CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0
Governance and Training

CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 CPG-4.B: OT Cybersecurity Leadership

Designate a leader specifically accountable for OT cybersecurity outcomes.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 14 controls across 9 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NISTSP82-2 OT Risk Assessment and Threat/Vulnerability Identification
  • NISTSP82-4 OT Access Control, Identity, Authentication, and Remote Access

API 1164 · 1 control

  • API1164-05 Network Segmentation and Zones

IEC 62443 · 1 control

  • IEC62443-05 Security policy for operational technology

IEEE 1686 · 1 control

  • IEEE1686-Scope-IED-Substation-Automation-2022-IEC-NERC-NIST-Coord IEEE 1686 - Scope + Intelligent Electronic Devices (IEDs) + Substation Automation + 2022 Edition + Coordination with IEC 62351 + IEC 62443 + NERC CIP + NIST SP 800-82

ISO/IEC 27019:2024 · 1 control

  • ISO27019-05 Security policy for operational technology

NIST SP 1800-32 · 1 control

  • SEMD-CS-1 Operational Technology Protection
  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Governance and Training

Query this from an agent

The graph holds this control, the 14 it maps to, and the evidence behind each claim, over MCP and REST.