CISA's Cybersecurity Performance Goals (CPGs) define a baseline set of cybersecurity practices for all critical infrastructure sectors — cross-sector goals that any organization can implement, measure, and demonstrate. Critically, CPG 4.D explicitly requires tabletop exercises. Skyhigh maps to all 6 CPG categories and directly fulfills CPG 4.D's exercise requirement.
| CPG Category | Key Goals | Skyhigh Coverage | Evidence Generated |
|---|---|---|---|
| 1 — Account Security | 1.A MFA, 1.B Privileged accounts, 1.C Phishing-resistant MFA, 1.E Unique credentials | Direct | Credential theft scenarios test MFA effectiveness; account compromise exercises |
| 2 — Device Security | 2.A Asset inventory, 2.B Default passwords, 2.C EDR, 2.D Secure RDP, 2.E Patching | Direct | Vulnerability exploitation scenarios; default credential attacks; EDR gap analysis |
| 3 — Data Security | 3.A Mitigate known vulns, 3.B File backups, 3.C Encrypted DNS | Supporting | Ransomware recovery scenarios test backup viability; data protection gap analysis |
| 4.A — IR Plan | Maintain an up-to-date incident response plan | Core | Exercise validates IR plan; gaps surface missing procedures; AAR updates plan |
| 4.B — Awareness Training | Conduct annual security awareness training | Core | Each exercise = annual awareness training documentation evidence (CPG 4.B) |
| 4.D — Tabletop Exercises | Conduct tabletop exercises (explicit CPG requirement) | Core | Skyhigh exercise = direct CPG 4.D fulfillment with dated exercise record |
| 5 — Vulnerability Management | 5.A Asset inventory review, 5.B Third-party validation, 5.C Vulnerability disclosure | Direct | Attack path exercises surface unpatched systems; vulnerability management gaps |
| 6 — Supply Chain / Third-Party | 6.A Third-party vendor risk program, 6.B Critical software validation | Direct | Vendor compromise and supply chain attack exercises test third-party risk processes |
Skyhigh exercise evidence maps to multiple frameworks simultaneously. One exercise program — complete regulatory coverage.
CPG 4.D explicitly requires tabletop exercises. Launch your first CPG-mapped exercise today — free to start.