Pillar Three: Shape Market Forces to Drive Security and
Resilience
3.2
3.3
3.4
3.5
3.6
8
Drive the Development of Secure IoT Devices
3.2.1 Implement Federal Acquisition Regulation (FAR) requirements per the Internet of
Things (IoT) Cybersecurity Improvement Act of 2020
3.2.2 Initiate a U.S. Government IoT security labeling program
Shift Liability for Insecure Software Products and Services
3.3.1 Explore approaches to develop a long-term, flexible, and enduring software
liability framework
3.3.2 Advance software bill of materials (SBOM) and mitigate the risk of unsupported
software
3.3.3 Coordinated vulnerability disclosure
Use Federal Grants and Other Incentives to Build in Security
3.4.1 Leverage Federal grants to improve infrastructure cybersecurity
3.4.2 Prioritize funding for cybersecurity research
3.4.3 Prioritize cybersecurity research, development, and demonstration on social,
behavioral, and economic research in cybersecurity
Leverage Federal Procurement to Improve Accountability
3.5.1 Implement Federal Acquisition Regulation (FAR) changes required under EO
14028
3.5.2 Leverage the False Claims Act to improve vendor cybersecurity
Explore a Federal Cyber Insurance Backstop
3.6.1 Assess the need for a Federal insurance response to a catastrophic cyber event
NATIONAL CYBERSECURITY STRATEGY
IMPLEMENTATION PLAN