OB JEC TIVE 1 .1 Increase visibility into, and ability to mitigate, cybersecurity threats and campaigns Today, our cybersecurity community, CISA included, lacks visibility of necessary breadth and depth into cybersecurity intrusions and adversary campaigns. We must achieve the ability to rapidly detect adversary activity and enable rapid eviction, denying malicious actors the persistent access they often seek, whether on-premises or in the cloud. We will achieve this visibility by all available means: through our own sensors and capabilities; by leveraging commercial and public data sources, and by partnering with the private sector, government agencies, and international allies. Our necessary gains in operational visibility must be underpinned by state-of-the-art tools, modern analytic infrastructure, trusted partnerships, and the world’s best analytic workforce. All this data must be seamlessly integrated across CISA and rapidly shared in real-time in a machine-readable manner with government, private sector, and international partners to provide operators with accurate, actionable information — a vision we will execute leveraging the Joint Collaborative Environment. Working collaboratively with our partners, we must identify and mitigate threat campaigns before significant damage occurs. ENA BL ING MEA SURE We will measure the breadth of our visibility into threat activity across critical infrastructure and government networks by building a coalition that leverages all available capabilities — our own and those of our partners. MEA SURE OF EFFEC TI V E N E SS We will use our increasing visibility to track progress in reducing the number and impact of incidents affecting critical infrastructure and government networks and the dwell time of our adversaries for each incident. 1 | Reduction in our time-to-detect adversary activity affecting federal agencies and critical infrastructure partners. C I S A C Y B ER S EC U RI T Y ST R AT EG I C PL A N 2 | Reduction in the time-to-remediation across each identified intrusion. 3 | Reduction in impact of incidents affecting CISA stakeholders. 9

Select target paragraph3