MEA SURE OF EFFEC TI V E N E SS 1 | Increase in the number of technology providers that have published detailed threat models, describing what the creators are trying to protect and from whom. 2 | Increase in the number of technology providers that have regularly and publicly attested to implementation of specific controls in the Secure Software Development Framework (SSDF). 3 | Increase in the number of technology providers that have published a commitment to ensure that product CVE entries are correct and complete. 4 | Increase in the number of technology providers that have published a secure-bydesign roadmap, including how the provider is making changes to their software development processes, measuring defect rates, and setting goals for improvement, and transitioning to memory-safe programming languages. 5 | Increase in the number of technology providers that regularly publish securityrelevant statistics and trends, such as MFA adoption, use of unsafe legacy protocols, and the percentage of customers using unsupported product versions. OB JEC TIVE 3. 2 Understand and reduce cybersecurity risks posed by emergent technologies The current technology environment poses of a variety of cybersecurity challenges: widespread use of products no longer supported by their vendor, complex network architectures that create gaps for adversaries, resource constrained organizations that are unable to deploy modern security controls. Even as we address these characteristics that challenge nearly every organization, we must recognize that the technology environment of the near future may present even great risks. While we collectively cannot predict the future technology environment with precision, we know that AI and cryptanalytically-relevant quantum computers (CRQCs) will fundamentally change aspects of how we secure our critical data and systems from cybersecurity threats. We will collaboratively work to ensure that our own work benefits from responsible use of emergent technologies, that we help the developers of emergent technologies protect their systems and data from malicious use, and that we help protect organizations from adversarial use of these technologies. C I S A C Y B ER S EC U RI T Y ST R AT EG I C PL A N 20

Select target paragraph3