 Initiative Number: 4.1.2 Initiative Title: Promote open-source software security and the adoption of memory safe programming languages Initiative Description The Office of the National Cyber Director will establish an Open-Source Software Security Initiative (OS3I) to champion the adoption of memory safe programming languages and opensource software security. As part of this initiative, CISA will work with OS3I and the opensource software community to enable the secure usage of open-source software in the Federal Government and critical infrastructure, and to raise the security baseline of the open-source software ecosystem. CISA will also develop close partnerships with open-source software community members and integrate into various community efforts. NCS Reference The Federal Government will lead by ensuring that its networks have implemented these and other security measures while partnering with stakeholders to develop and drive adoption of solutions that will improve the security of the Internet ecosystem and support research to understand and address reasons for slow adoption. Responsible Agency: ONCD Contributing Entities: CISA, NSF, OMB Completion Date: 1Q FY24 Initiative Number: 4.1.3 Initiative Title: Accelerate development, standardization, and adoption of foundational Internet infrastructure capabilities and technologies Initiative Description Consistent with the National Standards Strategy, the National Institute of Standards and Technology will convene the Interagency International Cybersecurity Standardization Working Group to coordinate on major issues in international cybersecurity standardization and enhance U.S. Federal agency participation in the process. NCS Reference By supporting non-governmental Standards Developing Organizations, the United States will partner with industry leaders, international allies, academic institutions, professional societies, consumer groups, and nonprofits, to secure emerging technologies, enable interoperability, foster global market competition, and protect our national security and economic advantage. Responsible Agency: NIST Completion Date: 1Q FY24 36 NATIONAL CYBERSECURITY STRATEGY IMPLEMENTATION PLAN

Select target paragraph3