Initiative Number: 4.1.2
Initiative Title: Promote open-source software security and the adoption of memory safe
programming languages
Initiative Description
The Office of the National Cyber Director will establish an Open-Source Software Security
Initiative (OS3I) to champion the adoption of memory safe programming languages and opensource software security. As part of this initiative, CISA will work with OS3I and the opensource software community to enable the secure usage of open-source software in the Federal
Government and critical infrastructure, and to raise the security baseline of the open-source
software ecosystem. CISA will also develop close partnerships with open-source software
community members and integrate into various community efforts.
NCS Reference
The Federal Government will lead by ensuring that its networks have implemented these and
other security measures while partnering with stakeholders to develop and drive adoption of
solutions that will improve the security of the Internet ecosystem and support research to
understand and address reasons for slow adoption.
Responsible Agency: ONCD
Contributing Entities: CISA, NSF, OMB
Completion Date: 1Q FY24
Initiative Number: 4.1.3
Initiative Title: Accelerate development, standardization, and adoption of foundational Internet
infrastructure capabilities and technologies
Initiative Description
Consistent with the National Standards Strategy, the National Institute of Standards and
Technology will convene the Interagency International Cybersecurity Standardization Working
Group to coordinate on major issues in international cybersecurity standardization and enhance
U.S. Federal agency participation in the process.
NCS Reference
By supporting non-governmental Standards Developing Organizations, the United States will
partner with industry leaders, international allies, academic institutions, professional societies,
consumer groups, and nonprofits, to secure emerging technologies, enable interoperability, foster
global market competition, and protect our national security and economic advantage.
Responsible Agency: NIST
Completion Date: 1Q FY24
36
NATIONAL CYBERSECURITY STRATEGY
IMPLEMENTATION PLAN