consumable by our partners, guiding target rich/resource poor entities to alternative providers when necessary, benefitting from relationships and scale offered by our regional teams. In the final category, we will leverage commercial Attack Surface Management and similar capabilities to both help our partners identify exploited or exploitable conditions and gain a better picture into security trends across the country. In all cases, our strong bias will be to leverage commercially-available tools and services; only when no viable capabilities exist in the commercial market will we consider developing an in-house capability. Our capabilities and services will be designed with scalability as a top priority, leveraging the breadth and capability of our regional cybersecurity workforce and focusing on delivering measurable value to every participating partner. These capabilities will be underpinned by modern analytic infrastructure, executed through our Cyber Analytics and Data System (CADS) for our own operators and expanding into the Joint Collaborative Environment (JCE) to incorporate data and analysis from our partners across government and the private sector. ENA BL ING MEA SURE We will expand and modernize our cybersecurity capabilities and services to cover more partners and address a more complete set of risks. MEA SURE OF EFFEC TI V E N E SS We will define measures of effectiveness for every capability and service, to include: 1 | Protective DNS Service: Number of malicious domain requests blocked. 2 | Continuous Diagnostics and Mitigation: Percentage increase in agencies that have fully automated key vulnerability and asset management processes and can report advanced measurements such as time-to-remediate, scan frequency, and scan quality. 3 | Attack Surface Management: Percentage decrease in prevalence of, and time-to-remediate, vulnerabilities in all participating organizations and percentage C I S A C Y B ER S EC U RI T Y ST R AT EG I C PL A N increase in visibility across all sectors. 4 | Vulnerability Disclosure Platform: Increase in vulnerabilities identified via agency Vulnerability Disclosure Platforms prior to adversary exploitation. 5 | DotGov program: Increase in eligible organizations enrolled in DotGov. 6 | CyberSentry: Number of potential threats detected by the CyberSentry capability prior to identification by participating entity. 17

Select target paragraph3