most effectively realize our collaboration and planning capabilities, we will update, exercise, execute, and maintain the National Cyber Incident Response Plan (NCIRP) to ensure that the breadth of our nation’s capacity is effectively coordinated and leveraged in reducing the impact of cyber incidents. We will accelerate coordination with our government partners that maintain the ability to impose costs on our adversaries so that decisions to target American networks are met with appropriate consequences. Recognizing the borderless nature of cyber defense, we will maximize our role as America’s Computer Emergency Response Team (CERT) to serve as an operational exemplar to the international community and forge a coalition of national cyber defense organizations to act in concert in protecting against shared threats. ENA BL ING MEA SURE 1 | We will expand the breadth and depth of our persistent collaboration model by increasing both the number of participating organizations and the operational value derived by each participant. 2 | We will increase the number of cyber defense plans and the alignment of each plan to high-priority risks identified by our public and private stakeholders. MEA SURE OF EFFEC TI V E N E SS 1 | Increase in the volume of unique, timely, and relevant information shared by industry or government partners through our persistent collaboration channels. 3 | Increase in post-incident after-action reports demonstrating that actions developed in cyber defense plans reduced negative outcomes. 2 | Increase in specific actions codified in cyber defense plans adopted by industry and government partners. C I S A C Y B ER S EC U RI T Y ST R AT EG I C PL A N 12

Select target paragraph3