OB JEC TIVE 1 .1
Increase visibility into, and ability to mitigate,
cybersecurity threats and campaigns
Today, our cybersecurity community, CISA included, lacks visibility of necessary breadth and
depth into cybersecurity intrusions and adversary campaigns. We must achieve the ability to
rapidly detect adversary activity and enable rapid eviction, denying malicious actors the
persistent access they often seek, whether on-premises or in the cloud. We will achieve this
visibility by all available means: through our own sensors and capabilities; by leveraging
commercial and public data sources, and by partnering with the private sector, government
agencies, and international allies. Our necessary gains in operational visibility must be
underpinned by state-of-the-art tools, modern analytic infrastructure, trusted partnerships, and
the world’s best analytic workforce. All this data must be seamlessly integrated across CISA and
rapidly shared in real-time in a machine-readable manner with government, private sector, and
international partners to provide operators with accurate, actionable information — a vision we
will execute leveraging the Joint Collaborative Environment. Working collaboratively with our
partners, we must identify and mitigate threat campaigns before significant damage occurs.
ENA BL ING MEA SURE
We will measure the breadth of our visibility into threat activity across critical infrastructure
and government networks by building a coalition that leverages all available capabilities — our
own and those of our partners.
MEA SURE OF EFFEC TI V E N E SS
We will use our increasing visibility to track progress in reducing the number and impact of
incidents affecting critical infrastructure and government networks and the dwell time of our
adversaries for each incident.
1 | Reduction in our time-to-detect
adversary activity affecting federal agencies
and critical infrastructure partners.
C I S A C Y B ER S EC U RI T Y ST R AT EG I C PL A N
2 | Reduction in the time-to-remediation
across each identified intrusion.
3 | Reduction in impact of incidents
affecting CISA stakeholders.
9