As the central location for DHS cybersecurity and cyber risk management resources, the C³ Voluntary Program provides tools for download that enable organizations to learn more about the program, use the Framework, and talk about cyber risk management with their peers, customers, and stakeholders.
The CRR is a no-cost, voluntary, non-technical assessment to evaluate an organization’s operational resilience and cybersecurity practices. The CRR may be conducted as a self-assessment or as an on-site assessment facilitated by DHS cybersecurity professionals. The CRR assesses enterprise programs and practices across a range of ten domains including risk management, incident management, service continuity, and others. The assessment is designed to measure existing organizational resilience as well as provide a gap analysis for improvement based on recognized best practices. For additional information please see http://www.us-cert.gov/ccubedvp/self-service-crr.
After a CRR, participants will receive a report that includes options for consideration that provide general guidance aimed at increasing an enterprise’s cybersecurity posture and preparedness. This report may be used to support decision-making and help formulate cybersecurity investment justifications. The CRR Report is for the enterprise’s use only and DHS does not share the results. This information is afforded protection under the DHS Protected Critical Infrastructure Information (PCII) Program http://dhs.gov/pcii.
The C³ Voluntary Program Outreach and Messaging Kit includes informational materials provided in PDF format for easy printing and/or electronic distribution to help educate stakeholders about the C³ Voluntary Program. The kit includes:
- A Chief Executive Officer (CEO) Slick Sheet that provides information for CEOs regarding cyber risk management and information on the C³ Voluntary Program.
- Frequently Asked Questions (FAQs) about the C³ Voluntary Program in anticipation of common questions.
- A C³ Voluntary Program Promotional Infographic that provides an overview of the program.
The C³ Voluntary Program also provides customizable outreach and messaging materials to assist your organization with disseminating messaging about involvement with the C³ Voluntary Program, using your organization’s communication channels. The customizable materials are by request only and include:
- A sample leadership message that can be used to inform your organization’s involvement with the C³ Voluntary Program.
- A sample newsletter article that can be included in your organization’s regularly distributed newsletter or other forms of communication to announce its partnership with the C³ Voluntary Program.
- Sample messaging for blogs and social media language that can be disseminated on your organization’s digital platforms, including language for Facebook and Twitter, regarding involvement with the C³ Voluntary Program.
To request these materials, please email firstname.lastname@example.org.