CISA Cybersecurity Performance Goals (v1.0.1)
Overview of CISA Cybersecurity Performance Goals
The CISA Cybersecurity Performance Goals (CPG), published in 2023, provides voluntary, outcome-focused cybersecurity practices that critical infrastructure organizations should implement to significantly reduce risks from common and impactful cyber threats. Developed by the Cybersecurity and Infrastructure Security Agency (CISA) in collaboration with industry partners, the CPGs represent baseline security objectives that, when implemented, establish foundational cyber defenses appropriate for organizations across all 16 critical infrastructure sectors.
Unlike prescriptive compliance frameworks detailing specific technical implementations, the CPGs define security outcomes organizations should achieve while allowing flexibility in how they reach those outcomes. This approach recognizes the diversity of technologies, operational requirements, and constraints across critical infrastructure sectors including energy, healthcare, financial services, water, transportation, and manufacturing. The CPGs prioritize security practices proven most effective at preventing successful cyberattacks, with emphasis on enterprise-wide multi-factor authentication, comprehensive endpoint detection, timely patching, and incident response capabilities.
The Cybersecurity Performance Goals
CISA organizes the CPGs into priority groups addressing fundamental security capabilities. Organizations should implement all CPGs to establish comprehensive baseline defenses.
Authentication and Access Control
Multi-Factor Authentication (MFA): Implement phishing-resistant MFA for all users accessing enterprise systems, particularly privileged accounts, remote access, and critical systems. CISA emphasizes phishing-resistant methods (FIDO2, smart cards, certificate-based) over SMS or push-notification MFA vulnerable to social engineering. Universal MFA deployment prevents credential-based attacks that dominate successful intrusions.
Password Management: Enforce strong password policies requiring unique, complex passwords for each account. Implement password managers to help users maintain unique passwords without resorting to weak or reused credentials. Organizations should disable or closely monitor accounts with weak or compromised passwords identified through breach databases.
Vulnerability and Patch Management
Vulnerability Remediation: Identify and remediate known exploited vulnerabilities within enterprise systems based on CISA's Known Exploited Vulnerabilities (KEV) catalog. Prioritize patching vulnerabilities that CISA has confirmed are actively exploited by threat actors over theoretical vulnerabilities without observed exploitation. This threat-informed approach focuses limited resources on highest-risk vulnerabilities.
Asset Visibility: Maintain comprehensive, accurate inventories of hardware and software assets to enable vulnerability management, security monitoring, and incident response. Organizations cannot patch what they don't know exists—complete asset visibility represents a foundational requirement for all other CPGs.
Detection and Response
Endpoint Detection and Response (EDR): Deploy EDR capabilities across enterprise endpoints to detect malicious activity, enable rapid investigation, and support incident response. EDR provides visibility into endpoint activities that network monitoring cannot observe, detecting sophisticated malware, credential abuse, and insider threats. Organizations should ensure EDR deployments cover servers and workstations comprehensively.
Security Operations and Monitoring: Establish centralized security logging, monitoring, and alerting capabilities enabling detection of suspicious activities and security incidents. Implement Security Information and Event Management (SIEM) or cloud-native security monitoring platforms correlating logs from diverse systems. 24/7 monitoring (internal or through managed security service providers) enables rapid threat detection and response.
Incident Response Planning: Develop, maintain, and regularly test incident response plans with defined roles, procedures, and communication protocols. Organizations should conduct tabletop exercises quarterly and full simulations annually to validate plan effectiveness and build team capabilities. Incident response plans should address ransomware, data breaches, denial of service, and supply chain compromises.
Configuration and Hardening
Secure Configuration: Implement secure configurations for enterprise assets following industry-standard hardening guides like CIS Benchmarks. Default configurations rarely provide adequate security—organizations must disable unnecessary services, enforce strong cryptography, implement security features, and remove default credentials. Configuration management tools enable consistent security hardening across environments.
Email Security: Deploy email security capabilities including anti-phishing protections, malicious attachment filtering, domain-based message authentication (DMARC, SPF, DKIM), and email encryption for sensitive communications. Email represents the primary initial access vector for most cyber intrusions—robust email security prevents attackers from reaching users.
Implementation Approach
CISA designed the CPGs for flexible implementation across diverse critical infrastructure organizations. Rather than one-size-fits-all requirements, the goals allow organizations to achieve security outcomes using approaches appropriate to their technology environments, operational constraints, and resources.
Conduct CPG Assessment: Evaluate current security posture against each CPG to identify implementation gaps. CISA provides assessment tools and guidance for self-evaluation. Gap assessments should involve stakeholders across IT, security, operations, and business leadership to ensure comprehensive understanding of current capabilities and required improvements.
Prioritize Based on Risk and Feasibility: While all CPGs are important, organizations should prioritize implementations delivering greatest risk reduction earliest. MFA, EDR, and vulnerability remediation for KEV catalog items typically provide highest immediate value. Balance risk reduction with implementation feasibility—some CPGs may require multi-year efforts for complex environments.
Leverage Existing Investments: Many organizations already possess technologies supporting CPG implementation but may not use them fully. Maximize existing capabilities before purchasing new solutions. Cloud platforms include MFA, logging, and monitoring capabilities. Endpoint protection platforms often include EDR features requiring only activation and configuration.
Document and Measure Progress: Track CPG implementation through documented metrics demonstrating progress toward each goal. Measurements should include MFA enrollment percentages, EDR deployment coverage, average vulnerability remediation timeframes, incident response exercise frequency, and other quantifiable indicators. Regular measurement identifies implementation obstacles early and demonstrates security program value to leadership.
Relationship to Other Frameworks
The CPGs complement comprehensive frameworks like NIST Cybersecurity Framework, CIS Controls, and ISO 27001 by highlighting specific high-priority outcomes from those frameworks. Organizations already implementing NIST CSF or CIS Controls can assess CPG alignment—many controls directly support CPG achievement. The CPGs should not replace comprehensive frameworks but rather focus organizations on priority outcomes within broader security programs.
For sector-specific requirements, organizations should combine CPGs with industry frameworks like NERC CIP for electricity, TSA Pipeline Security Directives for pipelines, HIPAA for healthcare, and PCI DSS for payment systems. CPGs provide baseline security applicable across sectors while sector frameworks address specialized requirements.
Frequently Asked Questions
Are CISA CPGs mandatory for critical infrastructure?
The CPGs are voluntary guidance rather than mandatory regulations for most critical infrastructure operators. However, certain sectors and situations create expectations for CPG implementation. Federal contractors may face CPG requirements in contracts. Organizations regulated under sector-specific frameworks (TSA directives, NERC CIP) should implement CPGs as they align with regulatory requirements. Cyber insurance providers increasingly reference CPGs in underwriting and may offer premium reductions for documented implementation.
How do CPGs differ from NIST CSF or CIS Controls?
CPGs are focused, outcome-based goals highlighting specific high-priority security practices, while NIST CSF and CIS Controls provide comprehensive frameworks covering all aspects of cybersecurity programs. CPGs tell organizations what security outcomes to achieve, while NIST CSF and CIS Controls provide detailed how-to guidance for achieving those outcomes. Organizations should use CPGs to prioritize within broader framework implementations rather than treating CPGs as standalone comprehensive programs.
How long does CPG implementation take?
CPG implementation timelines vary dramatically based on starting security posture. Organizations with mature security programs may already satisfy most CPGs and can fill gaps within 6-12 months. Organizations with limited existing security capabilities typically require 12-24 months for comprehensive CPG implementation, with MFA and EDR deployments often representing the longest-duration activities. Organizations should implement CPGs progressively, delivering security improvements incrementally rather than waiting for complete implementation.
Can small critical infrastructure operators implement the CPGs?
Yes, though small operators face resource challenges. CISA designed CPGs to be achievable across organization sizes, focusing on high-impact practices rather than expensive, complex controls. Small operators should leverage cloud services providing built-in security capabilities (MFA, logging, EDR), consider managed security service providers (MSSPs) for monitoring and incident response, and focus initially on CPGs providing greatest risk reduction. CISA offers free resources, tools, and assistance to help small operators implement CPGs.
How do organizations demonstrate CPG implementation?
Organizations can demonstrate CPG implementation through documented evidence including MFA enrollment reports, EDR deployment coverage statistics, vulnerability management reports showing KEV remediation, security monitoring configurations, incident response exercise documentation, and third-party assessments. While CISA does not offer formal CPG certification, independent cybersecurity assessments can validate implementation for customer due diligence, regulatory reporting, or cyber insurance purposes. Organizations should maintain continuous evidence collection supporting CPG claims.