CISA to Require Federal Agencies to Patch Some Vulnerabilities Within 3 Days
ID: 11e0e4cd-574a-5b4f-969b-ca806906df83
STIX ID: report--11e0e4cd-574a-5b4f-969b-ca806906df83
Feed Name: Security Boulevard
CISA issued a binding operational directive requiring federal civilian agencies to adopt a risk-based vulnerability management process within 180 days and to patch vulnerabilities that meet at least three of four criteria (internet-exposed, in the Known Exploited Vulnerabilities catalog, automatable, and capable of giving attacker control) within 72 hours; non-automatable but actively exploited flaws have a two-week window, and agencies must perform compromise assessments before patching while state, local, and critical infrastructure operators are strongly urged to adopt similar practices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
