CISA’S CY BERSEC URIT Y Goals and Objectives Our Cybersecurity Strategic Plan includes goals and associated objectives that will be executed through Annual Operating Plans, assigning each CISA organization responsibilities for key milestones and metrics. Importantly, our three goals do not operate in isolation, as shown below. GOA L 1 | Our understanding of immediate and emerging threats will enable us to prioritize investment in the security controls, product attributes, and services that most effectively reduce risks. GOAL 1 AD D R E SS IM M E D IATE T H REAT S GOAL 3 D R IV E SE C UR IT Y AT SCALE GOAL 2 H AR D E N T HE T E R R AIN GOA L 2 | As we provide guidance and services that help organizations prioritize reductions in enterprise risk, we will more clearly define the risks that can be most effectively addressed by safer products. GOA L 3 | As we advance security across the product lifecycle, we will force threat actors to adopt more time-consuming and expensive tactics, reducing the prevalence of attacks. F I G U R E 2 . CISA Cybersecurity Strategic Plan Goals C I S A C Y B ER S EC U RI T Y ST R AT EG I C PL A N 6

Select target paragraph3