CISA
Cybersecurity and Infrastructure Security Agency — directives and guidance · CISA (US Department of Homeland Security) · Official site
Binding Operational Directives, Emergency Directives, and cross-sector guidance from the US federal cyber defence agency. The directives bind federal civilian agencies directly; the surrounding catalogue — the Known Exploited Vulnerabilities list, Secure by Design, the Cross-Sector Cybersecurity Performance Goals — is what their contractors and critical-infrastructure operators are measured against in practice.
Timeline
CISA released new guidance titled "Using Cyber Decoys to Strengthen Detection and Response" to help critical infrastructure owners and operators implement cyber decoy systems that detect and disrupt …
CISA and NIST released Interagency Report (IR) 8587 providing comprehensive guidelines for federal agencies and cloud service providers to defend identity tokens and assertions used in single sign-on…
CISA released an updated version of its Insider Threat Mitigation Guide, originally published in 2020, to address evolving threats in the modern operational landscape. The updated guide includes new …
CISA has published the Logging Reference Architecture, an outcome-driven guide developed with OMB and the CISO Council to help federal civilian executive branch (FCEB) agencies establish enterprise l…
CISA released the K-12 Cybersecurity Foundations Resource Package on August 12, 2026, providing guides, videos, and supplemental materials to help K-12 schools and districts prevent and respond to cy…
CISA published a new guidance document for federal agencies on the secure and effective use of open source software (OSS) and open source AI models. The guide provides best practices for reviewing an…
CISA, together with other U.S. government agencies and international organizations, released the 2026 Minimum Elements for a Software Bill of Materials (SBOM), which builds on the 2021 NTIA framework…
CISA, Australian Signals Directorate, UK National Cyber Security Centre, and Canadian Centre for Cyber Security published CI Fortify – Advice for Isolating Vital Systems, a joint guidance document to…
CISA, NSA, FBI and international partners published a joint advisory warning of ongoing Russian state-supported cyber attacks on Zimbra Collaboration Suite (ZCS) users. The advanced persistent threat…
CIS and SAFECode have published version 1.1 of Secure by Design: A Guide to Assessing Software Security Practices, updating the original framework to address evolving software development practices a…
FedRAMP has published NOTICE-0010 as an official response to CISA V1: ED 25-03. This notice provides FedRAMP's position and guidance on how the CISA directive applies to the FedRAMP authorization pro…
CISA has published a public notice for Emergency Directive 26-03. This announcement makes the directive publicly available for federal agencies and contractors using federal information systems. The …
Monitoring
Watched by 2 official sources. Watching since 10 September 2026. Last checked 56 minutes ago.