CISA Released their First Ever Cross-Sector Cyber Performance Goals. What's Inside?
CISA has finally released its highly anticipated Cross-Sector Cybersecurity Performance Goals in collaboration with DHS, NIST and numerous industry leaders.
??The Performance Goals (or CPGs) come as a response to National Security Memorandum (NSM)-5 which?President Biden signed in 2021 , instructing CISA to develop baseline cybersecurity goals that are consistent across all critical infrastructure sectors.
At the time,?geopolitical tensions had risen precipitously , and the US was looking to shore up its critical infrastructure against digital attacks from foreign actors like?Russia ,?China , and?North Korea .
What are the CPGs?
The CPGs are a prioritized list of cybersecurity practices that combat the most common and impactful security threats, specifically those facing?critical infrastructure entities . The framework incorporates both IT and OT, and is designed to function in tandem with broader cybersecurity frameworks such as the NIST CSF.
The framework is divided into 8 categories, covering issues ranging from Data Security and Vulnerability Management to Governance and Incident Response. Each category is further broken down into a series of best practices, along with detailed goals, scope, recommended actions, and NIST mapping. Along with the CPGs themselves, CISA released a workbook to help?guide organizations during the implementation process , as well as a data matrix that contains all the raw CPG data and mappings to other leading frameworks.
What the CPGs are not
Comprehensive
Risk Management
Mandatory
Areas of Focus
领英推荐
Authentication
People
Attack Surface Management
Incident Response
To view the 2022 Cross-Sector Cybersecurity Performance Goals in their entirety, visit?https://www.cisa.gov/cpg
Silent Breach can assist in understanding your company's posture with respect to the CPGs and guide you in implementing the gaps to meet this new regulation. To learn more, contact?[email protected] ?or visit us at?https://silentbreach.com
Similar Reads:
About Silent Breach:?Silent Breach ?is an award-winning provider of cyber security services. Our global team provides cutting-edge insights and expertise across the Data Center, Enterprise, SME, Retail, Government, Finance, Education, Automotive, Hospitality, Healthcare and IoT industries.
Experienced Information Security Manager, Cybersecurity Professional | Information Assurance ? Risk Management . Security Operations
11 个月I took the training. It aligns very well with the NIST. I had a thought about applying the CPG model to my overarching INFOSEC Policy to see how well the organizational policy aligns to what we say we do in our security control answers. I see a benefit also for organizations to use this as a metrics tool during annual cybersecurity audits.