Cybersecurity and Infrastructure Security Agency (CISA)
22 Articles

NIST Can’t Keep Up. The Whole Digital Ecosystem Will Soon Feel It.
The United States is underinvesting in a key piece of public cyber infrastructure that many depend on to stay secure.

The Trump Administration Has a Cyber Strategy. Does It Have a Plan?
The real test will be whether clearer policy guidance, legal authorities, and institutional structures follow the Trump administration's Cyber Strategy for America.

The Just Security Podcast: What Just Happened – CISA and the Fate of U.S. Cybersecurity
As CISA faces expiration, former FBI official Cynthia Kaiser joins David Aaron to discuss its importance and highlight the risks of failing to reauthorize it.

The Next Cyber Breach Will Not Wait: Why Congress Must Reauthorize CISA 2015
Passing the WIMWIG Act to renew CISA 2015 is vital to defend the foundations of U.S. cybersecurity and technological superiority.

What It Takes to Stop the Next Salt Typhoon
A roadmap for the Trump administration to address cyber vulnerabilities that persist nearly a year after the Salt Typhoon intrusion.

The Just Security Podcast: A Conversation with Jen Easterly — Cybersecurity at a Crossroads
How do leaders steer through cyber crises and chart a path forward? Jen Easterly unpacks challenges, breakthroughs, and lessons from the front lines of U.S. cybersecurity.

Is the U.S. Abandoning the Fight Against Foreign Information Operations?
The Trump administration's policy shift paves the way for foreign propaganda to flourish, leaving Europe to step into the breach.

Biden’s Cybersecurity Executive Order and What Comes Next Under Trump
Regardless of what steps Trump takes next, Biden's cybersecurity EO reflects an important consensus on the evolving cyber threat landscape.

Software Backdoor is a Wakeup Call for Cybersecurity
As shown by the xz backdoor, relying on luck is not a sustainable cybersecurity strategy when much of the world depends on secure software.

Remote Sensing from Space: What Norms Govern?
"If recent excitement about spy balloons is any indication, it may be high time to prioritize a coherent international framework for remote sensing."

Congress Debates Cyber Incident Reporting Deadlines in the NDAA
The next NDAA could require cyber incident reporting for critical cyber infrastructure owners and operators within 24 or 72 hours of the incident.

US Cybersecurity Has a Metrics Problem. Here’s How to Fix It.
Lawmakers have taken critical steps this year, but the lack of data makes it hard to know whether U.S. cybersecurity is actually improving.