U.S. Cybersecurity & Infrastructure Security Agency (CISA) Data Feeds
Cybersecurity & Infrastructure Security Agency (CISA) is the operational lead for federal cybersecurity and the national coordinator for critical infrastructure security and resilience. We are designed for collaboration and partnership. Learn about our layered mission to reduce risk to the nation’s cyber and physical infrastructure.
CISA works with partners to defend against today’s threats and collaborate to build a more secure and resilient infrastructure for the future.
The CISA and Archer integration allows you to centralize the RSS feeds from the CISA site and store the data in a searchable, standardized format within Archer. It captures and stores an abstract of the issue and a link to an external site (such as the regulatory news article) that helps to analyze regulatory news and alerts as they pertain to your organization's critical business processes.
On this page
Release notes
Release Date |
Version |
Comment |
---|---|---|
July 2024 |
2024.03 |
Recertified on Archer platform release 2024.03. Renamed installation package to reflect release version but no changes were made to the data feed |
July 2023 |
6.13 |
Initial Release |
Overview of U.S. Cybersecurity & Infrastructure Security Agency (CISA) Data Feeds Integration
Benefits
With the U.S. Cybersecurity & Infrastructure Security Agency (CISA) Data Feeds Integration, you will be able to:
-
Consolidate Regulatory Intelligence Data.
-
Get updates on recent events, current news and information.
-
Automatically pulls the data into Archer on a scheduled basis.
Prerequisites (ODA and system requirements)
Components |
Prerequisites |
---|---|
Archer Solution Area(s) |
Archer Regulatory & Corporate Compliance Management |
Archer Use Case(s) |
Archer Corporate Obligations Management |
Archer Applications |
Regulatory Intelligence Items |
Uses Custom Application |
No |
Requires On-Demand License |
No |
Archer Requirements |
Archer Platform Release 2024.03 and later |
Supported Archer Environments |
The following Archer environments are supported:
|
Additional resources
The following additional resources are available for this offering:
-
Subscribe to updates from CISA: https://www.cisa.gov/about/contact-us/subscribe-updates-cisa
U.S. Cybersecurity & Infrastructure Security Agency (CISA) Data Feeds Integration components
Architecture diagram
Business process
The business process follows the following flow:
-
CISA posts the most recent news, alerts, or updates on regulatory compliance on their website in several formats, including XML. This includes:
-
CISA - News
-
CISA – Blog
-
CISA - Cybersecurity Alerts & Advisories (all)
-
CISA – ICS Advisories
-
CISA – ICS Medical Advisories
-
-
-
The integration pulls the below mentioned data from the source: CISA website and imports the
data into Target: Archer’s Regulatory Intelligence Items application within the following fields:
-
title -> Title
-
Source -> Source
-
link -> Link
-
pubDate -> Date Published
-
link -> GUID
-
description -> Abstract
-
Installing U.S. Cybersecurity & Infrastructure Security Agency (CISA) Data Feeds Integration
Installation overview
This section provides instructions for configuring the offering. This document is not intended to suggest optimum installations or configurations.
It is assumed that the reader has both working knowledge of all products involved, and the ability to perform the tasks outlined in this section. Administrators should have access to the product documentation for all products to install the required components.
The prerequisite use case must be installed and working prior to the integration. Perform the necessary tests to confirm that this is true before proceeding.
Prerequisites (system requirements)
The Regulatory Intelligence Items application is required for installation and operation of this offering. It serves as a target application for the data feed.
Setting up data feed
The following data feed issued as a part of the integration process:
-
RegInt: CISA News is a RSS transporter feed which fetches the data from https://www.cisa.gov/news.xml site and creates/updates the records inRegulatory Intelligence Items Application.
-
RegInt: CISA Blog is a RSS transporter feed which fetches the data from https://www.cisa.gov/cisa/blog.xml site and creates/updates the records in Regulatory Intelligence Items Application.
-
RegInt: CISA Cybersecurity Alerts and Advisories All is a RSS transporter feed which fetches the data from https://www.cisa.gov/cybersecurity-advisories/all.xml site and creates/updates the records inRegulatory Intelligence Items Application.
-
RegInt: CISA ICS Medical Advisories is a RSS transporter feed which fetches the data from https://www.cisa.gov/cybersecurity-advisories/ics-medical-advisories.xml and creates/updates the records inRegulatory Intelligence Items Application
-
RegInt: CISA ICS Advisories is a RSS transporter feed which fetches the data from https://www.cisa.gov/cybersecurity-advisories/ics-advisories.xml site and creates/updates the records inRegulatory Intelligence Items Application.
For data feed configuration, perform the following steps:
-
Log into the Archer platform and click the Administration workspace tab.
-
Click Data Feeds in the Navigation Menu under Integration.
-
Click the Import link and browse to the [File_Name].dfx5.
-
Verify settings on the General Information tab. Be sure to change the status to Active before using the feed.
-
Verify the settings on the Transport tab.
Note: Default Retrieval Count is set to 1 Day. Update this as per your requirement.
-
Verify the settings on the Source Definition tab. This will be pre-configured to identify the necessary fields to generate a score snapshot.
Note: The Source value is set in Source Parsing Tab -> File Definition to avoid value loss if fields are re-load in Source Definition tab.
-
Verify the settings and mappings on the Data Map tab.
Note: If an article with same GUID is provided by multiple feeds, then Source is replaced in the record. If you want to append the source information, update the field configuration to allow multiple values in selection and then update the data mapping configuration to append for the Source field.
-
The Key Definition fields should be pre-populated based on the information from the DFX import file. Ensure that the Key Definition field (GUID) is set.
-
The final configuration step is to schedule the data feed. Click the Run Configuration tab and configure the frequency and start time of the Data Feed.
-
Click Save to apply your configuration to the data feed. Click on Run Now to run the data feed immediately. Click the data feed status (Completed/Faulted/Warning etc) link for additional information on the status of the feed or to troubleshoot any feed errors.
Certification environment
Date tested: July 2024
Product Name |
Version Information |
Operating System |
---|---|---|
Archer |
2024.03 |
Windows |