OB JEC TIVE 1 . 2
Coordinate disclosure of, hunt for, and drive
mitigation of critical and exploitable vulnerabilities
Most intrusions today are perpetrated using known vulnerabilities or exploiting weak security
controls. This makes life too easy for our adversaries. As a nation, we must urgently progress
to a model in which pervasive vulnerabilities and security weaknesses in critical infrastructure
and government networks are considered intolerable. While much progress in this area must
be driven through deployment of technology that is safe and secure by design and default,
we will also take near-term steps to reduce the prevalence of exploitable vulnerabilities
by providing authoritative instruction on prioritized mitigations, hunting for exploitable
vulnerabilities in domestic networks, and using all possible levers to widely publicize and drive
remediation. We must gain a persistent understanding of vulnerabilities across our nation’s
critical infrastructure and government networks in order to enable more timely remediation
before intrusions occur. We must also encourage, catalyze, and support the security research
community and product security teams to ensure that vulnerabilities are discovered and fixed
before adversaries can use them to cause harm. The uncoordinated or premature disclosure
of significant vulnerabilities can lead to opportunities for easy exploitation by threat actors
across all sectors of government and the economy. To this end, we will work closely with
vendors, integrators, system owners, the security research community, and other key partners
to incentivize identification and reporting of previously unknown vulnerabilities, enable timely
and coordinated vulnerability disclosure, and drive mitigation before compromise occurs.
C I S A C Y B ER S EC U RI T Y ST R AT EG I C PL A N
10