The goal of the plan is to focus and guide the agency’s efforts over the next three years. The plan shows four goals CISA feels it must achieve over the next three years that will help keep critical infrastructure up and running.
Three of the goals focus on “how” the agency will work to reduce risk and build resilience, while the fourth goal focuses internally to ensure the agency can execute the CISA Strategic Plan.
The four goals include:
- Cyber defense: Spearhead the national effort to ensure the defense and resilience of cyberspace. Serving as the country’s cyber defense agency, the agency will lead the national effort to defend against threat actors that target U.S. critical infrastructure, federal and State, local, tribal, and territorial (SLTT) governments, the private sector, and the American people.
- Risk reduction and resilience: Reduce risks to, and strengthen the resilience of, America’s critical infrastructure. Safety and security depend on the ability of critical infrastructure to prepare for and adapt to changing conditions and to withstand and recover rapidly from disruptions. CISA will coordinate a national effort to secure and protect against critical infrastructure risks. This national effort is centered around identifying which systems and assets are truly critical to the nation, understanding how they are vulnerable, and taking action to manage and reduce risks to them. CISA will serve as a partner to critical infrastructure owners and operators nationwide to help reduce risks and build their security capacity to withstand new threats and disruptions.
- Operational collaboration: Strengthen operational collaboration and information sharing. At the heart of CISA’s mission is partnership and collaboration. Securing the nation’s cyber and physical infrastructure is a shared responsibility. CISA hopes to challenge traditional ways of doing business and actively working with government, industry, academic, and international partners to move toward more forward-leaning, action-oriented collaboration.
- Agency unification: Unify as One CISA through integrated functions, capabilities, and workforce. As one team unified behind a shared mission, CISA said it will “work smart” to operate in an efficient and cost-effective manner.
“The convergence of cyber-physical technologies and systems that deliver our critical functions – from manufacturing to healthcare to transportation and beyond – means that single events can manifest in the loss or degradation of service across multiple industries,” the plan said. “Operational technology (OT) and industrial control systems (ICS) pose unique risks that demand particular focus due to the heightened consequences of disruption and challenges related to deploying certain security controls at scale. While new and emerging technologies are vital drivers of innovation and opportunity, they can also present unanticipated risks. Similarly, unforeseen interdependencies can lead to systemic risk conditions and cascading impacts. Such an evolving environment requires a more unified approach than ever before.”
To that end, CISA said in a dynamic risk landscape, it needs to be smart, innovative, and adaptable and have an empowered workforce collaborating as a unified agency.
“It is our duty to work with our stakeholders to mitigate these risks to preserve our national security, economic stability, and the health and safety of all of our citizens,” said Jen Easterly, CISA director.
Click here to view the entire strategic plan.

