CISA CSET Download

What are the best tools and resources?  (THIS IS DATED - written in 2016. If you've got tools you'd like featured in this article, reach out to This email address is being protected from spambots. You need JavaScript enabled to view it.)

  • Turn in your business email to get links and downloads
  • CSF provides a cyber security model
  • Use: NIST Framework for Improving Critical Infrastructure Cybersecurity; Annex A
  • Determine Alignment to ISMS and NIST 800-53 or CCM or any standard ITGCC program
  • Download NIST Assessment Tool http://www.nist.gov/cyberframework/csf_reference_tool.cfm
  • Cyber Security Evaluation Tool
  • Download and install CSET https://www.us-cert.gov/forms/csetiso
  • HITRUST CSF 9.3 Resources – registration required
  • Offers manual mapping of controls for implementation of controls assessment of HITECH / HIPAA security and privacy rule using multiple frameworks and standards https://hitrustalliance.net/hitrust-csf/https://hitrustalliance.net/hitrust-csf/

Other Cyber Security Must Reads

CSF Process requires analysis of attack surface (read more at Secure Host Baselines & Common Security Framework CSF)

All of these industries require asset-level cyber security

All industries expect us to provide:

  • Board reports
  • Boss reports
  • Boss’s boss reports
  • Decision support systems
  • Security roadmap
  • Enable business
  • Drive IT Value

As an industry, our sensory system is overwhelmed

We need a fabric

What creates the threads that we can assert?

Ten normative references that totally rock the compliance world

  1. Benchmark contains both descriptive information and structural information
  2. Group  item that can hold other items
  3. Item three types of items: <xccdf:Group>, <xccdf:Rule> and <xccdf:Value>
  4. Model suggested scoring model for an <xccdf:Benchmark>
  5. Profile element is a named tailoring for an <xccdf:Benchmark>
  6. Rule the description for a single item of guidance or constraint. <xccdf:Rule> elements form the basis for testing a target platform for benchmark compliance
  7. Status acceptance status of an element with an optional date attribute, which signifies the date of the status change
  8. Tailoring element holds one or more <xccdf:Profile> elements-records additional benchmark tailoring
  9. TestResult element encapsulates the results of a single application of an <xccdf:Benchmark> to a single target platform
  10. Value a named parameter that can be substituted into properties of other elements within the <xccdf:Benchmark>

KEY IT Security and Risk resources

Main Menu