The Department of Homeland Security released a list of cybersecurity performance goals and metrics designed by the Cybersecurity & Infrastructure Security Agency (CISA) to help drive cybersecurity best practices across the private sector.
The CISA works daily with government, private sector, and international partners to gain unique insights into cybersecurity across the US.
The Cross-Sector Cybersecurity Performance Goals document includes a list of best practices for securing accounts, devices, and data, vulnerability management, governance, the supply chain, and recovery. This list of cybersecurity good practices comes in answer to the fact that there are still significant gaps in the National Cybersecurity landscape:
Lacking foundational measures and basic protections such as multi-factor authentication (MFA), strong password management, and backups exposes organizations to cyber intrusions.
Primarily because of limited resources, they often need help knowing where to start to protect themselves in reasonable and sustainable ways.
Organizations have been ignoring operational technology as a rising attack surface, and cybersecurity standards across different sectors need to be more consistent or better.
The CISA puts it this way "the CPGs are a prioritized subset of IT and OT cybersecurity practices aimed at meaningfully reducing risks to both CI operations and the American people." CPGs are divided into eight sections: Account Security, Device Security, Data Security, Governance and Training, Vulnerability Management, Supply Chain / Third Party, Response and Recovery, and Others.
Here is an example from the Cross-Sector Cybersecurity Performance Goals Report:
Book a free cybersecurity audit to make the right decision for your organization.