CISA
Cybersecurity and Infrastructure Security Agency — directives and guidance · CISA (US Department of Homeland Security) · Official site
Binding Operational Directives, Emergency Directives, and cross-sector guidance from the US federal cyber defence agency. The directives bind federal civilian agencies directly; the surrounding catalogue — the Known Exploited Vulnerabilities list, Secure by Design, the Cross-Sector Cybersecurity Performance Goals — is what their contractors and critical-infrastructure operators are measured against in practice.
Timeline
CISA has released an updated version of its insider threat guide containing new insights and recommendations for mitigating both physical and cyber threats related to insider risks. This is a guidanc…
Joint warning from CISA, NSA, and FBI regarding coordinated campaigns by China-based AI companies using industrial-scale knowledge distillation techniques to extract and replicate US AI models. The a…
CISA has published an advisory that presents red team findings and recommendations to assist organizations in assessing security risks, identifying threats, and improving incident response capabiliti…
CISA has released new guidance to assist federal agencies in implementing effective logging, visibility, and operational standards. The guidance is described as foundational and flexible.
CISA, FBI and partner agencies issued a joint warning regarding Gunra ransomware actors actively targeting organizations across multiple critical infrastructure sectors. The advisory alerts organizat…
CISA has published guidance to help federal agencies securely and effectively use open source software. Based on the title alone, this appears to be informational guidance without mandatory complianc…
CISA announced an update to a Software Bill of Materials (SBOM) resource developed in partnership with other organizations. The resource aims to improve transparency, security, and enable risk-inform…
CISA, in collaboration with Australian authorities and other partners, has published guidance on isolating operational technology (OT) and enabling systems in critical infrastructure environments. Th…
Joint advisory from CISA, NSA, FBI and partners warning organizations using Zimbra Collaboration Suite about ongoing malicious threat activity attributed to Russian state-supported threat actors. The…
Sources we monitor
- CISA — news checked 3 hours, 27 minutes ago