Archived Content
In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.Pipeline Cybersecurity Resources Library
The Pipeline Cybersecurity Initiative and its activities are transitioning to enduring programs in the Transportation Security Administration (TSA) and CISA to continue building on the success of this initiative.
Contact
For questions regarding PCI or the resources below, please email CISA Central.
Assessments, Tools, and Services
Incident Detection, Response, and Prevention
Incident detection, response, and prevention strategies are a critical consideration for the Nation's homes and business organizations.
Cyber Hygiene Services
CISA offers several scanning and testing service (i.e., testing susceptibility to phishing attacks and testing perimeter defense) to help organizations reduce their exposure to threats by taking a proactive approach to mitigating attack vectors.
Cyber Resilience Review (CRR)
An assessment that evaluates an organization's operational resilience and cybersecurity practices
Cyber Resource Hub
To assist a variety of stakeholders to ensure the cybersecurity of our Nation's critical infrastructure, CISA offers a range of cybersecurity assessments that evaluate operational resilience, cybersecurity practices, organizational management.
Department of Energy’s Cybersecurity Capability Maturity Model (C2M2)
C2M2 is a voluntary tool to help organizations measure the maturity of their cybersecurity capabilities in a consistent manner that focuses on the implementation and management of cybersecurity practices.
Malcolm
Idaho National Laboratory’s Malcolm is a powerful and easily deployable network traffic analysis tool suite.
Exercises
Tabletop Exercise Packages
CISA Tabletop Exercise Packages are a comprehensive set of resources designed to assist stakeholders in conducting their own exercises and initiating discussions within their organizations about their ability to address a variety of threat scenarios.
COVID-19 Recovery CISA Tabletop Exercise Package (CTEP)
Assists private sector stakeholders and critical infrastructure owners and operators in assessing short-term, intermediate, and long-term recovery and business continuity plans related to the COVID-19 pandemic.
Cybersecurity Training & Exercises
CISA looks to enable the cyber-ready workforce of tomorrow by leading training and education of the cybersecurity workforce.
Reporting
Automated Indicator Sharing (AIS)
The AIS ecosystem empowers participants to share cyber threat indicators and defensive measures such as information about attempted adversary compromises as they are being observed.
Homeland Security Information Network (HSIN) – Critical Infrastructure
The Critical Infrastructure community on HSIN (HSIN-CI) is the primary system through which DHS, private sector owners and operators, and other government agencies collaborate to protect the nation’s critical infrastructure.
Report Incidents, Phishing, Malware, or Vulnerabilities
Secure means for constituents and partners to report incidents, phishing attempts, malware, and vulnerabilities.
Risk Awareness and Reduction Information
Ransomware Guide
Best practices and ways to prevent, protect and/or respond to a ransomware attack.
Cybersecurity Alerts & Advisories
Regularly updated summary of the most frequent, high-impact types of security incidents currently being reported.
Cyber Essentials
Modules broken down into bite-sized actions for IT and C-suite leadership to work toward full implementation of each Cyber Essential.
Industrial Control Systems - Recommended Practices
Reduces risks within and across all critical infrastructure sectors and to share common ICS-related security mitigation recommendations. This page provides abstracts for existing recommended practices and links to source documents.
Information Sharing and Awareness
Shares information with state, local, tribal, and territorial governments and with international partners, as cybersecurity threat actors are not constrained by geographic boundaries.
National Cyber Awareness System (NCAS)
CISA offers no-cost, subscription-based information products to stakeholders. CISA designed these products to improve situational awareness among technical and non-technical audiences by providing timely information about cybersecurity threats.
Pipeline Cyber Risk Mitigation Infographic
CISA and the TSA developed this infographic to outline activities that pipeline operators can undertake to improve the cybersecurity of their information technology (IT) and operational technology (OT) systems.
Ransomware Fact Sheets & Information
Technical guidance documentation to inform critical infrastructure entities and organizations about industry best practices and mitigation strategies/
Cybersecurity Awareness Program
National public awareness effort aimed at increasing the understanding of cyber threats and empowering the American public to be safer and more secure online.
Standards and Guidance
NIST Cybersecurity Framework
Voluntary guidance, based on existing standards, guidelines, and practices to help critical infrastructure owners and operators reduce cybersecurity risk.
NIST SP 800-53 Rev 5: Security and Privacy Controls for Information Systems and Organizations
Catalog of security and privacy controls for organizations to protect operations and assets, individuals, and information systems from a diverse set of threats and risks.
NIST SP 800-82 Rev 2: Guide to Industrial Control Systems (ICS) Security
Overview of ICS and typical system topologies, identifies typical threats and vulnerabilities to these systems, and provides recommended security countermeasures to mitigate associated risks.
Transportation Security Administration’s (TSA) Pipeline Security Guidelines
Voluntary guidelines for pipeline industry partners to increase their security awareness.
Training
Basic Phishing Training (DoD Cyber Exchange Public)
Interactive training explains what phishing is and provides examples of the different types of phishing.
Control Systems Security Program—Industrial Control Systems Cybersecurity Training
Various training courses at no tuition cost via the CISA Virtual Learning Portal (VLP). Web
Federal Virtual Training Environment (FedVTE)
Online and on-demand cybersecurity training system.