CISA
What is CISA?
The Cybersecurity and Infrastructure Security Agency, a US government agency responsible for protecting critical infrastructure from cyber and physical threats.
Terms that appear alongside cisa
Each of these is named in at least one of the same controls as cisa. The number is how many controls name both.
- cybersecurity 44 shared controls
- nist 35 shared controls
- vulnerability 23 shared controls
- incident response 21 shared controls
- threat intelligence 17 shared controls
- incident reporting 16 shared controls
- cyber incident 15 shared controls
- integrity 14 shared controls
Frameworks that govern cisa
What the standards actually require on cisa
Requirements naming cisa across 6 standards, quoted from the control text.
If CISA has reason to believe a covered entity experienced a covered cyber incident or made a ransom payment but failed to report, it may request additional information; the entity should respond to confirm whether a reportable event occurred.
CIRCIA-2244b · Response to a CISA Request for Information →44 USC 3553 - Authority and Functions of the Director of OMB + the CISA Director. OMB DIRECTOR AUTHORITY: (a) overseeing agency information security policies + practices;
FISMA-3553-OMB-CISA-BOD · OMB and CISA Authority and Binding Operational Directives (44 USC 3553) →Per TSA SD: incident reporting to CISA within 24 hours of identification + cooperate with FBI + maintain incident log.
TSAPIPE-3 · Cybersecurity Incident Reporting to CISA →Aviation supply chain cybersecurity covers: (a) Executive Order 14028 'Improving the Nation's Cybersecurity' SBOM + secure software development practices + NIST SSDF (SP 800-218) alignment;
FAA-CSA-SupplyChain · Supply Chain Cybersecurity (CISA + NIST SSDF + Executive Orders alignment) →Conduct OT risk assessment per NIST SP 800-82 Rev 3 Chapter 4 (Risk Management) + Chapter 5 (OT Risk Analysis) tailored to OT-specific risk model.
NISTSP82-2 · OT Risk Assessment and Threat/Vulnerability Identification →FIRST CSIRT Services Framework v2.1 Service Area 3 - Vulnerability Management. SCOPE: discovery + tracking + remediation + disclosure of vulnerabilities affecting the constituency.
FIRST-CSIRTF-SA3-VulnMgmt · Service Area 3 - Vulnerability Management and Coordinated Disclosure →Questions people ask about cisa
What is CISA?
Why is CISA important for compliance?
Which compliance frameworks address CISA?
Where can I learn more about CISA?
See how CISA applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.