 Initiative Number: 3.3.3 Initiative Title: Coordinated vulnerability disclosure Initiative Description The Cybersecurity and Infrastructure Security Agency will work to build domestic and international support for an expectation of coordinated vulnerability disclosure among public and private entities, across all technology types and sectors, including through the creation of an international vulnerability coordinator community of practice. This will include supporting international institutions, including international Computer Emergency Response Teams and other community-driven organizations, to build global awareness and capacity around coordinated vulnerability disclosure. NCS Reference To further incentivize the adoption of secure software development practices, the Administration will encourage coordinated vulnerability disclosure across all technology types and sectors… Responsible Agency: CISA Contributing Entities: State Completion Date: 4Q FY25 Strategic Objective 3.4: Use Federal Grants and Other Incentives to Build in Security Initiative Number: 3.4.1 Initiative Title: Leverage Federal grants to improve infrastructure cybersecurity Initiative Description The Office of the National Cyber Director will develop materials to clarify, facilitate, and encourage incorporation of cybersecurity equities into Federal grant projects. NCS Reference Through programs funded by the Bipartisan Infrastructure Law…, the United States is making once-in-a-generation investments in our infrastructure and the digital ecosystem that supports it. This Administration is committed to making investments in a manner that increases our collective systemic resilience. Responsible Agency: ONCD Contributing Entities: CISA, OMB Completion Date: 4Q FY23 NATIONAL CYBERSECURITY STRATEGY IMPLEMENTATION PLAN 31

Select target paragraph3