 Strategic Objective 1.2: Scale Public-Private Collaboration Initiative Number: 1.2.1 Initiative Title: Scale public-private partnerships to drive development and adoption of secureby-design and secure-by-default technology Initiative Description The Cybersecurity and Infrastructure Security Agency (CISA) will lead public-private partnerships with technology manufacturers, educators, non-profit organizations, academia, the open-source software community, and others to drive the development and adoption of software and hardware that is secure-by-design and secure-by-default. CISA, working with NIST, other Federal agencies, including SRMAs, as appropriate, and the private sector will develop secureby-design and secure-by-default principles and practices that first leverage existing and relevant international, industry, and government standards and practices. CISA will identify barriers to adoption for such principles and best practices, and will work to drive collective action to adopt these principles across the private sector. In the case that gaps between secure-by-design and secure-by-default principles and existing standards and practices are identified, CISA, NIST, NSF, and other Federal agencies, including SRMAs, as appropriate, will lead open and transparent public-private partnerships to fill those gaps. NCS Reference The Federal Government will also deepen operational and strategic collaboration with software, hardware, and managed service providers with the capability to reshape the cyber landscape in favor of greater security and resilience. Responsible Agency: CISA Contributing Entities: NIST, NSF, SRMAs Completion Date: 4Q FY24 14 NATIONAL CYBERSECURITY STRATEGY IMPLEMENTATION PLAN

Select target paragraph3