Strategic Objective 1.2: Scale Public-Private Collaboration
Initiative Number: 1.2.1
Initiative Title: Scale public-private partnerships to drive development and adoption of secureby-design and secure-by-default technology
Initiative Description
The Cybersecurity and Infrastructure Security Agency (CISA) will lead public-private
partnerships with technology manufacturers, educators, non-profit organizations, academia, the
open-source software community, and others to drive the development and adoption of software
and hardware that is secure-by-design and secure-by-default. CISA, working with NIST, other
Federal agencies, including SRMAs, as appropriate, and the private sector will develop secureby-design and secure-by-default principles and practices that first leverage existing and relevant
international, industry, and government standards and practices. CISA will identify barriers to
adoption for such principles and best practices, and will work to drive collective action to adopt
these principles across the private sector. In the case that gaps between secure-by-design and
secure-by-default principles and existing standards and practices are identified, CISA, NIST,
NSF, and other Federal agencies, including SRMAs, as appropriate, will lead open and
transparent public-private partnerships to fill those gaps.
NCS Reference
The Federal Government will also deepen operational and strategic collaboration with software,
hardware, and managed service providers with the capability to reshape the cyber landscape in
favor of greater security and resilience.
Responsible Agency: CISA
Contributing Entities: NIST, NSF, SRMAs
Completion Date: 4Q FY24
14
NATIONAL CYBERSECURITY STRATEGY
IMPLEMENTATION PLAN