APPENDIX 1 Alignment with the CISA Strategic Plan CISA STRATE G IC PL AN G OA L 1 CYBER D EFENSE C I S A CY B ERSEC URIT Y ST R AT EGI C PL A N O B JEC T I V E S 1.1. Enhance the ability of federal systems to withstand cyberattacks and incidents All Objectives 1.2. Increase CISA’s ability to actively detect cyber threats targeting America’s critical infrastructure and critical networks 1.1. Increase visibility into, and ability to mitigate, cybersecurity threats and campaigns 1.3. Drive the disclosure and mitigation of critical cyber vulnerabilities 1.2. Coordinate disclosure of, hunt for, and drive mitigation of critical and exploitable vulnerabilities 3.1. Drive development of trustworthy technology products 1.4. Advance the cyberspace ecosystem to drive security-by-default 3.2. Understand and reduce cybersecurity risks posed by emergent technologies 3.3. Contribute to efforts to build a national cyber workforce CISA STRATEG IC PL AN G OA L 2 RI SK RE DUC TION A ND RESIL IENC E 2.1. Expand visibility of risks to infrastructure, systems, and networks 2.2. Advance CISA’s risk analytic capabilities and methodologies 2.3. Enhance CISA’s security and risk mitigation guidance and impact C I S A C Y B ER S EC U RI T Y ST R AT EG I C PL A N C I S A CY B ERSEC URIT Y ST R AT EGI C PL A N O B JEC T I V E S 1.1. Increase visibility into, and ability to mitigate, cybersecurity threats and campaigns 2.1. Understand how attacks really occur — and how to stop them 2.1. Understand how attacks really occur — and how to stop them 1.1. Increase visibility into, and ability to mitigate, cybersecurity threats and campaigns 1.2. Coordinate disclosure of, hunt for, and drive mitigation of critical and exploitable vulnerabilities 25

Select target paragraph3