OB JEC TIVE 2. 2 Drive implementation of measurably effective cybersecurity investments We must provide timely, accurate, actionable, and achievable guidance that helps organizations prioritize investment in controls and mitigations that address how attacks actually occur and how adversaries are evolving. For federal civilian executive branch agencies, we will fully exercise our directive authorities to drive toward a common security baseline and execute agency improvement plans to address tailored gaps. We will ensure that our guidance remains relevant in a changing technology environment, with particular focus on ensuring secure adoption of cloud computing resources. For organizations across the country, we will provide guidance that supports prudent investment, including machine-readable technical information by default. At the center of these efforts are the Cybersecurity Performance Goals (CPGs), which can help critical infrastructure and other entities make risk management decisions that achieve high-priority security outcomes and consider aggregate risk to the nation. We will work with a variety of partners across government and industry to promote adoption and take steps to align incentives that address constraints limiting further progress. ENA BL ING MEA SURE We will develop guidance that is directly responsive to how intrusions occur and how adversaries are adapting, and that drives investment toward the most impactful security measures, including by regularly updating the Cross-Sector Cybersecurity Performance Goals, collaboratively developing Sector-Specific Cybersecurity Performance Goals, and leveraging our Binding Operational and Emergency Directives to drive urgent investment toward the most impactful measures. MEA SURE OF EFFEC TI V E N E SS 1 | Increase in the average number of Cybersecurity Performance Goals effectively adopted by organizations across each critical infrastructure sector. 3 | Increase in the number of organizations outside of the FCEB that have adopted applicable requirements in CISA directives. 2 | Where possible, reduction in confirmed impactful incidents in organizations that have adopted a higher number of Cybersecurity Performance Goals. 4 | Increase in the percentage of FCEB agency adoption of CISA directive requirements. C I S A C Y B ER S EC U RI T Y ST R AT EG I C PL A N 15

Select target paragraph3