logo

CISA delivers new directive to agencies on securing cloud environments

ID: 43b960d4-b979-5506-9640-21d1a94f3f52

STIX ID: report--43b960d4-b979-5506-9640-21d1a94f3f52

Feed Name: CyberScoop

Date Published: 2024-12-17

Date Updated: 2026-04-21

Author: mbracken

...
...

CISA issued Binding Operational Directive (BOD) 25-01 requiring federal civilian agencies to identify and inventory all cloud instances, deploy Secure Cloud Business Applications (SCuBA) assessment tools, and align cloud environments with SCuBA configuration baselines. Deadlines include Microsoft 365 instance inventories by Feb 21, 2025; SCuBA assessment tool deployment by Apr 25, 2025; and implementation of required SCuBA policies by Jun 20, 2025. The directive is presented as a proactive, agency-wide effort to reduce cloud-related risk and will be supported and monitored by CISA.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.