News

CISA issues guidance on reducing known exploited vulnerabilities

The Cybersecurity and Infrastructure Security Agency (CISA) has issued guidance to prioritize remediation of vulnerabilities presently actively exploited by adversaries.

Binding Operational Directive (BOD) 22-01 – Reducing the Significant Risk of Known Exploited Vulnerabilities establishes a CISA-managed catalog of known exploited vulnerabilities. It requires federal civilian agencies to address the vulnerabilities within specific timeframes.

“Every day, our adversaries are using known vulnerabilities to target federal agencies,” CISA Director Jen Easterly said. “As the operational lead for federal cybersecurity, we are using our directive authority to drive cybersecurity efforts toward mitigation of those specific vulnerabilities that we know to be actively used by malicious cyber actors. The Directive lays out clear requirements for federal civilian agencies to take immediate action to improve their vulnerability management practices and dramatically reduce their exposure to cyberattacks.”

Easterly noted, while the Directive applies to federal civilian agencies, there is the understanding organizations nationwide are targeted via the same vulnerabilities. She said it is critical every organization adopt the Directive and prioritize mitigation of vulnerabilities listed in the agency’s public catalog.

CISA personnel acknowledged the Directive applies to federal civilian agencies, but the agency recommends private businesses and state, local, tribal, and territorial (SLTT) governments prioritize addressing vulnerabilities and subscribe to receive notifications when new vulnerabilities are added.

Douglas Clark

Recent Posts

Embattled TikTok in jeopardy as President Biden signs legislative ban

The ByteDance-owned TikTok faces an uphill battle in the United States after President Joe Biden…

3 days ago

Raytheon begins $115M expansion of Alabama missile integration facility

Promising to grow space for integrating and delivering on critical defense programs by more than…

3 days ago

Reward offered for Iranian nationals charged over multi-year cyber campaign against U.S. companies

In unsealing a 13-page indictment this week, the U.S. Department of Justice (DOJ) revealed charges…

4 days ago

FEND OFF Fentanyl Act included in national security supplemental

A bill targeting the illicit fentanyl supply chain, the Fentanyl Eradication and Narcotics Deterrence (FEND)…

4 days ago

Pennsylvania earns $10M federal grant to improve crime statistics reporting

In order to move the state closer to federal standards and allow reporting of local…

5 days ago

DoD innovative technologies pilot funds 13 additional projects

For the next round of participants in a pilot program to Accelerate the Procurement and…

5 days ago

This website uses cookies.