MEA SURE OF EFFEC TI V E N E SS
1 | Increase in the number of technology
providers that have published detailed
threat models, describing what the creators
are trying to protect and from whom.
2 | Increase in the number of technology
providers that have regularly and publicly
attested to implementation of specific
controls in the Secure Software
Development Framework (SSDF).
3 | Increase in the number of technology
providers that have published a
commitment to ensure that product CVE
entries are correct and complete.
4 | Increase in the number of technology
providers that have published a secure-bydesign roadmap, including how the provider
is making changes to their software
development processes, measuring defect
rates, and setting goals for improvement,
and transitioning to memory-safe
programming languages.
5 | Increase in the number of technology
providers that regularly publish securityrelevant statistics and trends, such as MFA
adoption, use of unsafe legacy protocols,
and the percentage of customers using
unsupported product versions.
OB JEC TIVE 3. 2
Understand and reduce cybersecurity risks posed
by emergent technologies
The current technology environment poses of a variety of cybersecurity challenges: widespread
use of products no longer supported by their vendor, complex network architectures that
create gaps for adversaries, resource constrained organizations that are unable to deploy
modern security controls. Even as we address these characteristics that challenge nearly
every organization, we must recognize that the technology environment of the near future
may present even great risks. While we collectively cannot predict the future technology
environment with precision, we know that AI and cryptanalytically-relevant quantum computers
(CRQCs) will fundamentally change aspects of how we secure our critical data and systems
from cybersecurity threats. We will collaboratively work to ensure that our own work benefits
from responsible use of emergent technologies, that we help the developers of emergent
technologies protect their systems and data from malicious use, and that we help protect
organizations from adversarial use of these technologies.
C I S A C Y B ER S EC U RI T Y ST R AT EG I C PL A N
20