Topics
Below are links to Cloud Services, 5G, and Grant Information that have articles, videos and PDF documents that will help you navigate your way through those issues.
CISA has updated the minimum elements for an SBOM published by NTIA in 2021. The new guidance incorporates stakeholder feedback from a 2025 public comment period and reflects current SBOM tools and needs while preserving the core principles of the original NTIA document.
This document includes the most recent versions of C-SCRM key resources, guidance, and activities.
This document focuses on the development of system plans that address system-level security, privacy, and C-SCRM requirements that are derived from enterprise, organization, and mission/business process requirements.
This Quick-Start Guide provides cybersecurity supply chain risk management (C-SCRM) program management capabilities with considerations for creating due diligence supply chain risk assessments in accordance with NIST Special Publication (SP) 800-161 (Revision 1).
Ransomware Risk Management: A Cybersecurity Framework 2.0 Community Profile helps organizations take a more focused and risk-informed approach to ransomware preparedness. The publication identifies a prioritized set of CSF 2.0 outcomes that support governing management of, identifying, protecting against, detecting, responding to, and recovering from ransomware events.
SBOMs act as a software “ingredients list,” enabling organizations to identify components, assess risks, and take informed action to protect critical systems. As modern software increasingly relies on third-party and open-source components, SBOMs are essential for managing vulnerabilities and supporting secure-by-design development.
In this guidance, CISA lays out questions and resources that organizations buying software can use to better understand a software manufacturer’s approach to cybersecurity and ensure that the manufacturer makes secure by design a core consideration.
The FCC has announced the addition of cybersecurity and anti-virus software produced or provided by Kaspersky Lab, Inc., together with all affiliates, subsidiaries, and parent companies (Kaspersky), to the list of communications equipment and services (Covered List) that have been determined to pose an unacceptable risk to the national security of the United States or the security and safety of United States persons.
This guide assists public safety communications systems operators, owners, and managers in understanding the steps of a cyber risk assessment. Included with this guide are customizable reference tables to help organizations identify and document personnel and resources involved with each step of the assessment.
This two-page guide discusses how to protect your resources and enhance your routing security using ARIN’s Resource Public Key Infrastructure (RPKI) services.