 Defending Federal systems at speed and scale requires the government to advance an enterpriselevel view of risk across departments and agencies. Through the adoption of shared services, agencies have bolstered their capabilities, reduced their attack surfaces, and improved visibility across Federal networks. In October 2023, OMB and ONCD convened an interagency working group that explored the deployment and use of cybersecurity shared services across the Federal Government, interviewed providers and customers, and identified gaps and challenges in getting shared services to small and micro agencies. CISA has equipped agencies with greater capabilities to identify, prioritize, and mitigate cybersecurity risks while enabling them to understand and manage critical threats through its Continuous Diagnostics and Mitigation (CDM) program, which is aligned to government-wide documents such as the Known Exploited Vulnerabilities catalog. In 2023, CISA helped enable the shift toward shared services by expanding its CDM program to all 23 civilian CFO Act agencies and 69 non-CFO Act agencies, and by onboarding 97 agencies onto their Protective Domain Name System service. CISA, OMB, and ONCD have engaged with industry to determine the feasibility of providing enhanced logging capabilities to Federal civilian executive branch agencies. In February 2024, these engagements resulted in the rollout of expanded logs to all agencies and the extension of the default log retention period from 90 to 180 days. This major step forward is in line with CISA’s Secure by Design guidance, which calls for technology providers to furnish “highquality audit logs to customers at no extra charge.” The Director of NSA, as the National Manager for NSS, continues to enhance cyber coordination and alignment across over 70 Federal departments and agencies through greater centralized accountability, alignment of policy processes, and formalization of standards for NSS across Federal owners and operators. ONCD, in collaboration with interagency partners, developed a plan to drive improvements in Internet routing security, focusing on addressing vulnerabilities in the BGP. These vulnerabilities can be addressed by solutions such as Resource Public Key Infrastructure Route Origin Authorizations (RPKI ROA). The Federal Government has developed a Legacy Registration Services Agreement template for Federal agency use, and is developing a playbook to facilitate adoption of RPKI ROA. This solution removes a significant barrier to adoption and will facilitate government-wide implementation of RPKI ROA. Efforts are also underway to improve collective operational defense so that breaches are isolated and remediated rapidly. CISA’s Persistent Access Capability, made possible through the widely adopted EDR initiative born out of Executive Order 14028, facilitates real-time threat intelligence sharing. The Federal Government's deliberate shift toward ZTA, the expansion of shared services, and the maturation of collective operational defense reflects a concerted effort to address the current cyber threat landscape and prepare for future challenges. 2024 REPORT 18 ON THE CYBERSECURITY OF THE UNITED STATES POSTURE

Select target paragraph3