Skip to content

CISA

What is CISA?

The Cybersecurity and Infrastructure Security Agency, a US government agency responsible for protecting critical infrastructure from cyber and physical threats.

Compliance and Regulatory

Each of these is named in at least one of the same controls as cisa. The number is how many controls name both.

What the standards actually require on cisa

Requirements naming cisa across 6 standards, quoted from the control text.

If CISA has reason to believe a covered entity experienced a covered cyber incident or made a ransom payment but failed to report, it may request additional information; the entity should respond to confirm whether a reportable event occurred.

CIRCIA-2244b · Response to a CISA Request for Information
FISMA7 controls

44 USC 3553 - Authority and Functions of the Director of OMB + the CISA Director. OMB DIRECTOR AUTHORITY: (a) overseeing agency information security policies + practices;

FISMA-3553-OMB-CISA-BOD · OMB and CISA Authority and Binding Operational Directives (44 USC 3553)

Per TSA SD: incident reporting to CISA within 24 hours of identification + cooperate with FBI + maintain incident log.

TSAPIPE-3 · Cybersecurity Incident Reporting to CISA

Aviation supply chain cybersecurity covers: (a) Executive Order 14028 'Improving the Nation's Cybersecurity' SBOM + secure software development practices + NIST SSDF (SP 800-218) alignment;

FAA-CSA-SupplyChain · Supply Chain Cybersecurity (CISA + NIST SSDF + Executive Orders alignment)

Conduct OT risk assessment per NIST SP 800-82 Rev 3 Chapter 4 (Risk Management) + Chapter 5 (OT Risk Analysis) tailored to OT-specific risk model.

NISTSP82-2 · OT Risk Assessment and Threat/Vulnerability Identification

FIRST CSIRT Services Framework v2.1 Service Area 3 - Vulnerability Management. SCOPE: discovery + tracking + remediation + disclosure of vulnerabilities affecting the constituency.

FIRST-CSIRTF-SA3-VulnMgmt · Service Area 3 - Vulnerability Management and Coordinated Disclosure

Questions people ask about cisa

What is CISA?
The Cybersecurity and Infrastructure Security Agency, a US government agency responsible for protecting critical infrastructure from cyber and physical threats.
Why is CISA important for compliance?
CISA is a key concept in Compliance and Regulatory. Understanding cisa helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address CISA?
CISA appears in the requirement text of CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act), FISMA, TSA Pipeline Cybersecurity Directives, FAA Cybersecurity Framework for Aviation, NIST SP 800-82 Revision 3: Guide to Industrial Control Systems (ICS) Security. Across these standards we have identified 39 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about CISA?
Explore our compliance framework pages to see how cisa applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how CISA applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.