APPENDIX 1 Cybersecurity Strategic Plan alignment CISA STRATE G IC PL AN G OA L 2 RI SK RE DUC TION A ND RESIL IENC E C I S A CY B ERSEC URIT Y ST R AT EGI C PL A N O B JEC T I V E S 1.3. Plan for, exercise, and execute joint cyber defense operations and coordinate the response to significant cybersecurity incidents 2.3. Enhance CISA’s security and risk mitigation guidance and impact 2.2. Drive implementation of measurably effective cybersecurity investments 2.3. Provide cybersecurity capabilities and services that fill gaps and help measure progress 3.2. Understand and reduce cybersecurity risks posed by emergent technologies 2.4. Build greater stakeholder capacity in infrastructure and network security and resilience 2.5. Increase CISA’s ability to respond to threats and incidents 2.6. Support risk management activities for election infrastructure CISA STRATEG IC PL AN G OA L 3 O PE RATIONA L C OL L A BORATIO N 3.1. Optimize collaborative planning and implementation of stakeholder engagements and partnership activities 3.2. Fully integrate regional offices into CISA’s operational coordination 3.3. Streamline stakeholder access to and use of appropriate CISA programs, products, and services C I S A C Y B ER S EC U RI T Y ST R AT EG I C PL A N 2.3. Provide cybersecurity capabilities and services that fill gaps and help measure progress 1.1. Increase visibility into, and ability to mitigate, cybersecurity threats and campaigns 1.3. Plan for, exercise, and execute joint cyber defense operations and coordinate the response to significant cybersecurity incidents All Objectives C I S A CY B ERSEC URIT Y ST R AT EGI C PL A N O B JEC T I V E S 1.3. Plan for, exercise, and execute joint cyber defense operations and coordinate the response to significant cybersecurity incidents 1.3. Plan for, exercise, and execute joint cyber defense operations and coordinate the response to significant cybersecurity incidents 2.3. Provide cybersecurity capabilities and services that fill gaps and help measure progress 1.3. Plan for, exercise, and execute joint cyber defense operations and coordinate the response to significant cybersecurity incidents 26

Select target paragraph3