Open Source Software: Security Principles and Practices banner

CISA Releases New Guidance on Open Source Software Security Principles and Practices

Open source software drives innovation but demands careful oversight. Learn how to select, evaluate, and contribute to open source software projects with our new guidance on secure use, software supply chain, and AI-related risks.

Guidance: 2026 Minimum Elements for a Software Bill of Materials (SBOM)

2026 Minimum Elements for a Software Bill of Materials (SBOM)

This joint guidance includes refined baseline data fields, practices, and processes for SBOMs that reflect advancements driven by software community adoption.

Guidance: CI Fortify -  Advice for Isolating Vital Systems.

CISA and Partners Release Joint Guidance on Isolating Vital Operational Technology and Enabling Systems During Crisis

This CI Fortify guidance outlines practical steps for organizations to proactively isolate essential systems, minimize cyber risk through network separation, and ensure critical services stay operational and resilient during disruptions.

Joint Cybersecurity Advisory: Russian State-Supported Cyber Actors Conduct Phishing campaign targeting Users of Zimbra Collaboration Suite

CISA Releases Joint Cybersecurity Advisory on Russian State-Supported Threat Actors Targeting Zimbra Collaboration Suite Users

This advisory warns of Russian state-supported threat group LAUNDRY BEAR exploiting a known vulnerability in the Zimbra Collaboration Suite (ZCS) to exfiltrate sensitive data; includes indicators of compromise, mitigations, and remediation guidance.

Update. Joint Cybersecurity Advisory: Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure

CISA and Partners Update Joint Cybersecurity Advisory on Iranian-affiliated Cyber Actors Targeting Programmable Logic Controllers

This updated advisory provides new mitigations and indicators of compromise for internet-connected programmable logic controllers (PLCs) from multiple manufacturers used across U.S. critical infrastructure. 

Establishing a Coordinated Vulnerability Disclosure Program to Work With Security Researchers with an image of a lock on top of a computer chip repeated

NEW GUIDANCE ON ESTABLISHING COORDINATED VULNERABILITY DISCLOSURE PROGRAMS

This joint guidance helps software manufacturers and online service providers establish a framework for working with external security researchers to proactively find and fix vulnerabilities in their products.

JCDC unifies cyber defenders from organizations worldwide. This team proactively gathers, analyzes, and shares actionable cyber risk information to enable synchronized, holistic cybersecurity planning, cyber defense, and response.

StopRansomware.gov is the U.S. Government's official one-stop location for resources to tackle ransomware more effectively.

SAFECOM works to improve emergency communications interoperability across local, regional, tribal, state, territorial, international borders, and with federal government entities.

Additional CISA Resources

abstract cyber space

CISA Resources & Tools

CISA offers an array of free resources and tools, such as technical assistance, exercises, cybersecurity assessments, free training, and more.

Image of an event with speaker and participants

CISA Events

CISA hosts and participates in events throughout the year to engage stakeholders, seek research partners, and communicate with the public to help protect the homeland.

CISA Services Catalog

A single resource that provides you with access to information on services across CISA’s mission areas.

Employees pictured during training session

CISA Training

As part of our continuing mission to reduce cybersecurity and physical security risk, CISA provides a robust offering of cybersecurity and critical infrastructure training opportunities.