{
  "node_id": "cisa-cross-sector-cybersecurity-goals",
  "title": "Cross-Sector Cybersecurity Performance Goals",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2023-03-31",
  "bluf": "The Cross-Sector Cybersecurity Performance Goals (CPGs) provide an approachable common set of IT and OT cybersecurity protections that are clearly defined, straightforward to implement, and aimed at addressing some of the most common and impactful cyber risks. These goals are applicable across all critical infrastructure sectors and are informed by the most common and impactful threats and adversary tactics, techniques, and procedures (TTPs) observed by CISA and its government and industry partners. They are a minimum set of practices that all critical infrastructure entities-from large to small-should implement to get started on their path toward a strong cybersecurity posture. The CPGs are intended to be a floor, not a ceiling, for what cybersecurity protections organizations should implement to reduce their cyber risk.\n\nThe CPGs do not constitute a comprehensive cybersecurity program but rather represent a minimum baseline of cybersecurity practices with known risk-reduction value. They are designed to be easy to understand and communicate with non-technical audiences, including senior business leadership, to help organizations focus investment toward the most impactful security outcomes. The goals are voluntarily adopted and can be used as a quick-start guide, particularly for small and medium organizations, to prioritize security investments in conjunction with broader frameworks like the NIST Cybersecurity Framework (NIST CSF).",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "industry_mapping"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "nist-cybersecurity-framework-2-0",
    "cis-controls-v8",
    "nist-sp-800-53-r5",
    "cyber-nist-csf-2",
    "nist-sp-800-40r4-enterprise-patch-management",
    "nist-sp-800-63b-authentication"
  ],
  "primary_citations_count": 9
}