Managing National Cybersecurity Risk
DHS must find innovative ways to leverage our broad resources and capabilities across the
Department and the homeland security enterprise to strategically manage national cybersecurity
risks. We have accordingly identified five pillars of a DHS-wide risk management approach.
Through our efforts to accomplish seven identified goals across these five pillars, we work to
ensure the availability of critical national functions and to foster efficiency, innovation,
trustworthy communication, and economic prosperity in ways consistent with our national values
and that protect privacy and civil liberties.
DHS Cybersecurity Goals
Pillar I – Risk Identification
Goal 1: Assess Evolving Cybersecurity Risks. We will understand the evolving national
cybersecurity risk posture to inform and prioritize risk management activities.
Pillar II – Vulnerability Reduction
Goal 2: Protect Federal Government Information Systems. We will reduce vulnerabilities of
federal agencies to ensure they achieve an adequate level of cybersecurity.
Goal 3: Protect Critical Infrastructure. We will partner with key stakeholders to ensure that
national cybersecurity risks are adequately managed.
Pillar III – Threat Reduction
Goal 4: Prevent and Disrupt Criminal Use of Cyberspace. We will reduce cyber threats by
countering transnational criminal organizations and sophisticated cyber criminals.
Pillar IV – Consequence Mitigation
Goal 5: Respond Effectively to Cyber Incidents. We will minimize consequences from
potentially significant cyber incidents through coordinated community-wide response efforts.
Pillar V – Enable Cybersecurity Outcomes
Goal 6: Strengthen the Security and Reliability of the Cyber Ecosystem. We will support
policies and activities that enable improved global cybersecurity risk management.
Goal 7: Improve Management of DHS Cybersecurity Activities. We will execute our
departmental cybersecurity efforts in an integrated and prioritized way.
The first pillar of our approach is better understanding our national risk posture. Understanding
these risks at the strategic level will enable us to effectively allocate resources and prioritize
efforts to address vulnerabilities, threats, and consequences across all of our cybersecurity
activities.
Under pillars two through four, we focus on reducing or mitigating vulnerabilities, threats, and
the potential consequences from cybersecurity incidents. DHS leads national efforts to protect
3