OB JEC TIVE 3.1
Drive development of trustworthy technology
products
As noted in the National Cybersecurity Strategy, “poor software security greatly increases
systemic risk across the digital ecosystem and leaves Americans bearing the ultimate cost.”
We will partner with like-minded organizations across government and industry to drive
progress toward a world in which a technology product must be safe before it can be sold.
We will focus first on defining what it means for a technology product to be safe and secure,
collaboratively developing guidance and technical criteria to help customers choose safe
products and manufacturers to deliver accordingly. Recognizing that technology manufacturers
will need to prioritize areas for improvement, we will take a data-driven approach to identify
those practices that drive down the most risk and address entire classes of attacks, such as
using memory safe coding languages. We will take steps to advance transparency, including
through adoption of Software Bills of Materials and rigorous vulnerability disclosure practices.
Even as we maintain our voluntary, trust-based model of collaboration, we will strive to ensure
that regulators and other government entities with compulsory authorities leverage technically
sound and effective practices developed together with our partners across the private sector,
ideally enabling harmonization across both U.S. and global regulatory regimes.
ENA BL ING MEA SURE
We will produce and regularly update criteria and practices to develop and maintain products
that are secure by design and default, and work with partners to assess the extent to which
technology products adopt these clearly defined practices.
C I S A C Y B ER S EC U RI T Y ST R AT EG I C PL A N
19