Skip to content

CISA Resources

Who is CISA

The Cybersecurity and Infrastructure Security Agency (CISA) leads the national effort to understand, manage, and reduce risks to the cyber and physical infrastructure of the United States. It connects stakeholders in industry and government with resources, analyses, and tools to improve their cyber, communications, and physical security and resilience. This ensures a secure infrastructure for the American people. Source: CISA Overview

CISA Free Cybersecurity Services and Tools

On September 24, 2022, CISA released a list of free cybersecurity tools and services:

"As part of our continuing mission to reduce cybersecurity risk across U.S. critical infrastructure partners and state, local, tribal, and territorial governments, CISA has compiled a list of free cybersecurity tools and services to help organizations further advance their security capabilities. This living repository includes cybersecurity services provided by CISA, widely used open-source tools, and free tools and services offered by private and public sector organizations across the cybersecurity community." Source: CISA Free Cybersecurity Services

General CISA Cybersecurity Guidelines

  1. Fix known security flaws in software by referencing the CISA Known Exploited Vulnerabilities Catalog. Regularly update software to the latest versions as per vendor instructions.

  2. Implement multifactor authentication (MFA). MFA requires two or more authenticators to verify identity, providing enhanced protection over just a username and password.

  3. Halt bad practices such as using end-of-life software, systems with default passwords, and lacking MFA for critical systems.

  4. Sign up for CISA’s Cyber Hygiene Vulnerability Scanning by emailing vulnerability@cisa.dhs.gov. Weekly reports help secure internet-facing systems.

  5. Get your Stuff Off Search (S.O.S.) by reducing internet-visible attack surfaces. Learn more at Get Your Stuff Off Search (S.O.S.).

CISA Tool Recommendations

Reducing the Likelihood of a Cyber Incident

ServiceSkill LevelOwnerDescriptionLink
Network ReportingBasicShadowServerReports on network state and security exposuresShadowServer
Vulcan Cyber Remedy CloudBasicVulcan CyberSearchable database of vulnerability remediesRemedy Cloud
Ransomware Risk AssessmentBasicZscalerAssesses ransomware-specific intrusion defensesTest My Defenses
Internet Threat ExposureBasicZscalerEvaluates cyber risk postureZscaler Scan
CISA Vulnerability ScanningBasicCISAScans public IPs for vulnerabilitiesvulnerability@cisa.dhs.gov
CISA Web Application ScanningBasicCISAEvaluates web applications for security risksvulnerability@cisa.dhs.gov
Cloudflare DDoS ProtectionBasicCloudflareProtects against DDoS attacksCloudflare Free
Quad9BasicOpen SourceBlocks malware and phishing sitesQuad9
WiresharkAdvancedOpen SourceNetwork protocol analyzerWireshark
SnortAdvancedCiscoIntrusion detection and preventionSnort

Other Tools

Ensure Preparedness for Intrusions

Cyber Readiness

Categorty:Tech

References

IrregularChat Community Wiki