cisa-cpg

Provides reference notes on CISA Cross-Sector Cybersecurity Performance Goals 2.0 aligned to NIST CSF 2.0.

5|1|Updated Jun 19, 2026
One-click install
npx skills add https://github.com/jgsystemsconsulting/jgs-se-knowledge-packs --skill cisa-cpg-jgsystemsconsulting
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cisa-cpg
Source: https://github.com/jgsystemsconsulting/jgs-se-knowledge-packs/tree/main/packs/cisa-cpg
Command: npx skills add https://github.com/jgsystemsconsulting/jgs-se-knowledge-packs --skill cisa-cpg-jgsystemsconsulting

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve? Security practitioners and critical-infrastructure operators struggle to recall and apply CISA's prioritized cybersecurity baseline mid-task, especially when mapping goals to NIST CSF 2.0 Functions or briefing executives on foundational IT/OT hygiene. ## Core Features & Use Cases - Goal lookup by Function: Query GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND, and RECOVER goals with outcome statements and recommended actions drawn from five chapter files. - Implementation guidance: Use patterns.md for When/How/Trade-offs playbooks such as first-mile control bundles, MSP trust boundaries, and OT-safe identity rollouts. - Quick reference: Consult the cheatsheet for decision rules, goal anchors, and common gap indicators, plus a glossary of CPG/CSF terms. - Use Case: Ask which CPG goals address MFA, segmentation, and backups before a board briefing, and receive the relevant goal IDs with chapter references. ## Quick Start Ask the agent which CISA CPG 2.0 goals cover MFA and network segmentation for an OT environment.

Frequently Asked Questions about cisa-cpg

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I find which CISA CPG goals cover MFA and segmentation?

Ask the skill about MFA or network segmentation and it returns the relevant PROTECT goals (3.F for MFA, 3.I for segmentation) with outcome language and recommended actions. The topic index in SKILL.md maps common terms to chapter files.

What changed between CPG 1.x and CPG 2.0?

CPG 2.0 adds the GOVERN function, renumbers and consolidates prior goals, and folds former OT-only goals into a universal IT/OT set aligned to NIST CSF 2.0. Chapter ch01 covers the changes and warns against reusing 1.x goal IDs in 2.0 trackers.

Does this pack cover the full NIST CSF 2.0 catalog?

No. The pack covers only the CISA CPG 2.0 prioritized baseline, not the full CSF 2.0 catalog, sector-specific goals in depth, or CSET tooling detail. It explicitly positions CPGs as a floor, not a complete program.

Can I use CPG goals for OT environments with safety constraints?

Yes. Chapter ch05 and the patterns file address OT-specific implementation, including staged credential rollouts, boundary controls instead of endpoint agents on fragile controllers, and safety-aware change management.

What are the limitations of the CPG baseline for compliance?

CPGs are a prioritized subset, not exhaustive assurance, and the pack does not provide organization-specific compliance scoring or legal interpretation of NSM-5. Users needing full control catalogs should consult broader frameworks like NIST CSF or 800-53.