Contents EXECUTIVE S UM MARY 01 OUR S T RAT EGIC I N TE N T 03 OUR GOA L S A ND O B J E C TI V E S 06 GOA L 1 . A D D RE SS I M M E D I ATE TH R E AT S 1.1. Increase visibility into, and ability to mitigate, cybersecurity threats and campaigns 1.2. Coordinate disclosure of, hunt for, and drive mitigation of critical and exploitable vulnerabilities 1.3. Plan for, exercise, and execute joint cyber defense operations and coordinate the response to significant cybersecurity incidents 08 GOA L 2. HA RDEN TH E TE R R A I N 2.1. Understand how attacks really occur — and how to stop them 2.2. Drive implementation of measurably effective cybersecurity investments 2.3. Provide cybersecurity capabilities and services that fill gaps and help measure progress 13 14 GOA L 3. DRIV E SE C UR IT Y AT SCA LE 3.1. Drive development of trustworthy technology products 3.2. Understand and reduce cybersecurity risks posed by emergent technologies 3.3. Contribute to efforts to build a national cyber workforce 18 19 C ONC LUSION 23 A PPENDICES Appendix 1. Alignment with the CISA Strategic Plan Appendix 2. Alignment with the National Cybersecurity Strategy 24 25 28 C I S A C Y B ER S EC U RI T Y ST R AT EG I C PL A N 09 10 11 15 16 20 21 I

Select target paragraph3