FE D E R A L AG E N C I E S TA RG E T- RI C H RE SO U RC E - P O O R federal civilian executive branch agencies, where we maintain unique authorities and capabilities target rich, resource poor entities where federal assistance and support is most needed, including SLTT partners and our nation’s election infrastructure C RI T I CA L I N FR A S T RU C T U RE KE Y T EC H N O LO GY PROV I D E RS organizations prioritized for partnership to maxinize national risk reduction, identified by our National Risk Management Center technology and cybersecurity companies with unique capability and visibility, including the Industrial Control System and Operational Technology communities F I G U R E 1 . Priority Stakeholders importantly, our success is based on the trust of our partners. At every turn, we will prioritize maintaining trusted relationships that allow us to serve as a unique partner and source of expertise. We also recognize that cybersecurity is a whole-of-society mission, in which every individual and organization has a role to play. PRIORITIZE OUR RES O URC E S WITH R IGO R A N D H UM ILI T Y: Like any organization, CISA’s resources are finite, and we must prioritize our actions to achieve the greatest impact for the American people. We will focus our activities on four broad sets of stakeholders: (1) federal civilian executive branch agencies, where we maintain unique authorities and capabilities; (2) target rich, resource poor entities where federal assistance and support is most needed, including SLTT partners and our nation’s election infrastructure; (3) organizations that are uniquely critical to providing or sustaining National Critical Functions, leveraging the analytic capabilities of our National Risk Management Center; and (4) technology and cybersecurity companies with capability and visibility to drive security at scale, including the Industrial Control System and Operational Technology communities. While we will not limit our support and engagement to these groups, prioritization will allow us to make prudent tradeoffs where necessary to maximize our contributions. ACH IEV E IMPACT OR FA I L FA S T: We recognize that cybersecurity risk to our country is too high, and that the American people expect CISA to play a central role in driving positive change. We must ensure that all of our efforts have a measurable impact in reducing cybersecurity risk, whether directly or indirectly, and rigorously leverage available data in determining whether our intended impacts are being achieved. Where we determine that a given program, service, or capability is not resulting in expected impacts, we will be disciplined in “failing fast” and making best use of our resources to pivot with agility. C I S A C Y B ER S EC U RI T Y ST R AT EG I C PL A N 5

Select target paragraph3