OB JEC TIVE 2. 2
Drive implementation of measurably effective
cybersecurity investments
We must provide timely, accurate, actionable, and achievable guidance that helps
organizations prioritize investment in controls and mitigations that address how attacks
actually occur and how adversaries are evolving. For federal civilian executive branch agencies,
we will fully exercise our directive authorities to drive toward a common security baseline and
execute agency improvement plans to address tailored gaps. We will ensure that our guidance
remains relevant in a changing technology environment, with particular focus on ensuring
secure adoption of cloud computing resources. For organizations across the country, we will
provide guidance that supports prudent investment, including machine-readable technical
information by default. At the center of these efforts are the Cybersecurity Performance
Goals (CPGs), which can help critical infrastructure and other entities make risk management
decisions that achieve high-priority security outcomes and consider aggregate risk to the
nation. We will work with a variety of partners across government and industry to promote
adoption and take steps to align incentives that address constraints limiting further progress.
ENA BL ING MEA SURE
We will develop guidance that is directly responsive to how intrusions occur and how
adversaries are adapting, and that drives investment toward the most impactful security
measures, including by regularly updating the Cross-Sector Cybersecurity Performance Goals,
collaboratively developing Sector-Specific Cybersecurity Performance Goals, and leveraging our
Binding Operational and Emergency Directives to drive urgent investment toward the most
impactful measures.
MEA SURE OF EFFEC TI V E N E SS
1 | Increase in the average number of
Cybersecurity Performance Goals effectively
adopted by organizations across each
critical infrastructure sector.
3 | Increase in the number of
organizations outside of the FCEB that have
adopted applicable requirements in CISA
directives.
2 | Where possible, reduction in confirmed
impactful incidents in organizations that
have adopted a higher number of
Cybersecurity Performance Goals.
4 | Increase in the percentage of FCEB
agency adoption of CISA directive
requirements.
C I S A C Y B ER S EC U RI T Y ST R AT EG I C PL A N
15