All terms

    Information Sharing and Analysis Organization

    A self-organized entity, authorized under the Cybersecurity Act of 2015, that gathers, analyzes, and shares cybersecurity threat information among members, including in the health sector.

    Reviewed by Christian Espinosa, Founder, Blue Goat CyberLast reviewed September 19, 2026

    Definition

    An ISAO is a voluntary organization created to gather, analyze, and disseminate cybersecurity threat information among its members and, where appropriate, with government partners. The concept was formalized in the Cybersecurity Act of 2015 and Executive Order 13691, which directed the Department of Homeland Security (now largely under CISA) to support the ISAO Standards Organization in developing voluntary standards for ISAO formation and operation. Unlike sector-specific Information Sharing and Analysis Centers (ISACs), which are organized around critical infrastructure sectors defined in Presidential Policy Directive 21, an ISAO can be organized around any community of interest, geography, or shared risk profile, making it a more flexible model. In MedTech, Health-ISAC operates as the principal health sector ISAC, and manufacturers may separately participate in ISAOs to fulfill FDA's expectation, stated in postmarket cybersecurity guidance, that manufacturers participate in an information sharing organization to receive and disseminate vulnerability and threat intelligence.
    What the regulation says
    The Cybersecurity Act of 2015 (Title I) authorizes the sharing of cyber threat indicators between private entities and the federal government through ISAOs, with liability protections for good-faith sharing conducted in accordance with the Act's requirements.

    What this means in practice

    FDA guidance references ISAO participation as a marker of a mature cybersecurity program and, for cyber devices under Section 524B, coordinated vulnerability disclosure processes commonly route disclosures through an ISAO or ISAC before public release. CISA maintains a list of standards developed by the ISAO Standards Organization covering ISAO creation, information sharing agreements, and privacy protections for shared data.
    Common pitfalls
    • Confusing an ISAO with an ISAC; ISACs are sector-specific and often more mature, while ISAOs can form around any shared interest and vary widely in rigor.
    • Assuming ISAO membership alone satisfies FDA's postmarket cybersecurity expectations without an internal vulnerability management process to act on shared intelligence.
    • Sharing threat data without following the liability-protection conditions in the Cybersecurity Act of 2015, which can expose the sharing entity to antitrust or privacy risk.

    Frequently asked questions

    Health-ISAC is organized as an Information Sharing and Analysis Center for the healthcare and public health sector, but it also performs ISAO-like functions and is commonly cited by FDA as an example of an appropriate information sharing venue for device manufacturers.
    Grouped by theme

    Editor's picks

    · Hand-selected related concepts
    Cited by

    Where this term appears across MedTech Terms.

    Sources

    3 sources

    Every citation below opens the original document. Each is graded against our source-tier hierarchy so you can see what rests on binding law versus commentary.

    Tier 1Binding law and standards· 1Tier 2Regulator guidance and consensus· 2
    Link health: 3 unchecked· last checked 2026-06-20
    CISA·1Congress.gov·1FDA·1
    1. 1
      CISA, Information Sharing and Analysis Organizations (ISAOs)
      Tier 2 Unchecked
      CISAcisa.gov
    2. 2
      Cybersecurity Act of 2015 (Title I)
      Tier 1 Unchecked
      Congress.govcongress.gov
    3. 3
      FDA Postmarket Management of Cybersecurity in Medical Devices (2016)
      Tier 2 Unchecked
      FDAfda.gov

    Inline markers like [1] jump to the matching reference above.