CISA Closes Ten Emergency Directives After Federal Cyber Reviews
ID: 0764508a-1507-5d9e-9947-bdc3fee37aa8
STIX ID: report--0764508a-1507-5d9e-9947-bdc3fee37aa8
Feed Name: Infosecurity Magazine (News)
CISA has retired 10 Emergency Directives from 2019–2024 after confirming required remediations were completed or absorbed into ongoing controls such as Binding Operational Directive 22-01 and the Known Exploited Vulnerabilities (KEV) catalog. The retired directives covered issues including DNS tampering, Windows/Netlogon, SolarWinds Orion, Microsoft Exchange, Pulse Connect Secure, Windows Print Spooler, VMware vulnerabilities, and a nation-state compromise of Microsoft corporate email; three (19-01, 21-01, 24-02) were closed due to shifts in risk posture and operations. CISA emphasizes ongoing risk reduction through standardized directives and secure-by-design principles, while reserving Emergency Directives for urgent threats.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
