This page provides National Risk Management Center (NRMC) outreach materials, information, and guides. Download and share these NRMC resources to enhance critical infrastructure security and resilience.
New Resources
- Version 2 of the Threat Scenarios Report. Developed by the Information and Communications Technology (ICT) Supply Chain Risk Management (SCRM) Task Force's Threat Evaluation Working Group, the original report was updated to include scenario-specific impacts, potential threat mitigating strategies, and SCRM controls. This report is a voluntary resource to provide government and industry officials in procurement decision-making with example-based guidance on supplier SCRM threat analysis and evaluation.
- ICT SCRM Task Force Year Two Report: A report on the progress made by the ICT SCRM Task Force over the past year to advance meaningful partnerships and analysis around supply chain security and resilience. The report details the work of the Task Force’s working groups to address challenges to information sharing, threat analysis, qualified bidder and qualified manufacturer lists, vendor assurance, and impacts of the COVID-19 pandemic on ICT supply chains.
- Edge vs. Core - An Increasingly Less Pronounced Distinction in 5G Networks: A 5G resource to inform stakeholders about how edge computing increases the risks of untrusted components into 5G networks by moving core functions away from traditional network boundaries. The product is intended to provide an overview of edge computing and represents CISA’s analysis of the risks associated with installation of untrusted components into 5G infrastructures.
- Lessons Learned During The COVID-19 Pandemic: An analysis report which examines how the COVID-19 pandemic impacted the logistical supply chains of ICT companies. Developed by the ICT SCRM Task Force, the report focuses on key supply chain operational areas, such as inventory management, supply chain mapping/transparency, and supply chain diversity and provides recommendations on how organizations can increase their ICT supply chain resilience from future risks.
Fact Sheets
- ICT Supply Chain Risk Management (SCRM) Fact Sheet
- ICT Supply Chain Risk Management (SCRM) Task Force Fact Sheet
- National Critical Functions (NCF) Fact Sheet
- National Risk Management Center (NRMC) Fact Sheet
- Pipeline Cybersecurity Initiative (PCI) Fact Sheet
- Time - The Invisible Utility: two quick reference guides designed for organization leaders (corporate level) and IT professionals and staff (technical level) on the importance of accurate and resilient timing.
- Corporate-level Fact sheet (for organization leaders)
- Technical-level Fact sheet (for IT and staff)
Infographics and Graphic Novels
- 5G Basics Infographic
- 5G Market Penetration and Risk Factors Infographic
- ICT Supply Chain Risks Infographic
- ICT Supply Chain Risk Management (SCRM) Essentials
- National Critical Functions (NCF) Set
- Pipeline Cyber Risk Mitigation Infographic
- Port Facility Cybersecurity Risks Infographic
- Resilience Series: Real Fake Graphic Novel
Initiative Papers and Reports
- 5G: Edge vs. Core - An Increasingly Less Pronounced Distinction in 5G Networks *new resource
- 5G: Overview of Risks Introduced by 5G Adoption in the United States
- Electromagnetic Pulse (EMP) Program Status Report
- ICT SCRM: Paper on Executive Order 13873 Response: Methodology for Assessing the Most Critical Information and Communication Technologies (ICT) and Services
- NCFs: Status Update to the Critical Infrastructure Community
- NCFs: Overview of the National Critical Functions
-
- PNT: Time Guidance for Network Operators, Chief Information Officers, and Chief Information Security Officers
ICT Supply Chain Risk Management Task Force Reports
- ICT SCRM Task Force: Interim Report
- ICT SCRM Task Force: Lessons Learned During the Covid-19 Pandemic
- ICT SCRM Task Force: Threat Scenarios Report (Version 1)
- ICT SCRM Task Force: Threat Scenarios Report (Version 2) *new resource
- ICT SCRM Task Force: Year Two Report *new resource
- ICT SCRM Vendor Template: *coming soon
Election Security Resources
These voluntary resources were developed by the Election Infrastructure Subsector’s Government Coordinating Council (GCC) and Sector Coordinating Council (SCC) to assist election officials and voters prepare for impacts to possible COVID-19 related impacts to upcoming elections.
COVID-19 & Election Security
- Ballot Drop Box: Deploying ballot drop boxes in support of increased mail voting, including considerations like security, chain of custody, and estimating the number of boxes needed.
- Election Education and Outreach for Increased Absentee or Mail Voting: Strategies for outreach to legislators/policy makers, parties, campaigns, advocacy groups, voters, and others to educate them on absentee voting and vote by mail.
- Electronic Ballot Delivery and Marking: Helping jurisdictions determine whether expanded electronic ballot delivery and marking options is appropriate for them.
- Helping Voters to Request a Mail-in Ballot: Public messaging and outreach to apprise voters of the application process for requesting mail-in ballots.
- Importance of Accurate Voter Data When Expanding Absentee or Mail Ballot Voting: Risks associated with inaccurate voter records and considerations for securing voter registration data.
- Inbound Ballot Process: Receipt and processing of increased volume of inbound mail ballots.
- Managing an Increase in Outbound Ballots: FAQs and recommendations for working with vendors, the U.S. Postal Service, and others for handling increased volume of outgoing mail ballots.
- Signature Verification and Cure Process: Processes for verifying signatures and giving voters the opportunity to remedy rejected mail ballots.
- Vote By Mail / Absentee Voting Timeline – Excel and PDF: Lays out estimated lead times required for states to consider when implementing processes to support significant increases in mail-in voting.
In-Person Voting Materials
- Assisting Sick, Exposed, Symptomatic, and Quarantined Voters: Guidance with measures for election officials to consider to mitigate the spread of COVID-19 during the November elections.
- Considerations for Modifying the Scale of In-Person Voting: Guidance to election administrators conducting in-person voting on a different scale, and considerations for combining precincts and alternative vote centers.
- Finding Voting Locations and Poll Workers: Outlines challenges election officials may face procuring polling places and poll workers and considerations for increased physical and cybersecurity risks associated with in-person voting.
- Health and Safety at the Polling Place: Guidance to election administrators regarding personal protective equipment (PPE), cleaning and disinfecting, establishing procedures, and considerations for modifying poll working training.
- Innovative Practices and New Solutions Guide: Provides ideas and solutions to election officials on how to administer and secure election infrastructure.
- Safeguarding Staff and Work Environment from COVID-19: Outlines new safety measures, (i.e., isolating staff and regular disinfecting protocols), providing PPE, exposed employees, and cybersecurity considerations regarding remote work.
#Protect2020 Resources
- #Protect2020 Rumor vs. Reality: This web page addresses some common election-related rumors, provides factual information, and lists the resources to support these facts.
- Election Infographic Products: A set of five products designed to combat disinformation by equipping election officials, stakeholders, and voters with information on the mail-in voting, post election, and election result processes (which vary by state and/or jurisdictions).
- Mail-in Voting Processing Factors Map: A weekly-updated map that offers a visual of the movement in each state’s mail-in ballot processing.
- Mail-in Voting 2020 Policy Changes Map: A map that offers a visual of changes established to each state as a result of COVID-19.
- Mail-in Voting Election Integrity Safeguards Infographic: A product that provides the description and in-person equivalent for procedural and physical ballot safeguards.
- Post Election Process Mapping Infographic: A product that provides a timeline of post-election processes for the Presidential election from close of polls on Election Day, November 3, 2020, to Inauguration Day on January 20, 2021.
- Election Results Reporting Risk and Mitigations Infographic: A product that provides an overview of the risks associated with results reporting systems and how they are managed through mitigating measures.
- Note: CISA is committed to providing access to our webpages and documents for individuals with disabilities, both members of the public and federal employees. If the format of any elements or content within these documents interfere with your ability to access the information, as defined in the Rehabilitation Act, please email EISSA@cisa.dhs.gov. To enable us to respond in a manner most helpful to you, please indicate the nature of your accessibility problem and the preferred format in which to receive the material.
- Election Disinformation Toolkit: A toolkit for election officials to emphasize their role as “trusted voices” for election information, and to spread the importance of “we’re all in this together” in reducing the impacts of disinformation campaigns on the 2020 elections.
- Election Risk Profile Tool
- 3 P’s of Voting: An infographic to help voters understand the importance of their engagement (by being prepared, participating, and being patient) in the 2020 election season.
- Cyber Incident Detection and Notification Planning Guide for Election Security
- Election Infrastructure Cyber Risk Assessment and Infographic
- FBI-CISA Public Service Announcement - Spoofed Internet Domains Pose Cyber and Disinformation Risks to Voters: The FBI and CISA are issuing this announcement to help the public recognize and avoid spoofed election-related internet domains during the 2020 election year.
- FBI-CISA Public Service Announcement - Foreign Actors Likely to Use Online Journals to Spread Disinformation Regarding 2020 Elections: The FBI and CISA are issuing this announcement to raise awareness of the potential threat posed by foreign-backed online journals that spread disinformation regarding the 2020 elections.
- FBI-CISA Public Service Announcement - DDOS Attacks on Election Infrastructure Can Hinder Access to Voting Information, Would Not Prevent Voting: The FBI and CISA are issuing this announcement to raise awareness that Distributed Denial of Service (DDoS) attacks on election infrastructure can hinder access to voting information but would not prevent voting.
- FBI-CISA Public Service Announcement - False Claims of Hacked Voter Information Likely Intended to Cast Doubt on Legitimacy of U.S. Elections: The FBI and CISA are issuing this announcement to raise awareness of the potential threat posed by attempts to spread disinformation regarding cyberattacks on U.S. voter registration databases or voting systems.
- FBI-CISA Public Service Announcement - Cyber Threats to Voting Processes Could Slow But Not Prevent Voting: The FBI and CISA are issuing this announcement to inform the public that attempts by cyber actors to compromise election infrastructure could slow but not prevent voting.
- FBI-CISA Public Service Announcement - Foreign Actors and Cybercriminals Likely to Spread Disinformation Regarding 2020 Election Results: The FBI and CISA are issuing this announcement to raise awareness of the potential threat posed by attempts to spread disinformation regarding the results of the 2020 elections.
- Guide to Vulnerability Reporting for America’s Election Administrators
- Mail-in Voting in 2020 Infrastructure Risk Assessment and Infographic
- Physical Security of Voting Locations and Election Facilities
- The War on Pineapple: Understanding Foreign Interference in 5 Steps Infographic
- Social Media Bots Overview Infographic
- Disinformation Stops With You