Free and Government Resources

Below is a list of free cybersecurity resources offered to defense contractors and others by the United States Government either directly or by providing funding to third-party organizations. Although the table below includes a list of the NIST SP 800-171 requirement(s) that the service helps address, we do are not suggesting that any service will entirely satisfy any requirement, especially without configuration or monitoring.
Are we missing a resource? If so, please contact us with any additions!
| Provider | Name | Description | Relevant NIST SP 800-171 Rev. 2 Requirements |
|---|---|---|---|
| Cybersecurity & Infrastructure Security Agency Logging Made Easy(“LME”) (log management) | Logging Made Easy (“LME”) (log management) | CISA’s Logging Made Easy (LME) is a centralized, no-cost log management and threat detection solution for small to medium-sized organizations with limited resources that would otherwise have little to no functionality to detect attacks. LME offers centralized logging, proactive threat detection and enhanced security by allowing organizations to monitor their network, identify users, and actively analyze Sysmon data to quickly identify potential malicious activity. As a locally run application, CISA cannot access LME data, ensuring the privacy and security of organizations’ information. | 3.3.1, 3.3.3, 3.3.5, 3.3.6, 3.14.7 |
| National Security AgencyCentral Security Service | NSA Evaluated Products Lists | A listing of products which have been evaluated by the NSA and found to meet their requirements for destruction of media that contains Controlled Unclassified Information (“CUI”) and more sensitive information consistent with NSA/CSS Policy Manual 9-12, “Storage Device Sanitization and Destruction Manual”. | 3.8.3 |
| National Security AgencyCentral Security Service | Advisories & Technical Guidance | The NSA publishes a wide range of resources that help alert private entities to active, ongoing threats. These include lists of the top routinely exploited vulnerabilities and alerts (including sector-specific alerts) about active threats. NSA also publishes guidance for teleworking and mobile security, and for those in manufacturing and utilities, guidance on determining levels of hardware assurance for systems and custom microelectronic components, which include application-specific integrated circuits (ASICs), field programmable gate arrays (FPGAs) and other devices containing reprogrammable digital logic. | 3.2.1, 3.2.2, 3.2.3, 3.14.3 |
| National Security Agency Cybersecurity Collaboration Center | Protective Domain Name Services (DNS) | Blocks users from connecting to malicious domains to drive down risk and protect DOD information. Domain Name System (DNS) is essentially the address book of the internet and redirects a human-readable URL such as www.NSA.gov to the appropriate machine-readable IP address. Because DNS is so central to the internet, it’s frequently hijacked by adversaries to install malware and gain initial access to sensitive systems. | 3.13.1, 3.13.4 |
| National Security Agency Cybersecurity Collaboration Center | Attack Surface Management (Vulnerability Scanning) | Through this service, the NSA team takes an adversarial approach to illuminate any internet facing assets, searching for ways your network might be vulnerable. This allows NSA’s customers to identify and remediate issues before they become compromises. Each customer receives a tailored, prioritized report of issues for mitigation, along with an overview of their organization’s Internet footprint. | 3.11.2, 3.12.1, 3.12.2, 3.12.3, 3.14.1 |
| National Security Agency Cybersecurity Collaboration Center | Continuous Autonomous Penetration Testing | Penetration testing, or pentesting, is a critical security exercise for identifying vulnerabilities, validating security measures, and protecting sensitive data from falling into the wrong hands. The NSA’s Continuous Autonomous Penetration Testing (CAPT) leverages an AI powered platform to give small businesses a way to conduct their own pentests for internal networks at no cost and with no prior expertise. | 3.12.1, 3.12.3 |
| National Security Agency Cybersecurity Collaboration Center | Threat Intelligence Collaboration | Enter into a voluntary, mutually beneficial cyber threat information sharing relationship with the NSA. The NSA team will establish a secure collaboration channel with your cyber threat analysts and share non-public, DIB-specific threat intelligence to help you prevent, detect, and mitigate malicious cyber activity. This channel is also a way for your team to submit questions and feedback on findings related to the threat intelligence we share directly back with NSA. | 3.2.1, 3.2.2, 3.2.3, 3.14.3 |
| Defense Cyber Crime Center (“DC3”) | DoD-Defense Industrial Base (“DIB”) Collaborative Information Sharing Environment (“DCISE”) | DC3 DCISE facilitates public-private cyber threat information sharing, offers no-cost Cybersecurity-as-a-Service capabilities, and collaboration events with government and industry collaboration events. DC3 DCISE provides threat analysis, mitigation strategies, best practices, and exchanges for DIB participants of all sizes. DC3 DCISE also offers no-cost forensics, malware analysis, and cybersecurity services for DIB Partners. | 3.2.1, 3.2.2, 3.2.3, 3.14.3 |
| NIST | Manufacturing Extension Partnerships | The Manufacturing Extension Partnership (MEP) National Network is a public-private partnership that delivers comprehensive, proven solutions by helping small and medium-sized manufacturers grow, make operational improvements, and reduce risk. The MEP is committed to supporting manufacturers and building productive partnerships in all fifty states and Puerto Rico. Their goal is to ensure the competitiveness of U.S. manufacturing in the global economy. Whether you’re a manufacturer, an interagency partner, a state, local, territorial or tribal government, an accredited research institution or an entrepreneur looking to turn your manufacturing vision into reality, the MEP is here to help. |
