V ISIO N
Secure and resilient
infrastructure for the American people.
M ISSI O N
Lead the national effort to understand, manage, and reduce risk to our cyber
and physical infrastructure.
G OA L 1
GOAL 2
GOAL 3
ADDR ESS
IM M E DI ATE TH REAT S
HARDEN
TH E TE R R A I N
D R IV E SE C UR IT Y
AT SCA LE
OBJECTIVE 1.1
OBJECTIVE 2.1
Increase visibility into, and ability
to mitigate, cybersecurity threats
and campaigns
OBJECTIVE 1.2
Coordinate disclosure of, hunt for,
and drive mitigation of critical and
exploitable vulnerabilities
OBJECTIVE 1.3
Plan for, exercise, and execute
joint cyber defense operations and
coordinate the response to
significant cybersecurity incidents
Understand how attacks really
occur — and how to stop them
OBJECTIVE 3.1
Drive development of trustworthy
technology products
OBJECTIVE 2.2
Drive implementation of
measurably effective cybersecurity
investments
OBJECTIVE 3.2
Understand and reduce
cybersecurity risks posed by
emergent technologies
OBJECTIVE 3.3
OBJECTIVE 2.3
Provide cybersecurity capabilities
and services that fill gaps and help
measure progress
Contribute to efforts to build a
national cyber workforce
CISA C O R E PR IN C IPLE S
People First • Do The Right Thing. Always • Lead With Empathy • Seek And Provide Honest Feedback • Communicate
Transparently And Effectively • Foster Belonging, Diversity, Inclusion, And Equality • Imagine, Anticipate, And Innovate To Win •
• Make It Count • Build And Cultivate Your Network • Play Chess • Stand In The Arena • Commit To A Lifetime Of Learning
CI SA CORE VA LUES
C O L L A B O R A T I O N || I N N O V A T I O N || S E R V I C E || A C C O U N T A B I L I T Y
F I G U R E 3 . CISA Cybersecurity Strategic Plan Overview
To the contrary, our work to address immediate threats will enable us to prioritize investment
in the security controls, measures, and capabilities that most effectively reduce risks. In turn,
as we provide guidance and services that help organizations reduce their enterprise risk, we
will be able to more clearly define the attributes of a safe and secure technology product.
Finally, as we advance security across the product lifecycle, we will force threat actors to adopt
more time-consuming and expensive tactics, reducing the prevalence of attacks. It is only
through this virtuous cycle that we will make necessary progress.
C I S A C Y B ER S EC U RI T Y ST R AT EG I C PL A N
7