 Strategic Objective 2.4: Prevent Abuse of U.S.-Based Infrastructure Initiative Number: 2.4.1 Initiative Title: Publish a Notice of Proposed Rulemaking on requirements, standards, and procedures for Infrastructure-as-a-Service (IaaS) providers and resellers Initiative Description The Department of Commerce will publish a Notice of Proposed Rulemaking implementing EO 13984 that lays out requirements for IaaS providers and resellers as well as standards and procedures for determining what risk-based prevention approach is sufficient to qualify for an exemption. NCS Reference The Administration will prioritize adoption and enforcement of a risk-based approach to cybersecurity across Infrastructure-as-a-Service providers that addresses known methods and indicators of malicious activity including through implementation of EO 13984, “Taking Additional Steps to Address the National Emergency with Respect to Significant Malicious Cyber-Enabled Activities.” Responsible Agency: Commerce Contributing Entities: DHS, DOJ, ODNI, FBI Completion Date: 4Q FY23 NATIONAL CYBERSECURITY STRATEGY IMPLEMENTATION PLAN 25

Select target paragraph3