Cybersecurity resource map

Industry Cybersecurity Links

Browse by industry first, then jump to the relevant laws, standards, controls, official guidance, free training, and reporting resources.

01

Healthcare and public health.

HIPAA Security Rule

Baseline cybersecurity obligation for covered entities and business associates that create, receive, maintain, or transmit ePHI.

HIPAA ePHI Administrative safeguards Technical safeguards

HHS healthcare cybersecurity guidance

Healthcare-sector threat briefings, practice guides, and operational resources for hospitals, clinics, providers, and health partners.

HHS 405(d) HICP HC3 Ransomware

CISA healthcare and cross-sector guidance

Healthcare-specific CISA resources plus cross-sector goals that help prioritize minimum viable cyber defense practices.

CISA HPH CPG 2.0 Incident response

02

Defense contractors and DIB.

FAR and DFARS contract clauses

Start here for federal contract information, covered defense information, cyber incident reporting, and NIST SP 800-171 assessment clauses.

FAR 52.204-21 DFARS 7012 DFARS 7019 DFARS 7020 DFARS 7021

CMMC and DoD documentation

Official DoD CMMC resource library for model guidance, scoping guides, assessment guides, and program references.

CMMC DIB Assessment scope

NIST CUI security requirements

Core CUI control requirements and assessment procedures used by defense contractors and other nonfederal organizations handling CUI.

NIST SP 800-171 800-171A CUI SPRS

DoD hardening and CUI training

DISA STIG baselines and government training resources for teams implementing defense-sector security requirements.

DISA STIGs DoD CUI DCSA training

03

U.S. federal government systems.

FISMA, RMF, and system categorization

Federal systems typically start with risk management, impact categorization, and minimum security requirements.

FISMA RMF FIPS 199 FIPS 200

NIST SP 800-53 Rev. 5

Federal control catalog used for security and privacy controls, baselines, assessment planning, and framework mappings.

800-53 Rev. 5 Control catalog Privacy controls

FedRAMP and federal cloud

Authorization resources for cloud services used by federal agencies and federal data environments.

FedRAMP Cloud authorization NIST baselines

Federal acquisition and OMB policy

Acquisition and policy references that often sit next to technical control work in federal cybersecurity programs.

FAR OMB A-130 Federal acquisition

04

Cloud and SaaS providers.

ISO/IEC 27000 series

Information security management standards for ISMS requirements, control selection, and security program governance.

ISO/IEC 27001 ISO/IEC 27002 ISMS

CSA STAR and Cloud Controls Matrix

Cloud assurance resources for provider transparency, questionnaire mapping, and cloud-specific control coverage.

CSA STAR CSA CCM CAIQ

CIS cloud benchmarks

Configuration hardening baselines for cloud platforms, operating systems, network devices, containers, and SaaS environments.

CIS Benchmarks Cloud hardening Configuration

Cloud application security

Application verification, API security, and secure development references for cloud-delivered products.

OWASP ASVS OWASP API NIST SSDF

05

Financial services.

FFIEC cybersecurity resources

Supervisory resources for financial institutions, third-party technology risk, cloud, authentication, exercises, and resilience planning.

FFIEC Third-party risk Cloud guidance

FTC Safeguards Rule and GLBA

Security program obligations for covered financial institutions under FTC jurisdiction and related customer information safeguards.

FTC Safeguards GLBA 16 CFR Part 314

DORA and operational resilience

EU digital operational resilience references for financial entities with ICT risk, incident reporting, testing, and third-party exposure.

DORA ICT risk Operational resilience

06

Critical infrastructure and OT.

CISA Cybersecurity Performance Goals

Cross-sector baseline security practices for critical infrastructure owners and operators.

CISA CPG 2.0 Baseline practices Governance

ICS and OT cybersecurity training

Free industrial control system cybersecurity training and CISA resources for operational technology defenders.

ICS OT Free training

Electric sector and NERC CIP

Reliability standards for bulk electric system cybersecurity and electric-sector security operations.

NERC CIP Bulk electric system Reliability

Incident reporting and sector support

CISA and federal reporting entry points for critical infrastructure incidents, vulnerabilities, phishing, malware, and ransomware.

CISA reporting IC3 StopRansomware

07

Education and public sector.

Student privacy and education data security

Security and privacy references for K-12, higher education, student records, cloud services, and education data handling.

FERPA Student data K-12 Higher education

State, local, tribal, and territorial security

Cybersecurity coordination, alerts, and shared services for public-sector organizations outside the federal enterprise.

SLTT MS-ISAC CISA services

Public safety and justice systems

References for law enforcement cybercrime reporting, public safety awareness, and criminal justice information security.

FBI IC3 CJIS Public safety

08

Software and product security.

OWASP application security

Common application risks, verification requirements, developer guidance, and API security references.

OWASP Top 10 ASVS API Security

Secure implementation references

Developer-focused cheat sheets and weakness lists for authentication, authorization, crypto, logging, and secure coding review.

OWASP Cheat Sheets CWE Top 25 Secure coding

NIST Secure Software Development Framework

Secure software development practices for organizing requirements, implementation, verification, release, and response work.

NIST SP 800-218 SSDF SDLC

09

Small business and general organizations.

CIS Controls and SANS resources

Prioritized controls, hardening benchmarks, templates, and practitioner resources that apply across most industries.

CIS Controls CIS Benchmarks SANS

10

Free government training.

CUI Training

Government-wide and DoD training for recognizing, marking, safeguarding, decontrolling, destroying, and reporting CUI incidents.

CUI DoD Federal contractors

CISA Learning and NICCS catalog

No-cost cybersecurity training, workforce development courses, and searchable learning paths.

CISA Learning NICCS Workforce

NIST NICE online learning

Free and low-cost cybersecurity learning content aligned to workforce development and practitioner growth.

NICE Workforce framework Online learning

11

Cyber agencies by region.

European Union

EU cybersecurity agency, institutional CERT, cybercrime support, and resilience regulation references.

EU ENISA NIS2 DORA

12

Alerts, vulnerabilities, and reporting.

CISA advisories and KEV catalog

Federal cybersecurity advisories and known exploited vulnerabilities for remediation prioritization.

CISA advisories KEV Remediation priority

NVD, CVE, and MITRE ATT&CK

Vulnerability records, identifiers, scoring references, and adversary technique knowledge base.

NVD CVE MITRE ATT&CK

Vendor security advisories

Product-specific update portals for tracking security releases and remediation guidance.

Microsoft Cisco Product security

Public reporting and recovery

Cybercrime, identity theft, and ransomware reporting or recovery resources for public-facing support situations.

IC3 Identity theft Ransomware