Some new resources out of CISA. On Thursday, they released their list of voluntary “cybersecurity performance goals” detailing what security practices critical infrastructure operators should follow — such as implementing multifactor authentication or changing default passwords on purchased technologies.
Alongside the goals, CISA published a checklist measuring how much it would cost to implement each solution, the estimated impact of resolving each issue, and the complexity of the task.
So.. why would any provider use anything other than NIST or CISA’s work? I’m also rather keen on some level of cost transparency here. Adapt and modify.. right? Or that good acronym SWIPE. Steal with integrity and pride… everywhere. In this case, the resources are made to be stolen.
