"Enhance open-source software security" and "publish guidance to help agencies secure open source software" are not the same thing.
To accomplish the former file vulnerability reports, submit patches, sponsor bug-bounties, etc. The latter is just ordinary vulnerability management, for which a CISA already has a directive. For those of us in private industry, stay up to date on patching and keep tabs on the software's reputation.