Summary: The Department of Homeland Security’s Cybersecurity Strategy
Amid concern about the security of the midterm elections and high-profile attacks on private companies, the Department of Homeland Security has issued its Cybersecurity Strategy, as mandated by the 2017 National Defense Authorization Act. The strategy provides DHS with a five-year framework for reducing cybersecurity vulnerabilities, building resilience, and enhancing response capabilities.
The DHS Office of Strategy, Policy, and Plans will annually audit how DHS is executing the strategy and provide a report to the secretary on its progress. The department plans to review and update the strategy in 2023, and periodically (though it is unclear how frequently) thereafter.
Lawfare summarizes the document, going through its five “pillars” – Risk Identification, Vulnerability Reduction, Threat Reduction, Consequence Mitigation, Enable Cybersecurity Outcomes – and the seven more specific goals that fall under them.

