HOME

TheInfoList



OR:

The Cybersecurity and Infrastructure Security Agency (CISA) is a component of the
United States Department of Homeland Security The United States Department of Homeland Security (DHS) is the U.S. United States federal executive departments, federal executive department responsible for public security, roughly comparable to the Interior minister, interior, Home Secretary ...
(DHS) responsible for
cybersecurity Computer security (also cybersecurity, digital security, or information technology (IT) security) is a subdiscipline within the field of information security. It consists of the protection of computer software, systems and networks from thr ...
and
infrastructure Infrastructure is the set of facilities and systems that serve a country, city, or other area, and encompasses the services and facilities necessary for its economy, households and firms to function. Infrastructure is composed of public and pri ...
protection across all levels of government, coordinating cybersecurity programs with U.S. states, and improving the government's cybersecurity protections against private and nation-state
hacker A hacker is a person skilled in information technology who achieves goals and solves problems by non-standard means. The term has become associated in popular culture with a security hackersomeone with knowledge of bug (computing), bugs or exp ...
s. The term "cyber attack" covers a wide variety of actions ranging from simple probes, to defacing websites, to denial of service, to espionage and destruction. The agency began in 2007 as the DHS National Protection and Programs Directorate. With the Cybersecurity and Infrastructure Security Agency Act of 2018, CISA's footprint grew to include roles protecting the
census A census (from Latin ''censere'', 'to assess') is the procedure of systematically acquiring, recording, and calculating population information about the members of a given Statistical population, population, usually displayed in the form of stati ...
, managing National Special Security Events, and the U.S. response to the COVID-19 pandemic. It has also been involved in overseeing 5G network security, securing elections, and strengthening the US grid against
electromagnetic pulse An electromagnetic pulse (EMP), also referred to as a transient electromagnetic disturbance (TED), is a brief burst of electromagnetic energy. The origin of an EMP can be natural or artificial, and can occur as an electromagnetic field, as an ...
s (EMPs). The Office for Bombing Prevention leads the national counter-IED effort. Currently headquartered in
Arlington, Virginia Arlington County, or simply Arlington, is a County (United States), county in the U.S. state of Virginia. The county is located in Northern Virginia on the southwestern bank of the Potomac River directly across from Washington, D.C., the nati ...
, in 2025 CISA is planning to move its headquarters along with 6,500 employees to a new 10 story, 620,000 sq ft building on the consolidated DHS St. Elizabeths campus headquarters.


History

The National Protection and Programs Directorate (NPPD) was formed in 2007 as a component of the
United States Department of Homeland Security The United States Department of Homeland Security (DHS) is the U.S. United States federal executive departments, federal executive department responsible for public security, roughly comparable to the Interior minister, interior, Home Secretary ...
. NPPD's goal was to advance the Department's
national security National security, or national defence (national defense in American English), is the security and Defence (military), defence of a sovereign state, including its Citizenship, citizens, economy, and institutions, which is regarded as a duty of ...
mission by reducing and eliminating threats to U.S. critical physical and cyber infrastructure. On November 16, 2018, President Trump signed into law the Cybersecurity and Infrastructure Security Agency Act of 2018, which elevated the mission of the former NPPD within DHS, establishing the Cybersecurity and Infrastructure Security Agency (CISA). CISA is a successor agency to NPPD, and assists both other government agencies and private sector organizations in addressing cybersecurity issues. Former NPPD Under-Secretary Christopher Krebs was CISA's first Director, and former Deputy Under-Secretary Matthew Travis was its first deputy director. On January 22, 2019, CISA issued its first Emergency Directive (19-01: Mitigate DNS Infrastructure Tampering) warning that "an active attacker is targeting government organizations" using
DNS spoofing DNS spoofing, also referred to as DNS cache poisoning, is a form of computer security hacking in which corrupt Domain Name System data is introduced into the DNS resolver's cache, causing the name server to return an incorrect result record, e ...
techniques to perform man-in-the-middle attacks. Research group FireEye stated that "initial research suggests the actor or actors responsible have a nexus to Iran." In 2020, CISA created a website, titled ''Rumor Control'', to rebut
disinformation Disinformation is misleading content deliberately spread to deceive people, or to secure economic or political gain and which may cause public harm. Disinformation is an orchestrated adversarial activity in which actors employ strategic dece ...
associated with the
2020 United States presidential election United States presidential election, Presidential elections were held in the United States on November 3, 2020. The Democratic Party (United States), Democratic ticket of former vice president Joe Biden and California junior senator Kamala H ...
. On November 12, 2020, CISA issued a press release asserting, "There is no evidence that any voting system deleted or lost votes, changed votes, or was in any way compromised." On the same day, Director Krebs indicated that he expected to be dismissed from his post by the Trump administration. Krebs was subsequently fired by President Trump on November 17, 2020 via tweet for his comments regarding the security of the election. According to various reports and statistics, the scale and frequency of cyber-attacks have been steadily increasing in recent years. For example, the number of data breaches reported in 2020 alone reached a record high of 3,932, a 48% increase compared to the previous year, with over 37 billion records exposed globally, and also the average cost of a data breach in 2020 was estimated to be $3.86 million, with an average time to identify and contain a breach of 280 days. On July 12, 2021, the
Senate A senate is a deliberative assembly, often the upper house or chamber of a bicameral legislature. The name comes from the ancient Roman Senate (Latin: ''Senatus''), so-called as an assembly of the senior (Latin: ''senex'' meaning "the el ...
confirmed
Jen Easterly Jen Easterly is an American cybersecurity expert and former government official who served as the Director of the Cybersecurity and Infrastructure Security Agency in the Biden administration. She was confirmed by a voice vote in the Senate on Jul ...
by a voice vote. Easterly's nomination had been reported favorably out of Senate Committee on Homeland Security and Governmental Affairs on June 16, but a floor vote had been reportedly
held Held may refer to: Places * Held Glacier People Arts and media * Adolph Held (1885–1969), U.S. newspaper editor, banker, labor activist *Al Held (1928–2005), U.S. abstract expressionist painter. *Alexander Held (born 1958), German television ...
(delayed) by Senator Rick Scott over broader national security concerns, until the President or Vice President had visited the southern border with Mexico. Easterly hired new staff to monitor online disinformation to enhance what she called the nation's "cognitive infrastructure" and utilized the existing rumor control website during the 2021 elections. In September 2022, CISA released their 2023–2025 CISA Strategic Plan, the first comprehensive strategy document since the agency was established in 2018. Resentful over CISA continuing to contradict his false claims of election fraud, when Donald Trump returned to the presidency in 2025, he directed his administration to start dismantling CISA. The administration canceled programs that monitor foreign influence, foreign election disinformation, and foreign attempts to break into critical infrastructure like voting systems and electrical grids. It also canceled contracts for penetration testing of local election systems.


Organization

CISA divisions include the: * Cybersecurity Division ** National Cybersecurity and Communications Integration Center ** Capacity Building ** Joint Cyber Defense Collaborative ** Mission Engineering ** Office of the Technical Director ** Threat Hunting ** Vulnerability Management * Infrastructure Security Division ** Bombing Prevention ** Chemical Security ** Exercises ** Infrastructure Assessment & Analysis ** School Safety ** Strategy, Performance & Resources * Emergency Communications Division * National Risk Management Center * Integrated Operations Division ** Regions 1 through 10 * Stakeholder Engagement Division ** Council Management ** International ** Sector Management ** Strategic Relations


Programs

The Continuous Diagnostics and Mitigations program provides cybersecurity tools and services to federal agencies. CISA issues "binding operational directives" that require federal government agencies to take action against specific cybersecurity risks. In March 2021, CISA assumed control of the .gov
top-level domain A top-level domain (TLD) is one of the domain name, domains at the highest level in the hierarchical Domain Name System of the Internet after the root domain. The top-level domain names are installed in the DNS root zone, root zone of the nam ...
(TLD) from the
General Services Administration The General Services Administration (GSA) is an Independent agencies of the United States government, independent agency of the United States government established in 1949 to help manage and support the basic functioning of federal agencies. G ...
. CISA manages the approval of domains and operates the TLD
Domain Name System The Domain Name System (DNS) is a hierarchical and distributed name service that provides a naming system for computers, services, and other resources on the Internet or other Internet Protocol (IP) networks. It associates various information ...
nameservers. In April 2021, CISA removed the fee for registering domains. In January 2023,
Cloudflare Cloudflare, Inc., is an American company that provides content delivery network services, cybersecurity, DDoS mitigation, wide area network services, reverse proxies, Domain Name Service, ICANN-accredited domain registration, and other se ...
received a $7.2M contract to provide DNS registry and hosting services for the TLD. CISA provides incident response services to the federal executive branch and US-based entities. CISA manages the EINSTEIN intrusion detection system to detect malicious activity on federal government agency networks. The National Defense Authorization Act for Fiscal Year 2021 granted CISA the authority to issue administrative subpoenas in order to identify the owners of internet connected critical infrastructure related devices with specific vulnerabilities. In 2021, CISA issued 47 subpoenas. In August 2021, Easterly stated "One could argue we’re in the business of critical infrastructure, and the most critical infrastructure is our cognitive infrastructure, so building that resilience to misinformation and disinformation, I think, is incredibly important." In 2021, CISA released a report that provided guidance for how to navigate and prevent
ransomware Ransomware is a type of malware that Encryption, encrypts the victim's personal data until a ransom is paid. Difficult-to-trace Digital currency, digital currencies such as paysafecard or Bitcoin and other cryptocurrency, cryptocurrencies are com ...
incidents. This was due to a significant jump in recent attacks related to ransomware.


Committees


Cybersecurity Advisory Committee

In 2021, the Agency created the Cybersecurity Advisory Committee with the following members: * Steve Adler, Mayor, City of Austin, Texas * Marene Allison, Chief Information Security Officer, Johnson & Johnson * Lori Beer, Chief Information Officer, JPMorgan Chase * Robert Chesney, James A. Baker III Chair in the Rule of Law and World Affairs, University of Texas School of Law * Thomas Fanning, chairman, President and CEO, Southern Company * Vijaya Gadde * Patrick D. Gallagher, Chancellor, University of Pittsburgh * Ronald Green, Executive Vice President and Chief Security Officer, Mastercard * Niloofar Razi Howe, board member, Tenable * Kevin Mandia, chief executive officer, Mandiant * Jeff Moss, President, DEF CON Communications * Nuala O’Connor, Senior Vice President & Chief Counsel, Digital Citizenship, Walmart * Nicole Perlroth, Cybersecurity journalist * Matthew Prince, chief executive officer, Cloudflare * Ted Schlein, General Partner, Kleiner Perkins; and Caufield & Byers * Stephen Schmidt, Chief Information Security Officer, Amazon Web Services * Suzanne Spaulding, Senior Advisor for Homeland Security, CSIS * Alex Stamos, Partner, Krebs Stamos Group * Kate Starbird, Associate Professor, Human Centered Design & Engineering, University of Washington * George Stathakopoulos, Vice President of Corporate Information Security, Apple * Alicia Tate-Nadeau (ARNG-Ret.), Director, Illinois Emergency Management Agency * Nicole Wong, Principal, NWong Strategies * Chris Young, Executive Vice President of Business Development, Strategy, and Ventures, Microsoft


Directors


See also

* Florida Digital Service *
List of federal agencies in the United States Legislative definitions of an agency of the federal government of the United States are varied, and even contradictory. The official '' United States Government Manual'' offers no definition. While the Administrative Procedure Act definition of ...


References


External links

* {{authority control 2018 establishments in the United States Ballston, Virginia Business services companies established in 2018 Computer security organizations Emergency services in the United States Government agencies established in 2018 United States Department of Homeland Security agencies