APPENDIX 2 Alignment with the National Cybersecurity Strategy NAT IONAL CYBERS ECURIT Y STRATEGY PILLAR T WO | DISRUPT A ND DIS MA N TLE T H REAT AC TORS C I S A CY B ERSEC URIT Y ST R AT EGI C PL A N O B JEC T I V E S 1.1. Increase visibility into, and ability to mitigate, cybersecurity threats and campaigns 2.1. Integrate federal disruption activities 2.2. Enhance public-private operational collaboration to disrupt adversaries 1.3. Plan for, exercise, and execute joint cyber defense operations and coordinate the response to significant cybersecurity incidents 1.1. Increase visibility into, and ability to mitigate, cybersecurity threats and campaigns 1.3. Plan for, exercise, and execute joint cyber defense operations and coordinate the response to significant cybersecurity incidents 2.3. Increase the speed and scale of intelligence sharing and victim notification 1.3. Plan for, exercise, and execute joint cyber defense operations and coordinate the response to significant cybersecurity incidents 2.4. Prevent abuse of U.S.-based infrastructure 1.3. Plan for, exercise, and execute joint cyber defense operations and coordinate the response to significant cybersecurity incidents 2.5. Counter cybercrime, defeat ransomware All Objectives NAT IONAL CY BE RS ECURIT Y STRATEGY PILLAR T H R E E | SH A PE MA RKET FO RC E S TO DRI VE SEC URIT Y A ND RES IL IE N C E C I S A CY B ERSEC URIT Y ST R AT EGI C PL A N O B JEC T I V E S 3.1. Hold the stewards of our data accountable N/A 3.2. Drive the development of secure internet of things devices 3.1. Drive development of trustworthy technology products 3.3. Shift liability for insecure software products and services C I S A C Y B ER S EC U RI T Y ST R AT EG I C PL A N 1.2. Coordinate disclosure of, hunt for, and drive mitigation of critical and exploitable vulnerabilities 3.1. Drive development of trustworthy technology products 29

Select target paragraph3