{"id":3907,"date":"2022-12-07T05:31:16","date_gmt":"2022-12-07T05:31:16","guid":{"rendered":"https:\/\/itegriti.com\/kw022024\/?p=3907"},"modified":"2022-12-21T14:46:36","modified_gmt":"2022-12-21T14:46:36","slug":"cisa-releases-cross-sector-cybersecurity-performance-goals-to-assist-critical-infrastructure-organizations","status":"publish","type":"post","link":"https:\/\/itegriti.com\/kw022024\/2022\/compliance\/cisa-releases-cross-sector-cybersecurity-performance-goals-to-assist-critical-infrastructure-organizations\/","title":{"rendered":"CISA Releases Cross-Sector Cybersecurity Performance Goals to Assist Critical Infrastructure Organizations"},"content":{"rendered":"<div class=\"fusion-fullwidth fullwidth-box fusion-builder-row-1 fusion-flex-container has-pattern-background has-mask-background nonhundred-percent-fullwidth non-hundred-percent-height-scrolling\" style=\"--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-flex-wrap:wrap;\" ><div class=\"fusion-builder-row fusion-row fusion-flex-align-items-flex-start fusion-flex-content-wrap\" style=\"max-width:1216.8px;margin-left: calc(-4% \/ 2 );margin-right: calc(-4% \/ 2 );\"><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-0 fusion_builder_column_1_1 1_1 fusion-flex-column\" style=\"--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:0px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:40px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-text fusion-text-1\"><p><em>Summary: CISA in cooperation with NIST and the interagency community released baseline <a href=\"https:\/\/www.cisa.gov\/cpg\" target=\"_blank\" rel=\"noopener\">Cybersecurity Cross-Sector Performance Goals<\/a><\/em><em> which are intended to help establish a common set of fundamental cybersecurity practices for critical infrastructure, and especially help small- and medium-sized organizations kickstart their cybersecurity efforts.\u00a0\u00a0<\/em><\/p>\n<h2>Background and motivation<\/h2>\n<p>Unfortunately, it is no secret that the critical infrastructure sector in the United States does not implement enough levels of basic cybersecurity standards. There is no theoretical or philosophical basis for this worry. U.S. citizens have felt the effects of these lapses firsthand, whether it is ransomware attacks on hospitals or school districts or sophisticated nation-state operations on government institutions and essential infrastructure. The national security, economic security, and health and safety of the American people are all at stake as a result of these invasions.<\/p>\n<p>\u201cWe have heard a common refrain from organizations across the spectrum, from the largest multinational corporations to state and local governments, to critical infrastructure entities of all sizes: How can we focus investment toward the most impactful security outcomes?\u201d notes Jen Easterly, CISA Director.<\/p>\n<p>\u201cIt became clear that even with comprehensive guidance from sources like the NIST Cybersecurity Framework, many organizations would benefit from help identifying and prioritizing the most important cybersecurity practices along with support in making a compelling argument to ensure adequate resources for driving down risk,\u201d Easterly explains.<\/p>\n<p>In response to these concerns, President Biden signed in July 2021 the <a href=\"https:\/\/www.whitehouse.gov\/briefing-room\/presidential-actions\/2021\/07\/28\/national-security-memorandum-on-improving-cybersecurity-for-critical-infrastructure-control-systems\/\" target=\"_blank\" rel=\"noopener\">National Security Memorandum on Improving Cybersecurity for Critical Infrastructure Control Systems<\/a>. This memorandum required CISA, in coordination with NIST and the interagency community, to develop baseline cybersecurity goals that are consistent across all critical infrastructure sectors.<\/p>\n<h2>What are the Cross-Sector Cybersecurity Performance Goals?<\/h2>\n<p>The <a href=\"https:\/\/www.cisa.gov\/sites\/default\/files\/publications\/2022_00092_CISA_CPG_Report_508c.pdf\" target=\"_blank\" rel=\"noopener\">Cross-Sector Cybersecurity Performance Goals<\/a> (CPGs) are a prioritized subset of cybersecurity practices for operational technology (OT) and information technology (IT) that owners and operators of critical infrastructure can use to significantly lower the likelihood and impact of known risks and adversary tactics. The objectives were influenced by current cybersecurity frameworks and recommendations as well as the threats and adversary tactics, methods, and procedures (TTPs) that CISA and its government and business partners had to deal with in the real world.<\/p>\n<p>According to the CISA CPG website, the document is intended to be:<\/p>\n<ul>\n<li>A baseline set of cybersecurity practices broadly applicable across the critical infrastructure with known risk-reduction value.<\/li>\n<li>A benchmark for critical infrastructure operators to measure and improve their cybersecurity maturity.<\/li>\n<li>A combination of recommended practices for IT and OT owners, including a prioritized set of security practices.<\/li>\n<li>Unique from other control frameworks as they consider not only the practices that address the risk to individual entities, but also the aggregate risk to the nation.<\/li>\n<\/ul>\n<p>The CPGs are intended to supplement the\u202fNIST Cybersecurity Framework (CSF)\u202ffor organizations seeking assistance in prioritizing investment toward a limited number of high-impact security outcomes, whether due to gaps in expertise, resources, or capabilities or to enable focused improvements across suppliers, vendors, business partners, or customers.<\/p>\n<p>In addition, CISA clarifies that the CPGs are:<\/p>\n<ul>\n<li>Voluntary: Critical infrastructure owners and operators are not compelled to adopt the CPGs or provide any reporting regarding or related to the CPGs to any government agency.<\/li>\n<li>Not Comprehensive. They do not identify all the cybersecurity practices needed to protect national and economic security and public health and safety. They capture a core set of cybersecurity practices with known risk-reduction value broadly applicable across sectors.<\/li>\n<\/ul>\n<h2>Which areas do the CPGs cover?<\/h2>\n<p>The CPGs cover the following eight cybersecurity areas:<\/p>\n<ol>\n<li><strong>Account Security<\/strong>, focusing on access management and credential lifecycle best practices, including (of course) multi-factor authentication.<\/li>\n<li><strong>Device Security<\/strong>, looking at asset management, documented device configuration, a hardware and software approval process, and more.<\/li>\n<li><strong>Data Security<\/strong>, where data encryption and safeguarding sensitive data play a key role.<\/li>\n<li><strong>Governance and Training<\/strong>, which covers leadership, roles, and responsibilities, and raising awareness through recurrent training.<\/li>\n<li><strong>Vulnerability Management<\/strong>, which includes an extensive list of actions from mitigating known vulnerabilities to limiting connections of OT to the internet to using security.txt files.<\/li>\n<li><strong>Supply Chain\/Third Party<\/strong>, to include vulnerability disclosure and incident, but surprisingly not SBOM.<\/li>\n<li><strong>Response and Recovery<\/strong>, focusing on incident response plans and backups.<\/li>\n<li><strong>Other<\/strong>, which includes network segmentation and email security.<\/li>\n<\/ol>\n<p>Interestingly, the CPGs move beyond traditional security measures to also highlight the importance of building relationships among team members. For example, item 4.5 (under Governance and Training) mentions \u201cOrganizations sponsor at least one \u2018pizza party\u2019 or equivalent social gathering per year that is focused on strengthening working relationships between IT and OT security personnel and is not a working event (such as providing meals during an incident response).\u201d<\/p>\n<p>What sets the CPGs apart from other benchmarks is that these goals were selected to address risks to the nation as well as individual entities. The CPGs can be leveraged by organizations as part of a broader cybersecurity program based on the NIST CSF or other frameworks and standards. The CPGs can help organizations that may lack the cybersecurity experience, resources, or structure in place to quickly identify and implement basic cybersecurity practices. The CPGs contain a <a href=\"https:\/\/www.cisa.gov\/sites\/default\/files\/publications\/CISA_CPG_CHECKLIST_508c.pdf\" target=\"_blank\" rel=\"noopener\">worksheet<\/a> that can help organizations with smaller or less mature cybersecurity programs prioritize which protections to implement, and communicate the importance and relative impact and cost of those protections to (non-technical) executives.<\/p>\n<p>Overall, the CISA CPGs are a great start and a great baseline for every critical infrastructure business to implement. Want to discuss this topic with one of our experts? Please visit our <a href=\"https:\/\/itegriti.com\/kw022024\/contact\/\">Contact Us<\/a> page to request more information or connect with a Subject Matter Expert (SME).<\/p>\n<\/div><\/div><\/div><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"","protected":false},"author":10,"featured_media":3928,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2179],"tags":[2188,2193,2192,2195],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v22.0 (Yoast SEO v23.5) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>CISA Releases Cross-Sector Cybersecurity Performance Goals to Assist Critical Infrastructure Organizations<\/title>\n<meta name=\"description\" content=\"CISA in cooperation with NIST released baseline Cybersecurity Cross-Sector Performance Goals to establish a set of cybersecurity practices.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/itegriti.com\/kw022024\/2022\/compliance\/cisa-releases-cross-sector-cybersecurity-performance-goals-to-assist-critical-infrastructure-organizations\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"CISA Releases Cross-Sector Cybersecurity Performance Goals to Assist Critical Infrastructure Organizations\" \/>\n<meta property=\"og:description\" content=\"CISA in cooperation with NIST released baseline Cybersecurity Cross-Sector Performance Goals to establish a set of cybersecurity practices.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/itegriti.com\/kw022024\/2022\/compliance\/cisa-releases-cross-sector-cybersecurity-performance-goals-to-assist-critical-infrastructure-organizations\/\" \/>\n<meta property=\"og:site_name\" content=\"kw022024\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/itegriti\" \/>\n<meta property=\"article:published_time\" content=\"2022-12-07T05:31:16+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-12-21T14:46:36+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/itegriti.com\/kw022024\/wp-content\/uploads\/2022\/12\/Untitled-design.png\" \/>\n\t<meta property=\"og:image:width\" content=\"800\" \/>\n\t<meta property=\"og:image:height\" content=\"450\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Anastasios Arampatzis\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@TassosAramp\" \/>\n<meta name=\"twitter:site\" content=\"@itegriti\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Anastasios Arampatzis\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/itegriti.com\/kw022024\/2022\/compliance\/cisa-releases-cross-sector-cybersecurity-performance-goals-to-assist-critical-infrastructure-organizations\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/itegriti.com\/kw022024\/2022\/compliance\/cisa-releases-cross-sector-cybersecurity-performance-goals-to-assist-critical-infrastructure-organizations\/\"},\"author\":{\"name\":\"Anastasios Arampatzis\",\"@id\":\"https:\/\/itegriti.com\/kw022024\/#\/schema\/person\/6fa12fbccd5abc86c2ce14ffbb619673\"},\"headline\":\"CISA Releases Cross-Sector Cybersecurity Performance Goals to Assist Critical Infrastructure Organizations\",\"datePublished\":\"2022-12-07T05:31:16+00:00\",\"dateModified\":\"2022-12-21T14:46:36+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/itegriti.com\/kw022024\/2022\/compliance\/cisa-releases-cross-sector-cybersecurity-performance-goals-to-assist-critical-infrastructure-organizations\/\"},\"wordCount\":1685,\"publisher\":{\"@id\":\"https:\/\/itegriti.com\/kw022024\/#organization\"},\"image\":{\"@id\":\"https:\/\/itegriti.com\/kw022024\/2022\/compliance\/cisa-releases-cross-sector-cybersecurity-performance-goals-to-assist-critical-infrastructure-organizations\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/itegriti.com\/kw022024\/wp-content\/uploads\/2022\/12\/Untitled-design.png\",\"keywords\":[\"Cybersecurity\",\"Energy Sector\",\"Finance Sector\",\"Water Sector\"],\"articleSection\":[\"Compliance\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/itegriti.com\/kw022024\/2022\/compliance\/cisa-releases-cross-sector-cybersecurity-performance-goals-to-assist-critical-infrastructure-organizations\/\",\"url\":\"https:\/\/itegriti.com\/kw022024\/2022\/compliance\/cisa-releases-cross-sector-cybersecurity-performance-goals-to-assist-critical-infrastructure-organizations\/\",\"name\":\"CISA Releases Cross-Sector Cybersecurity Performance Goals to Assist Critical Infrastructure Organizations\",\"isPartOf\":{\"@id\":\"https:\/\/itegriti.com\/kw022024\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/itegriti.com\/kw022024\/2022\/compliance\/cisa-releases-cross-sector-cybersecurity-performance-goals-to-assist-critical-infrastructure-organizations\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/itegriti.com\/kw022024\/2022\/compliance\/cisa-releases-cross-sector-cybersecurity-performance-goals-to-assist-critical-infrastructure-organizations\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/itegriti.com\/kw022024\/wp-content\/uploads\/2022\/12\/Untitled-design.png\",\"datePublished\":\"2022-12-07T05:31:16+00:00\",\"dateModified\":\"2022-12-21T14:46:36+00:00\",\"description\":\"CISA in cooperation with NIST released baseline Cybersecurity Cross-Sector Performance Goals to establish a set of cybersecurity practices.\",\"breadcrumb\":{\"@id\":\"https:\/\/itegriti.com\/kw022024\/2022\/compliance\/cisa-releases-cross-sector-cybersecurity-performance-goals-to-assist-critical-infrastructure-organizations\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/itegriti.com\/kw022024\/2022\/compliance\/cisa-releases-cross-sector-cybersecurity-performance-goals-to-assist-critical-infrastructure-organizations\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/itegriti.com\/kw022024\/2022\/compliance\/cisa-releases-cross-sector-cybersecurity-performance-goals-to-assist-critical-infrastructure-organizations\/#primaryimage\",\"url\":\"https:\/\/itegriti.com\/kw022024\/wp-content\/uploads\/2022\/12\/Untitled-design.png\",\"contentUrl\":\"https:\/\/itegriti.com\/kw022024\/wp-content\/uploads\/2022\/12\/Untitled-design.png\",\"width\":800,\"height\":450},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/itegriti.com\/kw022024\/2022\/compliance\/cisa-releases-cross-sector-cybersecurity-performance-goals-to-assist-critical-infrastructure-organizations\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/itegriti.com\/kw022024\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"CISA Releases Cross-Sector Cybersecurity Performance Goals to Assist Critical Infrastructure Organizations\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/itegriti.com\/kw022024\/#website\",\"url\":\"https:\/\/itegriti.com\/kw022024\/\",\"name\":\"ITEGRITI\",\"description\":\"cybersecurity | compliance | managed services\",\"publisher\":{\"@id\":\"https:\/\/itegriti.com\/kw022024\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/itegriti.com\/kw022024\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/itegriti.com\/kw022024\/#organization\",\"name\":\"ITEGRITI CORPORATION | Cybersecurity | Compliance | Managed Services\",\"url\":\"https:\/\/itegriti.com\/kw022024\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/itegriti.com\/kw022024\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/itegriti.com\/kw022024\/wp-content\/uploads\/2016\/06\/ItegritiLogo_600x100.png\",\"contentUrl\":\"https:\/\/itegriti.com\/kw022024\/wp-content\/uploads\/2016\/06\/ItegritiLogo_600x100.png\",\"width\":600,\"height\":100,\"caption\":\"ITEGRITI CORPORATION | Cybersecurity | Compliance | Managed Services\"},\"image\":{\"@id\":\"https:\/\/itegriti.com\/kw022024\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/itegriti\",\"https:\/\/x.com\/itegriti\",\"https:\/\/www.linkedin.com\/company\/itegriti\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/itegriti.com\/kw022024\/#\/schema\/person\/6fa12fbccd5abc86c2ce14ffbb619673\",\"name\":\"Anastasios Arampatzis\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/itegriti.com\/kw022024\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/adff645e812a27c2d07dd3c43fc9cd32?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/adff645e812a27c2d07dd3c43fc9cd32?s=96&d=mm&r=g\",\"caption\":\"Anastasios Arampatzis\"},\"description\":\"Anastasios Arampatzis is a retired Hellenic Air Force officer with over 20 years\u2019 worth of experience in managing IT projects and evaluating cybersecurity. During his service in the Armed Forces, he was assigned to various key positions in national, NATO and EU headquarters and has been honoured by numerous high-ranking officers for his expertise and professionalism. He was nominated as a certified NATO evaluator for information security. Anastasios\u2019 interests include among others cybersecurity policy and governance, ICS and IoT security, encryption, and certificates management. He is also exploring the human side of cybersecurity - the psychology of security, public education, organizational training programs, and the effect of biases (cultural, heuristic and cognitive) in applying cybersecurity policies and integrating technology into learning. He is intrigued by new challenges, open-minded and flexible. Currently, he works as a cybersecurity content writer for Bora - IT Security Marketing. Tassos is a member of the non-profit organization Homo Digitalis.\",\"sameAs\":[\"http:\/\/www.welcometobora.com\",\"https:\/\/www.linkedin.com\/in\/anastasiosarampatzis\/\",\"https:\/\/x.com\/TassosAramp\"],\"url\":\"https:\/\/itegriti.com\/kw022024\/author\/anastasios-arampatiz\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"CISA Releases Cross-Sector Cybersecurity Performance Goals to Assist Critical Infrastructure Organizations","description":"CISA in cooperation with NIST released baseline Cybersecurity Cross-Sector Performance Goals to establish a set of cybersecurity practices.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/itegriti.com\/kw022024\/2022\/compliance\/cisa-releases-cross-sector-cybersecurity-performance-goals-to-assist-critical-infrastructure-organizations\/","og_locale":"en_US","og_type":"article","og_title":"CISA Releases Cross-Sector Cybersecurity Performance Goals to Assist Critical Infrastructure Organizations","og_description":"CISA in cooperation with NIST released baseline Cybersecurity Cross-Sector Performance Goals to establish a set of cybersecurity practices.","og_url":"https:\/\/itegriti.com\/kw022024\/2022\/compliance\/cisa-releases-cross-sector-cybersecurity-performance-goals-to-assist-critical-infrastructure-organizations\/","og_site_name":"kw022024","article_publisher":"https:\/\/www.facebook.com\/itegriti","article_published_time":"2022-12-07T05:31:16+00:00","article_modified_time":"2022-12-21T14:46:36+00:00","og_image":[{"width":800,"height":450,"url":"https:\/\/itegriti.com\/kw022024\/wp-content\/uploads\/2022\/12\/Untitled-design.png","type":"image\/png"}],"author":"Anastasios Arampatzis","twitter_card":"summary_large_image","twitter_creator":"@TassosAramp","twitter_site":"@itegriti","twitter_misc":{"Written by":"Anastasios Arampatzis","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/itegriti.com\/kw022024\/2022\/compliance\/cisa-releases-cross-sector-cybersecurity-performance-goals-to-assist-critical-infrastructure-organizations\/#article","isPartOf":{"@id":"https:\/\/itegriti.com\/kw022024\/2022\/compliance\/cisa-releases-cross-sector-cybersecurity-performance-goals-to-assist-critical-infrastructure-organizations\/"},"author":{"name":"Anastasios Arampatzis","@id":"https:\/\/itegriti.com\/kw022024\/#\/schema\/person\/6fa12fbccd5abc86c2ce14ffbb619673"},"headline":"CISA Releases Cross-Sector Cybersecurity Performance Goals to Assist Critical Infrastructure Organizations","datePublished":"2022-12-07T05:31:16+00:00","dateModified":"2022-12-21T14:46:36+00:00","mainEntityOfPage":{"@id":"https:\/\/itegriti.com\/kw022024\/2022\/compliance\/cisa-releases-cross-sector-cybersecurity-performance-goals-to-assist-critical-infrastructure-organizations\/"},"wordCount":1685,"publisher":{"@id":"https:\/\/itegriti.com\/kw022024\/#organization"},"image":{"@id":"https:\/\/itegriti.com\/kw022024\/2022\/compliance\/cisa-releases-cross-sector-cybersecurity-performance-goals-to-assist-critical-infrastructure-organizations\/#primaryimage"},"thumbnailUrl":"https:\/\/itegriti.com\/kw022024\/wp-content\/uploads\/2022\/12\/Untitled-design.png","keywords":["Cybersecurity","Energy Sector","Finance Sector","Water Sector"],"articleSection":["Compliance"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/itegriti.com\/kw022024\/2022\/compliance\/cisa-releases-cross-sector-cybersecurity-performance-goals-to-assist-critical-infrastructure-organizations\/","url":"https:\/\/itegriti.com\/kw022024\/2022\/compliance\/cisa-releases-cross-sector-cybersecurity-performance-goals-to-assist-critical-infrastructure-organizations\/","name":"CISA Releases Cross-Sector Cybersecurity Performance Goals to Assist Critical Infrastructure Organizations","isPartOf":{"@id":"https:\/\/itegriti.com\/kw022024\/#website"},"primaryImageOfPage":{"@id":"https:\/\/itegriti.com\/kw022024\/2022\/compliance\/cisa-releases-cross-sector-cybersecurity-performance-goals-to-assist-critical-infrastructure-organizations\/#primaryimage"},"image":{"@id":"https:\/\/itegriti.com\/kw022024\/2022\/compliance\/cisa-releases-cross-sector-cybersecurity-performance-goals-to-assist-critical-infrastructure-organizations\/#primaryimage"},"thumbnailUrl":"https:\/\/itegriti.com\/kw022024\/wp-content\/uploads\/2022\/12\/Untitled-design.png","datePublished":"2022-12-07T05:31:16+00:00","dateModified":"2022-12-21T14:46:36+00:00","description":"CISA in cooperation with NIST released baseline Cybersecurity Cross-Sector Performance Goals to establish a set of cybersecurity practices.","breadcrumb":{"@id":"https:\/\/itegriti.com\/kw022024\/2022\/compliance\/cisa-releases-cross-sector-cybersecurity-performance-goals-to-assist-critical-infrastructure-organizations\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/itegriti.com\/kw022024\/2022\/compliance\/cisa-releases-cross-sector-cybersecurity-performance-goals-to-assist-critical-infrastructure-organizations\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/itegriti.com\/kw022024\/2022\/compliance\/cisa-releases-cross-sector-cybersecurity-performance-goals-to-assist-critical-infrastructure-organizations\/#primaryimage","url":"https:\/\/itegriti.com\/kw022024\/wp-content\/uploads\/2022\/12\/Untitled-design.png","contentUrl":"https:\/\/itegriti.com\/kw022024\/wp-content\/uploads\/2022\/12\/Untitled-design.png","width":800,"height":450},{"@type":"BreadcrumbList","@id":"https:\/\/itegriti.com\/kw022024\/2022\/compliance\/cisa-releases-cross-sector-cybersecurity-performance-goals-to-assist-critical-infrastructure-organizations\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/itegriti.com\/kw022024\/"},{"@type":"ListItem","position":2,"name":"CISA Releases Cross-Sector Cybersecurity Performance Goals to Assist Critical Infrastructure Organizations"}]},{"@type":"WebSite","@id":"https:\/\/itegriti.com\/kw022024\/#website","url":"https:\/\/itegriti.com\/kw022024\/","name":"ITEGRITI","description":"cybersecurity | compliance | managed services","publisher":{"@id":"https:\/\/itegriti.com\/kw022024\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/itegriti.com\/kw022024\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/itegriti.com\/kw022024\/#organization","name":"ITEGRITI CORPORATION | Cybersecurity | Compliance | Managed Services","url":"https:\/\/itegriti.com\/kw022024\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/itegriti.com\/kw022024\/#\/schema\/logo\/image\/","url":"https:\/\/itegriti.com\/kw022024\/wp-content\/uploads\/2016\/06\/ItegritiLogo_600x100.png","contentUrl":"https:\/\/itegriti.com\/kw022024\/wp-content\/uploads\/2016\/06\/ItegritiLogo_600x100.png","width":600,"height":100,"caption":"ITEGRITI CORPORATION | Cybersecurity | Compliance | Managed Services"},"image":{"@id":"https:\/\/itegriti.com\/kw022024\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/itegriti","https:\/\/x.com\/itegriti","https:\/\/www.linkedin.com\/company\/itegriti\/"]},{"@type":"Person","@id":"https:\/\/itegriti.com\/kw022024\/#\/schema\/person\/6fa12fbccd5abc86c2ce14ffbb619673","name":"Anastasios Arampatzis","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/itegriti.com\/kw022024\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/adff645e812a27c2d07dd3c43fc9cd32?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/adff645e812a27c2d07dd3c43fc9cd32?s=96&d=mm&r=g","caption":"Anastasios Arampatzis"},"description":"Anastasios Arampatzis is a retired Hellenic Air Force officer with over 20 years\u2019 worth of experience in managing IT projects and evaluating cybersecurity. During his service in the Armed Forces, he was assigned to various key positions in national, NATO and EU headquarters and has been honoured by numerous high-ranking officers for his expertise and professionalism. He was nominated as a certified NATO evaluator for information security. Anastasios\u2019 interests include among others cybersecurity policy and governance, ICS and IoT security, encryption, and certificates management. He is also exploring the human side of cybersecurity - the psychology of security, public education, organizational training programs, and the effect of biases (cultural, heuristic and cognitive) in applying cybersecurity policies and integrating technology into learning. He is intrigued by new challenges, open-minded and flexible. Currently, he works as a cybersecurity content writer for Bora - IT Security Marketing. Tassos is a member of the non-profit organization Homo Digitalis.","sameAs":["http:\/\/www.welcometobora.com","https:\/\/www.linkedin.com\/in\/anastasiosarampatzis\/","https:\/\/x.com\/TassosAramp"],"url":"https:\/\/itegriti.com\/kw022024\/author\/anastasios-arampatiz\/"}]}},"_links":{"self":[{"href":"https:\/\/itegriti.com\/kw022024\/wp-json\/wp\/v2\/posts\/3907"}],"collection":[{"href":"https:\/\/itegriti.com\/kw022024\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/itegriti.com\/kw022024\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/itegriti.com\/kw022024\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/itegriti.com\/kw022024\/wp-json\/wp\/v2\/comments?post=3907"}],"version-history":[{"count":2,"href":"https:\/\/itegriti.com\/kw022024\/wp-json\/wp\/v2\/posts\/3907\/revisions"}],"predecessor-version":[{"id":3910,"href":"https:\/\/itegriti.com\/kw022024\/wp-json\/wp\/v2\/posts\/3907\/revisions\/3910"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/itegriti.com\/kw022024\/wp-json\/wp\/v2\/media\/3928"}],"wp:attachment":[{"href":"https:\/\/itegriti.com\/kw022024\/wp-json\/wp\/v2\/media?parent=3907"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/itegriti.com\/kw022024\/wp-json\/wp\/v2\/categories?post=3907"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/itegriti.com\/kw022024\/wp-json\/wp\/v2\/tags?post=3907"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}