The Emergency Services Sector Cybersecurity Initiative is an ongoing effort to enable the Emergency Services Sector (ESS) to better understand and manage cyber risks and to coordinate the sharing of cyber information and tools between subject matter experts (both inside and outside the federal government) and the ESS disciplines.
Emergency Services Sector Cybersecurity Best Practices
The Emergency Services Sector Cybersecurity Best Practices is a fact sheet to assist ESS organizations and personnel to better protect themselves by implementing some simple, effective, low-cost measures. In addition to general cybersecurity practices, it also addresses best practices for social networking, email, Wi-Fi, and Bluetooth.
Emergency Services Sector Cyber Risk Assessment
The Emergency Services Sector Cyber Risk Assessment (ESS CRA) is the first sector-wide assessment that analyzes strategic cyber risks to ESS infrastructure. The ESS CRA results will help the sector understand and manage cyber risks, and provide a national-level risk profile that ESS organizations can use to prioritize how they spend resources and where to focus training, education, equipment investments, grant requests, and further study. View the Emergency Services Sector Cyber Risk Assessment Fact Sheet.
Emergency Services Sector Roadmap to Secure Voice and Data Systems
The follow-up to the Emergency Services Sector Cyber Risk Assessment (ESS CRA), the Emergency Services Sector Roadmap to Secure Voice and Data Systems, identifies and discusses proposed risk mitigation measures to address the risks identified in the ESS-CRA.
Enhanced Cybersecurity Services
The Cybersecurity and Infrastructure Security Agency's (CISA) Enhanced Cybersecurity Services (ECS) program is an intrusion detection, prevention, and analysis capability that is available to all U.S.-based entities.
Emergency Services Sector Cybersecurity Framework Implementation Guidance
The National Institute of Standards and Technology (NIST) released the voluntary Framework for Improving Critical Infrastructure Cybersecurity (Framework) in February 2014 to provide a common language that critical infrastructure organizations can use to assess and manage their cybersecurity risk. The Framework enables an organization—regardless of its sector, size, degree of risk, or cybersecurity sophistication—to apply the principles and effective practices of cyber risk management to improve the security and resilience of its critical infrastructure.
The U.S. Department of Homeland Security (DHS), as the Sector Risk Management Agency (SRMA), worked with the Emergency Services Sector Coordinating Council (SCC) and Government Coordinating Council (GCC) to develop the Emergency Services Sector Cybersecurity Framework Implementation Guidance specifically for Emergency Services Sector organizations. This Implementation Guidance provides Emergency Services Sector organizations with:
- Background on the Framework terminology, concepts, and benefits of its use.
- A mapping of existing cybersecurity tools and resources used in the Emergency Services Sector that can support Framework implementation.
- Detailed Framework implementation steps tailored for Emergency Services Sector owners and operators.
Executive Order 13636 and Presidential Policy Directive 21
Facing threats to our nation from cyber-attacks that could disrupt our power, water, communications, and other critical systems, the President issued Executive Order (EO) 13636: Improving Critical Infrastructure Cybersecurity and Presidential Policy Directive (PPD) 21: Critical Infrastructure Security and Resilience. These policies reinforce the need for holistic thinking about security and risk management. Implementation of the EO and PPD will drive action toward system and network security and resiliency, while simultaneously enhancing the efficiency and effectiveness of the U.S. government’s efforts to secure critical infrastructure and make it more resilient.
CISA Cyber Resource Hub
The Cybersecurity and Infrastructure Security Agency (CISA) offers a range of cybersecurity assessments that evaluate operational resilience, cybersecurity practices, organizational management of external dependencies, and other key elements of a robust and resilient cyber framework. These professional, no-cost assessments are provided upon request on a voluntary basis and can help any organization with managing risk and strengthening the cybersecurity of our Nation's critical infrastructure.