What CISA's new remediation directive means for CISOs | TechTarget
As patch management programs face mounting pressure from AI-driven threats and vulnerability discovery, CISA is pushing federal agencies toward risk-based remediation -- a move experts say will inevitably affect the private sector too.
CISA released a binding operational directive (BOD) on Wednesday requiring federal agencies to remediate the highest-risk flaws within three days and authorizing them to delay or defer addressing lower-severity flaws.
"The three-day remediation timeline provided is a pretty significant step up from the 14-day window CISA had on the previous BOD," said Erik Nost, an analyst at Forrester, adding that both public and private organizations should take note. "It's a signal that timelines are going to compress."
CISA told federal agencies to assess a bug's severity based on the following four factors:
- Exposure -- i.e., whether it is accessible on the internet.
- If the vulnerability has been actively exploited.
- If the exploitation of the flaw enables full...
Copyright of this story solely belongs to techtarget.com. To see the full text click HERE