The Biden-Harris Administration this week released the implementation plan for the National Cybersecurity Strategy in a bid to enhance cyber resilience against increasing threats and promote the “secure-by-design” concept in which security capabilities are implemented during the design phase of product development.

The White House unveiled the National Cybersecurity Strategy in March, which calls for the fundamental shift of the security burden away from individuals and small organizations to more capable entities in the public and private sectors and increase incentives to favor long-term investments into security.

The new National Cybersecurity Strategy Implementation Plan outlines more than 65 high-impact federal initiatives involving 18 different agencies and designed to combat cybercrimes and build a cyber-skilled workforce for the future.

The plan includes sample initiatives for the five pillars of the National Cybersecurity Strategy:

  1. Defending critical infrastructure: The Cybersecurity and Infrastructure Security Agency (CISA) will lead the update of the National Cyber Incident Response Plan that includes guidance for the roles and a coordinated manner between the government and private sector.
  2. Disrupting and dismantling threat actors: CISA and the FBI co-chair the Joint Ransomware Task Force to combat ransomware and other cybercrime. The FBI, in collaboration with international and private sector partners, aims to disrupt the ransomware ecosystem, including virtual asset providers that enable the laundering of ransomware proceeds and web forums offering initial access credentials.
  3. Shaping market forces to drive security and resilience: To increase software transparency and accountability, CISA continues to lead the drive to close gaps in software bill of materials (SBOM) scale and implementation.
  4. Investing in a resilient future: The National Institute of Standards and Technology (NIST) will lead the Interagency International Cybersecurity Standardization Working Group to drive key security standardization including the post-quantum cryptography standard.
  5. Forging international partnerships to pursue shared goals: the Department of State is set to publish an International Cyberspace and Digital Policy Strategy and work to help establish and strengthen country and regional interagency teams to facilitate coordination with partner nations.
Public-private collaboration in security

Security experts noted this National Cybersecurity Strategy Implementation Plan is a milestone for government and private sector collaboration.

“The National Cybersecurity Strategy Implementation Plan is a great step for both the government and the private sector to find ways to continue partnering together to help the President execute his vision for cyber,” Sabeen Malik, VP of global government affairs and public policy at Rapid7, noted in a statement. “The plan does a good job of identifying areas in which the private sector can continue to help, including ransomware, vulnerability disclosures and risk management strategies.”

Drew Bagley, VP of counsel of privacy and cyber policy at CrowdStrike, highlighted the focus on secure-by-design principles.

“While the implementation plan covers a lot of ground, it’s clear that the authors applied significant focus on the broad application of secure-by-design or secure-by-default principles,” Bagley said.

ForgeRock CEO Fran Rosch added that, “until now, the U.S. government has viewed cybersecurity as voluntary. Today’s plan demonstrates that it has shifted to viewing these cybersecurity policies as mandatory because attackers continue to have the upper hand when it comes to cybercrime and fraud. ”