CACybersecurity & Infrastructure Security Agency logo

Cybersecurity & Infrastructure Security Agency Unclaimed

Federal Agencies

www.cisa.gov

Arlington, VA, United States

CISA partners with government and industry to strengthen cybersecurity, physical security, and emergency readiness across the nation’s critical infrastructure.

Cybersecurity and Infrastructure Security Agency (CISA) is a U.S. federal agency within the Department of Homeland Security. It partners with government, industry, and other stakeholders to understand, manage, and reduce risk to cybersecurity, physical security, and emergency communications. CISA provides guidance, information sharing, incident response coordination, risk assessments, and technical assistance to strengthen the security and resilience of the nation’s critical infrastructure. It coordinates with SLTT governments, educational institutions, and private sector partners, delivering programs, resources, and services to protect essential services from cyber and physical threats.

CISA connects our stakeholders in government and industry to each other and to resources to help them increase their security and resilience across the cyber, physical, and emergency communications space.

What we offer

K-12 School Security Guide (3rd Edition)

Enhances school safety by providing comprehensive vulnerability assessment and security enhancement guidelines.

www.cisa.gov/resources-tools/resources/k-12-school-security-guide-3rd-edition

K-12 School Security Assessment Tool

Enhances K-12 school safety by identifying vulnerabilities and providing actionable security recommendations.

www.cisa.gov/school-security-assessment-tool

CISA Gateway

Streamline Cybersecurity Operations With Integrated Data Tools.

www.cisa.gov/resources-tools/services/cisa-gateway

CISA Tabletop Exercise Packages

Service

Enhance your organization's resilience with CISA's comprehensive tabletop exercise resources.

www.cisa.gov/resources-tools/services/cisa-tabletop-exercise-packages

Secure by Design Pledge

Service

Promotes secure software development through executive ownership and transparency.

www.cisa.gov/securebydesign/pledge

Market segments

Market size by segment

Growth potential (CAGR)

Threat intelligence sharing and incident coordination

3 Billion USD15% CAGR

Capabilities that collect, analyze, and share cyber and incident data to enable coordinated response, situational awareness, and information exchange across government and critical infrastructure partners.

Emergency preparedness and tabletop exercises

1.39 Billion USD8.9% CAGR

Resources and facilitation materials to design, run, and evaluate tabletop and crisis exercises that test response plans, roles, and interagency coordination.

K-12 campus security and vulnerability assessment

1.78 Billion USD11.2% CAGR

Tailorable assessment, planning, and guidance for K-12 campuses to identify vulnerabilities, implement layered physical security, integrate recommendations into safety plans, and train staff.

Secure product development governance

1 Billion USD18% CAGR

Policies and commitments that establish executive ownership, transparency, and measurable goals for adopting secure-by-design practices across product development and vendor roadmaps.

More information about our offering

K-12 School Security Guide (3rd Edition)

The K-12 School Security Guide (3rd Edition) provides a doctrine and systems-based methodology for vulnerability assessment, planning, and the implementation of layered physical security elements in K-12 campuses. It is part of the K-12 School Security Guide Product Suite, designed to help districts and campuses identify vulnerabilities, strengthen security, and better protect students and staff. This guide is complemented by several companions tailored for specific roles such as law enforcement officers and school business officials to further enhance security initiatives.

  • Enhances Security Protection
    This feature ensures that schools incorporate various security measures to create a robust safety framework.
  • Identifies Security Weaknesses
    Enables schools to pinpoint vulnerabilities, ensuring a more tailored and effective security strategy.
  • Enhance Security Planning
    Provides guidance on the vital role of law enforcement in assessing vulnerabilities and implementing security measures in schools.
  • Elevate Security Planning Role
    Highlights the critical role that school business officials play in devising and implementing effective security strategies at K-12 institutions.
  • Increases Preparedness
    Facilitates comprehensive training for staff and students, ensuring everyone knows how to respond to security threats.
  • Promotes Continuous Improvement
    Allows schools to regularly evaluate and enhance their security protocols based on current risks.

K-12 School Security Assessment Tool

The K-12 School Security Assessment Tool is a tailorable, web-based vulnerability analysis tool that walks users through assessment steps and provides results and recommendations that can be integrated into a school’s existing safety and security plans.

  • Integrates Security Recommendations
    This feature allows schools to seamlessly incorporate the tool’s findings into their ongoing safety strategies, enhancing overall readiness.
  • Customizes Assessment Process
    This allows schools to adapt the assessment process according to specific needs and circumstances, ensuring relevant and comprehensive vulnerability coverage.
  • Facilitates Effective Tool Use
    This resource ensures that personnel can navigate the assessment tool effectively, maximizing its benefits for school security planning.

CISA Gateway

CISA Gateway provides various data collection, analysis, and response tools in one integrated system, delivered through a single user registration, management, and authentication process.

  • Simplify Data Management
    Centralize your data workflows to enhance efficiency and response capabilities.
  • Streamline User Access
    Facilitate seamless user experiences with consolidated access points for all users.

CISA Tabletop Exercise Packages

CISA Tabletop Exercise Packages provide a comprehensive set of resources designed to help stakeholders conduct tabletop exercises and discuss responses to various threat scenarios within their organizations.

  • Facilitates Effective Training
    The comprehensive resources provided ensure that organizations can effectively conduct tabletop exercises, allowing teams to practice emergency response and evaluate their readiness against potential threats.
  • Tailor Exercises To Your Needs
    Stakeholders can customize tabletop exercises to reflect unique threats and vulnerabilities, ensuring that the training is relevant and impactful for their specific operational context.
  • Identify Areas For Improvement
    The evaluation tools allow organizations to assess their performance during the exercises, leading to actionable insights and enhanced preparedness.

Secure by Design Pledge

The Secure by Design Pledge is a voluntary commitment for software manufacturers to advance secure by design across enterprise software products and services, covering seven goals, with executive ownership, radical transparency, and public progress documentation.

  • Demonstrates Commitment to Security
    Executives are tasked with ensuring their products prioritize security, establishing accountability at the highest level.
  • Enhances Customer Trust
    By publicly sharing progress, manufacturers build trust with customers, showing their dedication to security.
  • Provides Clear Direction
    The structured goals form a framework for manufacturers to align their security practices with industry standards.

References

Methodology and sourcing behind the figures shown above.

Threat intelligence sharing and incident coordination

Estimated by triangulating multiple threat-intelligence market reports (2024–2026 reference points: market sizes $6–19B) and applying an informed share for the "sharing and incident coordination" subsegment (roughly 20–30% of the broader threat intelligence market). Chosen midpoint reflects the subsegment’s strategic importance for incident response, regulatory-driven adoption (NIS2, SEC), and faster growth versus legacy feeds.

Emergency preparedness and tabletop exercises

Primary estimate based on a dedicated Tabletop Exercise Services market report that explicitly values the global tabletop exercise market at USD 1.39B in 2025 and projects an 8.9% CAGR (2026–2034). Broader incident & emergency management market reports (Fortune Business Insights, MarketsandMarkets) and a U.S.-focused emergency management services report (Persistence) were used for context, showing much larger adjacent markets (USD 137–142B range) with ~6% CAGR and a U.S. services market of USD 43.3B (2026) at ~5.6% CAGR, supporting the tabletop segment’s positioning as a niche but faster-growing subset.

K-12 campus security and vulnerability assessment

Estimate derived by applying the reported K-12 share (~58% of school/campus security demand) to published total market figures and selecting a conservative mid-market CAGR. MarketResearchFuture reports a 2024 total market of $3.07B; applying the 58% K-12 share yields ~ $1.78B for K-12 vulnerability assessment and security services. Reported overall CAGRs vary widely (8.8%–20.6%); I use the market-growth reports’ 11.2% CAGR as a conservative, plausible growth rate for the K-12 segment.

Secure product development governance

No direct market reports for “secure product development governance” were provided in the search results. I triangulated an estimate from adjacent governance markets in the results: data governance (market sizes reported roughly USD 3–5.7B in mid-2020s) and AI/data-security governance (smaller current bases but higher growth). Secure product development governance is a narrower niche (governance/policy for secure-by-design across product lifecycles and vendor roadmaps), so I estimated a current global market ~USD 1.0B and a near-term growth potential (CAGR) of ~18%—between established data-governance growth (~15–20%) and faster-growing AI/governance segments (30%+), reflecting accelerating regulatory and secure-by-design adoption but narrower addressable scope.

Related Organizations