OB JEC TIVE 3.1 Drive development of trustworthy technology products As noted in the National Cybersecurity Strategy, “poor software security greatly increases systemic risk across the digital ecosystem and leaves Americans bearing the ultimate cost.” We will partner with like-minded organizations across government and industry to drive progress toward a world in which a technology product must be safe before it can be sold. We will focus first on defining what it means for a technology product to be safe and secure, collaboratively developing guidance and technical criteria to help customers choose safe products and manufacturers to deliver accordingly. Recognizing that technology manufacturers will need to prioritize areas for improvement, we will take a data-driven approach to identify those practices that drive down the most risk and address entire classes of attacks, such as using memory safe coding languages. We will take steps to advance transparency, including through adoption of Software Bills of Materials and rigorous vulnerability disclosure practices. Even as we maintain our voluntary, trust-based model of collaboration, we will strive to ensure that regulators and other government entities with compulsory authorities leverage technically sound and effective practices developed together with our partners across the private sector, ideally enabling harmonization across both U.S. and global regulatory regimes. ENA BL ING MEA SURE We will produce and regularly update criteria and practices to develop and maintain products that are secure by design and default, and work with partners to assess the extent to which technology products adopt these clearly defined practices. C I S A C Y B ER S EC U RI T Y ST R AT EG I C PL A N 19

Select target paragraph3