# CISA cybersecurity guidance for US agencies

> Live situation record from CLSTR: https://clstr.news/situations/cisa-cybersecurity-guidance-for-us-agencies
> Updated: 2026-08-25T00:15:02.000Z. Sources: 2. Developments: 2.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued new technical guidance aimed at strengthening the security posture of federal agencies and critical infrastructure.

In late July 2026, CISA released a resource titled ‘Open Source Software: Security Principles and Practices.’ This guidance focuses on the adoption, vetting, and evaluation of open-source software and AI models, urging agencies to manage vulnerabilities and establish formal review processes to align with existing Executive Orders.

By late August 2026, CISA expanded its efforts by releasing the Logging Reference Architecture (LRA). This framework is designed to improve network monitoring and visibility through Continuous Event Monitoring (CEM) and Threat Hunting, Investigation, Response, and Forensics (THIRF). While primarily intended to help federal civilian agencies meet OMB requirements, CISA is encouraging state, local, and tribal governments, as well as critical infrastructure operators, to adopt the LRA as a benchmark for timely and reliable data collection.

## Timeline

### 2026-08-25: CISA releases logging guidance for federal agencies and critical infrastructure

CISA has released the Logging Reference Architecture, a guide designed to help federal agencies and critical infrastructure entities improve cyber defense through effective event logging and monitoring.

2 sources. https://clstr.news/cluster/cisa-releases-logging-guidance-for-federal-agencies-and-critical-infrastructure

### 2026-07-31: CISA Issues Guidance for Secure Use of Open‑Source Software by Federal Agencies

CISA released guidance urging U.S. federal agencies to adopt formal review, patching and risk‑assessment practices for open‑source software, citing recent bugs like Log4Shell and complying with Exec Orders 1414

2 sources. https://clstr.news/cluster/cisa-issues-guidance-for-secure-use-of-opensource-software-by-federal-agencies

---
Cite as: CISA cybersecurity guidance for US agencies. CLSTR, https://clstr.news/situations/cisa-cybersecurity-guidance-for-us-agencies
