The National Security Agency (NSA) has issued two Cybersecurity CSIs ) for employees working from home Information Bulletins ( . These bulletins primarily contain tips and recommendations for National Security System (NSS) employees , Department of Defense (DoD) employees, and system administrators to help them protect their networks and respond to security incidents .

The first CSI is titled “ Compromised Personal Network Indicators and Mitigations ” and provides information on how home-based workers can identify and respond to a potential breach of their personal networks. Employees must protect government- provided data and equipment when working remotely.
Additionally, the guidance contained in this CSI includes a series of indicators of compromise (IoC), along with mitigation techniques that employees working from home can implement to prevent future attacks and breaches. The NSA guidance is intended for government employees, but the information provided is useful for employees in all sectors.
“There is no way to ensure that personal networks will be completely secure from attacks. Attackers are persistent and continue to find ways to bypass security controls. Users can still take steps to help prevent future attacks,” says the NSA’s first CSI.
Users should implement the security recommended by the NSA on any computer, mobile device, or IoT device connected to their personal network.
Some of the steps to mitigate violations include:
- Restarting and resetting routers
- Disabling remote management function
- Regular firmware updates
- Disconnecting infected machines from the network
- Reset passwords
- Use reliable antivirus and malware
- Backup
The NSA guidelines also suggest more “aggressive actions” to help employees working from home protect their personal devices or network by effectively addressing threats.

The second NSA CSI is titled “Performing Out-of-Band Network Management” and is intended primarily for system administrators. In this guidance, information is provided on how to segregate traffic and networks to ensure that a compromised device or malicious activity does not impact the operations of the entire network.
“OoB [Out-of-Band] management creates a framework that allows administrators to improve the security of their networks by separating management traffic from operational traffic and ensuring that management traffic only originates from the OoB communication path,” explains the NSA.
As we read in SecurityWeek, the NSA recommends using encryption protocols and strong encryption algorithms, using VPNs, constantly monitoring the network, establishing procedures to detect malicious activity, and much more.
