • Foster Belonging, Diversity, Inclusion, And Equality • Imagine, Anticipate, And Innovate To Win • • Make It Count • Build And Cultivate Your Network • Play Chess • Stand In The Arena • Commit To A Lifetime Of Learning CI SA CORE VA LUES C O L L A B O R A T I O N || I N N O V A T I O N || S E R V I C E || A C C O U N T A B I L I T Y F I G U R E 3 . CISA Cybersecurity Strategic Plan Overview To the contrary, our work to address immediate threats will enable us to prioritize investment in the security controls, measures, and capabilities that most effectively reduce risks. In turn, as we provide guidance and services that help organizations reduce their enterprise risk, we will be able to more clearly define the attributes of a safe and secure technology product. Finally, as we advance security across the product lifecycle, we will force threat actors to adopt more time-consuming and expensive tactics, reducing the prevalence of attacks. It is only through this virtuous cycle that we will make necessary progress. C I S A C Y B ER S EC U RI T Y ST R AT EG I C PL A N 7

Select target paragraph3