The Cybersecurity and Infrastructure Security Agency (CISA) and the Office of the National Cyber Director (ONCD) have jointly released a new playbook aimed at strengthening cybersecurity within federally funded infrastructure projects. This guide provides a framework, recommended actions, and model language for grant-making agencies to integrate cybersecurity into their programs. The primary objective is to improve the cyber resilience of critical infrastructure by ensuring that projects funded by federal grants are designed with security in mind from the outset. It is also intended to be a minimal burden on the federal grant awarding process.
The playbook offers a range of tools and resources for grant program managers and recipients, such as model language for funding opportunity announcements and terms, and templates. The document is advisory and non-binding, but it emphasizes the need for agencies to incorporate cybersecurity considerations throughout the lifecycle of their grant programs. It advises setting criteria for applying the playbook to specific projects, while also providing a mechanism to support the inclusion of baseline cybersecurity best practices. The playbook also targets critical infrastructure stakeholders and organizations involved in sub-awarding grant funds, to ensure wide-spread adoption.