Roll-Up of Implementation Plan Initiatives Pillar One: Defend Critical Infrastructure 1.1 1.2 1.3 1.4 1.5 6 Establish Cybersecurity Requirements to Support National Security and Public Safety 1.1.1 Establish an initiative on cyber regulatory harmonization 1.1.2 Set cybersecurity requirements across critical infrastructure sectors 1.1.3 Increase agency use of frameworks and international standards to inform regulatory alignment Scale Public-Private Collaboration 1.2.1 Scale public-private partnerships to drive development and adoption of secure-bydesign and secure-by-default technology 1.2.2 Provide recommendations for the designation of critical infrastructure sectors and SRMAs 1.2.3 Evaluate how CISA can leverage existing reporting mechanisms or the potential creation of a single portal to integrate and operationalize SRMAs’ sector-specific systems and processes 1.2.4 Investigate opportunities for new and improved information sharing and collaboration platforms, processes, and mechanisms 1.2.5 Establish an SRMA support capability Integrate Federal Cybersecurity Centers 1.3.1 Assess and improve Federal Cybersecurity Centers' and related cyber centers' capabilities and plans necessary for collaboration at speed and scale Update Federal Incident Response Plans and Processes 1.4.1 Update the National Cyber Incident Response Plan (NCIRP) 1.4.2 Issue final Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) rule 1.4.3 Develop exercise scenarios to improve cyber incident response 1.4.4 Draft legislation to codify the Cyber Safety Review Board (CSRB) with the required authorities Modernize Federal Defenses 1.5.1 Secure unclassified Federal Civilian Executive Branch (FCEB) systems 1.5.2 Modernize Federal Civilian Executive Branch (FCEB) technology 1.5.3 Secure National Security Systems (NSS) at Federal Civilian Executive Branch (FCEB) agencies NATIONAL CYBERSECURITY STRATEGY IMPLEMENTATION PLAN

Select target paragraph3