← BIDDA × CISA
PROGRAM 3 OF 3 · READY
CPG and Bidda Crosswalk
The Cybersecurity Performance Goals (CPGs) are CISA's voluntary, prioritised baseline for cybersecurity in United States critical infrastructure. There are eight outcome areas, which apply to both information-technology and operational-technology environments and which are designed to be accessible to small and medium-sized operators. Bidda's executable compliance nodes resolve CPG outcomes into deterministic workflow steps traceable to primary regulatory sources.
The eight CISA CPG outcome areas are Account Security, Device Security, Data Security, Governance and Training, Vulnerability Management, Supply Chain and Third Party, Response and Recovery, and Other (cross-cutting).
This crosswalk is the lightweight, surface-level view. The full bidirectional mapping, in which per-node CPG anchors are attached to every relevant Bidda node, lives inside the registry itself and is queryable via the MCP tool get_crosswalk.
BIDIRECTIONAL
Both directions of the mapping work
CPG TO EXECUTABLE WORKFLOW
"How do I implement CPG 2.A device security?"
Bidda resolves the question into the dependency chain of NIST SP 800-128, CIS Control 1 and IEC 62443-3-3 nodes, each of which has its own deterministic workflow and actionable schema.
WORKFLOW TO CPG OUTCOME
"Which CPG outcomes does this NIST control satisfy?"
The Bidda node carries its CPG anchors as part of its crosswalks block, so a compliance officer sees exactly which CISA outcome each implemented control is delivering against.
Eight outcome areas
1
Account Security
Detect and prevent unauthorised access to accounts: unique credentials, MFA, revocation of old accounts, separating privileged accounts.
BIDDA PILLARS
Cybersecurity
AI Governance & Law
EXAMPLE NODES
▸
nist-sp-800-63b-digital-identity
NIST SP 800-63B: Digital Identity
▸
nist-sp-800-205-access-control
NIST SP 800-205: Access Control
▸
cis-controls-v8
CIS Controls v8
OUTCOME
A defender can resolve the requirement to "implement CPG account security" into the specific executable workflow steps that Bidda has indexed against the authoritative standards.
2
Device Security
Asset inventory, hardware/software inventory currency, secure configurations, default-deny on devices that touch the OT network.
BIDDA PILLARS
Cybersecurity
Industrial IoT & Energy
EXAMPLE NODES
▸
nist-sp-800-128-config-management
NIST SP 800-128: Security-Focused Configuration Management
▸
iec-62443-4-2-component-security-2019
IEC 62443-4-2: Component Security Requirements
▸
isa-99-iec-62443-industrial-security-framework
ISA-99 and IEC 62443: Industrial Security Framework
OUTCOME
Bidda exposes IT and OT device-security obligations as a single chain, with the IT control pointing to the OT control via the dependency graph.
3
Data Security
Log collection, encryption at rest and in transit, segmentation, secure disposal, secrets management.
BIDDA PILLARS
Cybersecurity
Banking & Global Finance
Medical & Healthcare
EXAMPLE NODES
▸
nist-sp-800-53-r5
NIST SP 800-53 Rev 5: Security and Privacy Controls
▸
pci-dss-v4-requirement-3
PCI DSS v4 Requirement 3: Protect Stored Account Data
▸
us-hipaa-45-cfr-164-312-technical-safeguards
HIPAA 45 CFR 164.312: Technical Safeguards
OUTCOME
Domain-specific data-security obligations such as PCI for payments, HIPAA for health and GDPR for the European Union all resolve through the same CPG entry point.
4
Governance and Training
Designate a security leader, board oversight, OT cyber leadership, security training for staff, mitigation against known exploited vulnerabilities (KEVs).
BIDDA PILLARS
Cybersecurity
AI Governance & Law
Workplace
EXAMPLE NODES
▸
iso-iec-27001-2022-information-security-workflow
ISO/IEC 27001:2022: Information Security Management
▸
nist-csf-2-0-govern-function
NIST CSF 2.0: Govern Function (added in v2.0)
▸
iso-iec-42001-clause-7-support-resources
ISO/IEC 42001 Clause 7: Support and Resources
OUTCOME
Bidda explicitly captures the CSF 2.0 Govern function alongside the original Identify, Protect, Detect, Respond and Recover spine, which remains unusual across competing registries.
5
Vulnerability Management
Mitigate known exploited vulnerabilities (KEV catalogue), accept third-party vulnerability reports, do not roll your own crypto, no exploitable services on the public internet.
BIDDA PILLARS
Cybersecurity
EXAMPLE NODES
▸
nist-sp-800-40r4-enterprise-patch-management
NIST SP 800-40 Rev 4: Enterprise Patch Management
▸
nist-sp-800-216-vulnerability-disclosure-guidelines
NIST SP 800-216: Vulnerability Disclosure Guidelines
▸
nis2-directive-article-12-coordinated-vulnerability-disclosure
NIS2 Directive Article 12: Coordinated Vulnerability Disclosure
OUTCOME
A CPG-aligned vulnerability programme reduces to a small number of Bidda nodes, each with a deterministic workflow.
6
Supply Chain and Third Party
Detect and respond to supplier incidents, supplier risk management, SBOM availability, no procurement of unsupported software.
BIDDA PILLARS
Cybersecurity
Logistics & Supply Chain
AI Governance & Law
EXAMPLE NODES
▸
nist-sp-800-161-r1-supply-chain-risk-management
NIST SP 800-161 Rev 1: Cyber Supply Chain Risk Management
▸
eu-cra-2024-2847-article-3-essential-requirements-products-digital-elements
EU Cyber Resilience Act Article 3: Essential Requirements for Products with Digital Elements
▸
cisa-sbom-minimum-elements-2021
CISA SBOM Minimum Elements
OUTCOME
AI supply-chain risk, including model provenance, training-data software bill of materials and fine-tune lineage, is captured alongside conventional software supply chain inside the same registry.
7
Response and Recovery
Incident reporting to CISA, incident response plan, system backups, OT cyber incident response, OT recovery plans.
BIDDA PILLARS
Cybersecurity
Industrial IoT & Energy
Banking & Global Finance
EXAMPLE NODES
▸
nist-sp-800-61r3-incident-response-2024
NIST SP 800-61 Rev 3: Computer Security Incident Handling
▸
us-circia-cyber-incident-reporting-act-2022
CIRCIA: Cyber Incident Reporting for Critical Infrastructure (2022)
▸
dora-regulation-article-17-ict-related-incident-management-process
EU DORA Article 17: ICT-Related Incident Management Process
OUTCOME
US incident-reporting obligations under CIRCIA and EU obligations under DORA are mapped together, so a multinational operator does not have to maintain two parallel runbooks.
8
Other (cross-cutting)
Encompasses items that span IT and OT or that do not fit cleanly into the seven categories above, for example email security, OT default-deny on encrypted protocols, and network segmentation.
BIDDA PILLARS
Cybersecurity
Telecoms & Digital Infrastructure
EXAMPLE NODES
▸
nist-sp-800-177-trustworthy-email
NIST SP 800-177: Trustworthy Email
▸
nist-sp-800-207-zero-trust
NIST SP 800-207: Zero Trust Architecture
▸
iec-62443-iacs
IEC 62443: Industrial Automation and Control Systems
OUTCOME
Cross-cutting CPG outcomes resolve into a small set of foundational architecture nodes covering zero trust, network segmentation and trustworthy email.
HONEST SCOPE
The example nodes named above are illustrative anchors. They are the nodes that most directly express each CPG outcome, and they are intended to give a defender an entry point into the registry. Hundreds of additional Bidda nodes contribute to each area in some form. The deep, per-node CPG annotation is built incrementally, and the full bidirectional crosswalk lives inside each node's crosswalks block where it is queryable via the free MCP tool.
← BACK TO CISA HUB
BROWSE INTELLIGENCE FOREST →
MCP GET_CROSSWALK →