On Monday, the Cybersecurity and Infrastructure Security Agency (CISA) issued Binding Operational Directive 23-01 (BOD 23-10), which requires Federal Civilian Executive Branch (FCEB) entities to maintain an inventory of all IPv4- and IPv6-networked assets, perform regular, periodic scans of these devices, and provide this information to CISA. The agency takes extra steps to allow for flexibility of means of accomplishing these tasks, and instead lists asset discovery and vulnerability enumeration as the primary goals, leaving it up to the individual organizations to develop and implement a plan to meet the standard. The target date for FCEB entities to meet the BOD is 3 April 2023, which specifies that vulnerability enumeration tasks should be initiated every 14 days and includes collection of metrics for analyzing the effectiveness of the chosen course of action.
12 Essentials for a Successful SOC Partnership
As cyber threats continue to impact businesses of all sizes, the need for round-the-clock security