U.S. Critical Infrastructure Cyber Community Voluntary Program: As part of Executive Order (EO) 13636, the Department of Homeland Security (DHS) launched the Critical Infrastructure Cyber Community or C³ (pronounced “C Cubed”) Voluntary Program to assist the enhancement of critical infrastructure cybersecurity and to encourage the adoption of the National Institute of Standards and Technology’s (NIST) Cybersecurity Framework (the Framework), released in February 2014. The C³ Voluntary Program was created to help improve the resiliency of critical infrastructure’s cybersecurity systems by supporting and promoting the use of the Framework.
Cyber Resilience Review (CRR): The CRR is a no-cost, voluntary, non-technical assessment to evaluate an organization’s operational resilience and cybersecurity practices. The CRR may be conducted as a self-assessment or as an on-site assessment facilitated by DHS cybersecurity professionals. The CRR assesses enterprise programs and practices across a range of ten domains including risk management, incident management, service continuity, and others. The assessment is designed to measure existing organizational resilience as well as provide a gap analysis for improvement based on recognized best practices.
Enhanced Cybersecurity Services for Critical Infrastructure Entities: The Department of Homeland Security’s (DHS) Enhanced Cybersecurity Services (ECS) Program was expanded in February 2013 by Executive Order 13636: Improving Critical Infrastructure Cybersecurity as a voluntary information sharing program. ECS assists critical infrastructure owners and operators to improve protection of their systems from unauthorized access, exploitation, or data exfiltration. ECS shares sensitive and classified government vetted cyber threat information with qualified Commercial Service Providers (CSPs) and Operational Implementers (OIs). In turn, the CSPs use the cyber threat information to protect their customers who are validated critical infrastructure entities. OIs use the cyber threat information to protect only their internal networks.
Protecting the Healthcare Digital Infrastructure: Cybersecurity Checklist: Cybersecurity Checklist can be used to help the Healthcare and Public Health Sector improve its ability to identify and address potential vulnerabilities; to mitigate cyber threats; and to strengthen cybersecurity. The checklist serves as a starting point on cybersecurity and it outlines several hardware, software, and cybersecurity educational items organizations should consider and implement to protect their digital infrastructure.
Healthcare and Public Health Cybersecurity Primer: Cybersecurity 101: The Healthcare and Public Health Cybersecurity Primer is a tool intended for use by sector members, owners and operators, as well as Federal, State and local partners who may not be cyber experts, but wish to improve the sector’s level of understanding of cybersecurity. The document contains concepts and common practices of security as they pertain to the cyber component of healthcare and public health.