In July 2023, ONCD invited public responses to a Request for Information on opportunities for,
and obstacles to, harmonizing baseline cybersecurity requirements for critical infrastructure and
related assessments and audits. Respondents stressed the importance of leveraging existing
frameworks and best practices, such as the National Institute of Standards and
Technology (NIST) Cybersecurity Framework (CSF), to facilitate reciprocity, and recommended
that ONCD work with the federal regulatory agencies to deconflict current and emerging
cybersecurity requirements to drive harmonization.
Requirements are most often effective when they align with existing cybersecurity frameworks,
voluntary consensus standards, and other technical guidance. In March 2023, CISA updated its
Cybersecurity Performance Goals (CPGs) based on stakeholder input and engaged SRMAs to
begin to develop sector-specific goals through a phased approach. In February 2024, NIST
published version 2.0 of its CSF, which provides updated guidance on managing an evolving
cybersecurity risk landscape, implementation, and measuring effectiveness. In the energy sector,
the Department of Energy (DOE) partnered with the National Association of Regulatory Utility
Commissioners (NARUC) to develop cybersecurity baselines for electric distribution systems
and distributed energy resources. In February 2024, NARUC and DOE publicly released the
baselines and kicked off phase two to develop implementation strategies and adoption guidelines
with state regulatory bodies and industry.
Enhancing Federal Coordination and Partnerships
The Federal Government is modernizing its critical infrastructure protection policies to ensure
that Federal cyber capabilities are exercised in a clear, coordinated, and effective manner. In
April 2024, the Administration issued NSM-22 on Critical Infrastructure Security and
Resilience, replacing Presidential Policy Directive 21 (PPD-21) as the Federal Government’s
primary policy document governing critical infrastructure security and resilience. Released more
than 10 years ago, PPD-21 defined 16 critical sectors and assigned responsibility for identifying
and managing cyber and other all-hazards risks. NSM-22 strengthens the Federal Government’s
ability to enable cross-sector cyber defense; clarifies CISA’s role as the National Coordinator for
the Security and Resilience of Critical Infrastructure; improves connectivity with other Federal
agencies serving as SRMAs; and enhances integration and information sharing with law
enforcement, the intelligence community, and critical infrastructure owners and operators.
NSM-22 also better positions the Federal Government to balance collaboration with regulation,
directing SRMAs and sector-specific regulators to develop minimum security requirements.
CISA, as the National Coordinator, will engage with SRMAs to develop updated risk
assessments and the National Infrastructure Risk Management Plan.
CISA plays a central role in enabling critical infrastructure owners and operators to defend
themselves. In 2023, CISA’s Joint Cyber Defense Collaborative (JCDC) completed three joint
cyber defense plans to enhance the cybersecurity and resilience of critical infrastructure partners.
JCDC’s remote monitoring and management (RMM) and open-source software (OSS) plans
manage cross sector risk by addressing the exploitation of RMM software and producing best
practice guidance for the secure use of OSS in operational technology, respectively. JCDC also
published an incident response guide for the water and wastewater sector to support small- and
2024 REPORT
ON THE CYBERSECURITY
OF THE UNITED STATES
POSTURE
11