- Resources
- /CIO Handbook
5.3 Department of Homeland Security (DHS)
The Cybersecurity Information Sharing Act of 2015 gives responsibility to the DHS, Director of National Intelligence (DNI), Department of Defense (DoD) and Department of Justice (DOJ) to "develop procedures to share cybersecurity threat information with private entities, non federal agencies, state, tribal, and local governments, the public, and entities under threats." FISMA 2014 amended FISMA 2002 by "codifying DHS authority" to oversee information security policies for non-national security federal Executive Branch systems.
In accordance with CISA, DHS must establish processes where private sector entities can share information about cybersecurity threats with the Federal Government. DHS manages the delivery and adoption of BODs to federal agencies.
The United States Computer Emergency Readiness Team (US-CERT) works within DHS to prevent cyberthreats and coordinate incident response activities. US-CERT works with federal agencies, private sector, research entities, state and local government and international groups to protect the national technology landscape. The Continuous Diagnostics and Mitigation (CDM) Program "delivers automated tools" to federal agencies to build defense against threats to the national technology infrastructure.
Cybersecurity and Infrastructure Security Agency (CISA)
CISA is one of the newest federal agencies, established as an independent operational component of DHS in 2018 through the expansion of DHS's National Protection and Programs Directorate (NPPD). CISA is responsible for the national capacity to defend against cyber-attacks, and CISA works with the federal government to provide cybersecurity tools, incident response services, and assessment capabilities to safeguard ".gov" networks. Additionally, CISA houses the National Risk Management Center (NRMC) which is tasked with planning, analysis, and collaboration to identify and address significant risks to critical infrastructure.
CISA's Cybersecurity Division is the focal point for cybersecurity and related IT systems, and is tasked with seven primary functions:
- Capability Delivery
- Threat Hunting
- Operational Collaboration
- Vulnerability Management
- Capacity Building
- Strategy, Resources & Performance
- Cyber Defense Education & Training
CISA also maintains a Cyber Resource Hub which includes a range of voluntary cybersecurity assessments that evaluate operational resilience, cybersecurity practices, organizational management of external dependencies, and other key elements of a robust cybersecurity framework. Additional information including Best Practices, case studies, training and exercises, and information about CISA's Annual National Cybersecurity Summits can be found on the CISA.gov website.
Continuous Diagnostic Mitigation (CDM) Program
The CDM Program works under CISA to strengthen the cybersecurity of federal departments and agencies. CDM offers "industry-leading, commercial off-the-shelf (COTS) tools to support technical modernization as threats change." This program meets FISMA mandates and delivers four main objectives: reducing threats at the agency level, increasing visibility into the strengths of federal cybersecurity, improving cybersecurity response capabilities, and streamlining FISMA reporting.
US-CERT
US-CERT works under CISA to prevent cyberthreats and coordinate incident response activities. US-CERT works with federal agencies, private sector, research entities, state and local government and international groups to protect the national technology landscape.
Core Activities:
- Providing cybersecurity protection to Federal civilian executive branch agencies through intrusion detection and prevention capabilities.
- Developing timely and actionable information for distribution to Federal departments and agencies; state, local, tribal, and territorial (SLTT) governments; critical infrastructure owners and operators; private industry; and international organizations.
- Responding to incidents and analyzing data about emerging cybersecurity threats.
- Collaborating with foreign governments and international entities to enhance the nation's cybersecurity posture.
Latest News
AI Transparency Listening Session with the White House Office of Management and Budget
The White House Office of Management and Budget (OMB) is leading a series of listening sessions to learn more from industry about their approaches to AI transparency and auditable risk management.
AI in Action: 5 Essential Findings from the 2024 Federal AI Use Case Inventory
This year, agencies publicly reported more than 1,700 ways they are using Artificial Intelligence (AI) to advance their missions and deliver better experiences to the public.
CISO Council and CDO Council Release Joint Guide on Federal Zero Trust Data Security
Today, the CISO Council and CDO Council released the Federal Zero Trust (ZT) Data Security Guide, a first-of-its-kind document and key deliverable of OMB M-22-09, Moving the U.S. Government Towards Zero Trust Cybersecurity Principles. M-22-09 charged the Federal CDO Council and Federal CISO Council to convene a cross-agency working group of data and security experts to develop a data security guide for Federal agencies.