Security Policy Alert: CISA List of Free Cybersecurity Services and Tools

February 18, 2022

TSA has asked AAAE to help to distribute the following message from DHS' Cybersecurity and Infrastructure Security Agency (CISA) to airport security and cybersecurity coordinators: 
 
"The Cybersecurity and Infrastructure Security Agency (CISA) announced today that it has compiled and published a list of free cybersecurity services and to ols to help organizations reduce cybersecurity risk and strengthen resiliency. This non-exhaustive living repository includes services provided by CISA, widely used open source tools, and free tools and services offered by private and public sector organizations across the cybersecurity community.   
 
CISA also strongly recommends organizations take the following foundational measures: 
 
1. Fix known security flaws in software.  
2. Implement multifactor authentication .  
3. Take steps to halt bad practices , including the use of end-of-life software products and systems that rely on known/default/unchangeable passwords. 
4. Sign up for CISA's Cyber Hygiene Vulnerability Scanning service .  
5. Get your Stuff Off Search (S.O.S.) .  

CISA encourages network defenders to take the steps above and consult the list of free cybersecurity services and tools to reduce the likelihood of a damaging cyber incident, detect malicious activity, respond to confirmed incidents, and strengthen resilience.  
 
As a reminder, CISA encourages all organizations to review the new Shields Up webpage to find recommended actions on protecting their most critical assets." 

As always, please do not hesitate to contact AAAE if you have any questions or need any additional information.