Bidda Sovereign Intelligence · 10,090 Verified Nodes · 39 Sovereign Pillars

Cross-Sector Cybersecurity Performance Goals

The Cross-Sector Cybersecurity Performance Goals (CPGs) provide an approachable common set of IT and OT cybersecurity protections that are clearly…

What Cross-Sector Cybersecurity Performance Goals requires

The Cross-Sector Cybersecurity Performance Goals (CPGs) provide an approachable common set of IT and OT cybersecurity protections that are clearly defined, straightforward to implement, and aimed at addressing some of the most common and impactful cyber risks. These goals are applicable across all critical infrastructure sectors and are informed by the most common and impactful threats and adversary tactics, techniques, and procedures (TTPs) observed by CISA and its government and industry partners. They are a minimum set of practices that all critical infrastructure entities-from large to small-should implement to get started on their path toward a strong cybersecurity posture. The CPGs are intended to be a floor, not a ceiling, for what cybersecurity protections organizations should implement to reduce their cyber risk. The CPGs do not constitute a comprehensive cybersecurity program but rather represent a minimum baseline of cybersecurity practices with known risk-reduction value. They are designed to be easy to understand and communicate with non-technical audiences, including senior business leadership, to help organizations focus investment toward the most impactful security outcomes. The goals are voluntarily adopted and can be used as a quick-start guide, particularly for small and medium organizations, to prioritize security investments in conjunction with broader frameworks like the NIST Cybersecurity Framework (NIST CSF).

Pillar: Cybersecurity · Authority: Cybersecurity and Infrastructure Security Agency (CISA) · Version: 1.0.0 · Last updated:

Primary source: https://www.cisa.gov/sites/default/files/2023-03/CISA_CPG_REPORT_v1.0.1_FINAL.pdf

SHA-256 integrity: ef9cd88f4e22c029bef1777684767012b22ecdbf7bef89d1fa569b1eadf4720a

Primary Citations — 9 traced to source

  • 1.A ORGANIZATIONAL CYBERSECURITY LEADERSHIP: A single leader is responsible and accountable for cybersecurity within an organization.
  • 1.B ASSET INVENTORY: Maintain a regularly updated inventory of all organizational assets with an IP address (including IPv6), including OT. This inventory is updated on a recurring basis, no less than monthly for both IT and OT.

+ 7 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.

Access

⚠ Important: Human Verification Required

Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.