APPENDIX 1 Cybersecurity Strategic Plan alignment CISA STRATE G IC PL AN G OA L 3 O PE RATIONA L COL L A BORATIO N 3.3. Streamline stakeholder access to and use of appropriate CISA programs, products, and services C I S A CY B ERSEC URIT Y ST R AT EGI C PL A N O B JEC T I V E S 2.3. Provide cybersecurity capabilities and services that fill gaps and help measure progress 1.1. Increase visibility into, and ability to mitigate, cybersecurity threats and campaigns 1.2. Coordinate disclosure of, hunt for, and drive mitigation of critical and exploitable vulnerabilities 3.4. Enhance information sharing with CISA’s partnership base 1.3. Plan for, exercise, and execute joint cyber defense operations and coordinate the response to significant cybersecurity incidents 2.1. Understand how attacks really occur — and how to stop them 2.2. Drive implementation of measurably effective cybersecurity investments 3.5. Increase integration of stakeholder insights to inform CISA product development and mission delivery CISA STRATEG IC PL AN G OA L 4 AG ENCY UNIFICAT ION 1.3. Plan for, exercise, and execute joint cyber defense operations and coordinate the response to significant cybersecurity incidents 2.3. Provide cybersecurity capabilities and services that fill gaps and help measure progress C I S A CY B ERSEC URIT Y ST R AT EGI C PL A N O B JEC T I V E S 4.1. Strengthen and integrate CISA governance, management, and prioritization N/A 4.2. Optimize CISA business operations to be mutually supportive across all divisions N/A 4.3. Cultivate and grow CISA’s high-performing workforce N/A 4.4. Advance CISA’s culture of excellence N/A C I S A C Y B ER S EC U RI T Y ST R AT EG I C PL A N 27

Select target paragraph3