<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" href="stratmliso.xsl"?>
<StrategicPlan xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:stratml="urn:ISO:std:iso:17469:tech:xsd:stratml_core"><Name>Report on Strategic U.S. Government Engagement in International Standardization to Achieve U.S. Objectives for Cybersecurity</Name><Description>This report sets out proposed United States Government (USG) strategic objectives for pursuing the development and use of international standards for cybersecurity and makes recommendations to achieve those objectives. The recommendations cover interagency coordination, collaboration with the U.S. private sector and international partners, agency participation in international standards development, standards training and education, use of international standards to achieve mission and policy objectives, and other issues. </Description><OtherInformation>NISTIR 8074 Volume 2, Supplemental Information for the Report on Strategic U.S. Government Engagement in International Standardization to Achieve U.S. Objectives for Cybersecurity provides additional background on 
international cybersecurity standardization. </OtherInformation><StrategicPlanCore><Organization><Name>National Institute of Standards and Technology</Name><Acronym>NIST</Acronym><Identifier>_36a9a026-66b6-11e0-86fc-e93d7a64ea2a</Identifier><Description/><Stakeholder StakeholderTypeType="Person"><Name>Michael Hogan</Name><Description>Editor</Description></Stakeholder><Stakeholder StakeholderTypeType="Person"><Name>Elaine Newton</Name><Description>Editor</Description></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>Information Technology Laboratory</Name><Description>Office of the Director -- 
The Information Technology Laboratory (ITL) at the National Institute of Standards and Technology (NIST) promotes the U.S. economy and public welfare by providing technical leadership for the Nation's measurement and standards infrastructure. ITL develops tests, test methods, reference data, proof of concept implementations, and technical analyses to advance the development and productive use of information technology. ITL's responsibilities include the development of management, administrative, technical, and physical standards and guidelines for the cost-effective security and privacy of other than national security-related information in Federal information systems. </Description></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>Standards Developing Organizations</Name><Description>Cybersecurity relies upon a diverse set of standards including standards whose scopes are specific to one or more attributes of cybersecurity and standards from other domains that are relevant to cybersecurity.  The U.S. standardization community is comprised largely of non-governmental Standards Developing Organizations (SDOs). These groups are primarily shaped by industry participation and are motivated by market forces. USG participation is motivated by the need to achieve cost-efficient, timely and effective solutions for mission and policy objectives. These diverse motivations are mutually beneficial. </Description></Stakeholder></Organization><Vision><Description/><Identifier>_74ac74ce-4c72-11e5-87ab-b150e89d703b</Identifier></Vision><Mission><Description>To sets out proposed United States Government (USG) strategic objectives for pursuing the development and use of international standards for cybersecurity ...</Description><Identifier>_74ac7654-4c72-11e5-87ab-b150e89d703b</Identifier></Mission><Value><Name>Cybersecurity</Name><Description>Cybersecurity is the prevention of damage to, unauthorized use of, or exploitation of, and, if needed, the restoration of electronic information and communications systems and the information contained therein to ensure confidentiality, integrity, and availability.</Description></Value><Value><Name>Resilience</Name><Description>Resilience is the ability of both the private sector and the government to reduce the magnitude and/or duration of disruptive events to critical infrastructure. The effectiveness of a resilient infrastructure or enterprise depends upon its ability to anticipate, absorb, adapt to, and/or rapidly recover from a potentially disruptive event.</Description></Value><Goal><Name>Security &amp; Safety</Name><Description>Enhance National and Economic Security and Public Safety</Description><Identifier>_74ac7712-4c72-11e5-87ab-b150e89d703b</Identifier><SequenceIndicator>1</SequenceIndicator><Stakeholder StakeholderTypeType=""><Name/><Description/></Stakeholder><OtherInformation/><Objective><Name>Inventory</Name><Description>Ensure there is a sufficient inventory of international standards that can serve as a basis for the cybersecurity and resiliency of U.S. organizations, particularly critical infrastructure.</Description><Identifier>_74ac77a8-4c72-11e5-87ab-b150e89d703b</Identifier><SequenceIndicator>1.1</SequenceIndicator><Stakeholder StakeholderTypeType=""><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Procurement</Name><Description>Use international standards as a key part of USG procurement policy to support secure and resilient operations.</Description><Identifier>_74ac785c-4c72-11e5-87ab-b150e89d703b</Identifier><SequenceIndicator>1.2</SequenceIndicator><Stakeholder StakeholderTypeType=""><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>USG Interests</Name><Description>Ensure that international standards meet the cybersecurity interests of the USG including protecting against illicit cyber activities or actions by terrorist groups and hostile nation-state actors. </Description><Identifier>_74ac78fc-4c72-11e5-87ab-b150e89d703b</Identifier><SequenceIndicator>1.3</SequenceIndicator><Stakeholder StakeholderTypeType=""><Name/><Description/></Stakeholder><OtherInformation/></Objective></Goal><Goal><Name>Standards &amp; Assessment Tools</Name><Description>Ensure standards and assessment tools for the USG are Technically Sound</Description><Identifier>_74ac799c-4c72-11e5-87ab-b150e89d703b</Identifier><SequenceIndicator>2</SequenceIndicator><Stakeholder StakeholderTypeType=""><Name/><Description/></Stakeholder><OtherInformation/><Objective><Name>Development &amp; Use</Name><Description>Support the development and use of new standards by taking into account: the scope of standardization work of candidate SDOs, U.S. industry preferences, USG needs, and the recent track record of candidate SDOs in particular areas of cybersecurity standardization. </Description><Identifier>_74ac7a50-4c72-11e5-87ab-b150e89d703b</Identifier><SequenceIndicator>2.1</SequenceIndicator><Stakeholder StakeholderTypeType=""><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Soundness &amp; Fitness</Name><Description>Developing technically sound and fit for purpose standards in open, transparent, and consensus-based processes, and updating as often as necessary in collaboration with the private sector. </Description><Identifier>_74ac7af0-4c72-11e5-87ab-b150e89d703b</Identifier><SequenceIndicator>2.2</SequenceIndicator><Stakeholder StakeholderTypeType=""><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Coordination</Name><Description>Supporting coordination among SDOs to avoid duplication, promote interoperability, maximize the utility of standards projects, and extend the field of application for existing standards. </Description><Identifier>_74ac7b9a-4c72-11e5-87ab-b150e89d703b</Identifier><SequenceIndicator>2.3</SequenceIndicator><Stakeholder StakeholderTypeType="Generic_Group"><Name>SDOs</Name><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Assessment Tools</Name><Description>Support the development and use of associated assessment tools (e.g., reference  implementations, conformance and interoperability test suites) to complement timely, technically-sound standards development. </Description><Identifier>_74ac7c4e-4c72-11e5-87ab-b150e89d703b</Identifier><SequenceIndicator>2.4</SequenceIndicator><Stakeholder StakeholderTypeType="Generic_Group"><Name/><Description/></Stakeholder><OtherInformation/></Objective></Goal><Goal><Name>International Trade</Name><Description>Facilitate International Trade</Description><Identifier>_74ac7cee-4c72-11e5-87ab-b150e89d703b</Identifier><SequenceIndicator>3</SequenceIndicator><Stakeholder StakeholderTypeType=""><Name/><Description/></Stakeholder><OtherInformation/><Objective><Name>Standards &amp; Assessments</Name><Description>Support the development and use of international standards and associated assessment schemes for cybersecurity (where relevant, effective, and appropriate), which can promote international trade and provide a level playing field for U.S. companies. </Description><Identifier>_74ac7da2-4c72-11e5-87ab-b150e89d703b</Identifier><SequenceIndicator>3.1</SequenceIndicator><Stakeholder StakeholderTypeType="Generic_Group"><Name>U.S. Companies</Name><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Market Relevance</Name><Description>Ensure market relevance by developing standards in response to industry, government and consumer requirements and timelines.</Description><Identifier>_74ac7e60-4c72-11e5-87ab-b150e89d703b</Identifier><SequenceIndicator>3.2</SequenceIndicator><Stakeholder StakeholderTypeType="Generic_Group"><Name/><Description/></Stakeholder><OtherInformation/></Objective></Goal><Goal><Name>Innovation &amp; Competitiveness</Name><Description>Promote Innovation and Competitiveness</Description><Identifier>_74ac7f0a-4c72-11e5-87ab-b150e89d703b</Identifier><SequenceIndicator>4</SequenceIndicator><Stakeholder StakeholderTypeType=""><Name/><Description/></Stakeholder><OtherInformation/><Objective><Name>Collaboration</Name><Description>Support the development and use of international standards in collaboration with U.S. industry, to foster open and fair competition. </Description><Identifier>_74ac7fbe-4c72-11e5-87ab-b150e89d703b</Identifier><SequenceIndicator>4.1</SequenceIndicator><Stakeholder StakeholderTypeType="Generic_Group"><Name>U.S. industry</Name><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Competitiveness &amp; Equities</Name><Description>Promote the inclusion of existing and emerging technologies in international standards that boost U.S. competitiveness and ensuring that USG equities are well represented in those standards.
</Description><Identifier>_74ac80b8-4c72-11e5-87ab-b150e89d703b</Identifier><SequenceIndicator>4.2</SequenceIndicator><Stakeholder StakeholderTypeType="Generic_Group"><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Performance Standards</Name><Description>Encourage the development and use of performance standards for cybersecurity, where appropriate.</Description><Identifier>_74ac816c-4c72-11e5-87ab-b150e89d703b</Identifier><SequenceIndicator>4.3</SequenceIndicator><Stakeholder StakeholderTypeType="Generic_Group"><Name/><Description/></Stakeholder><OtherInformation>Performance standards generally are more likely to encourage innovation and enable competition than prescriptive design standards. Prescriptive design standards are sometimes necessary, however, particularly for describing test methods or procedures.</OtherInformation></Objective></Goal></StrategicPlanCore><AdministrativeInformation><PublicationDate>2015-08-26</PublicationDate><Source>http://csrc.nist.gov/publications/drafts/nistir-8074/nistir_8074_vol1_draft_report.pdf</Source><Submitter><GivenName>Owen</GivenName><Surname>Ambur</Surname><PhoneNumber/><EmailAddress>Owen.Ambur@verizon.net</EmailAddress></Submitter></AdministrativeInformation></StrategicPlan>