Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

CISA Binding Operational Directive (BOD) 23-01 requires Federal Civilian Executive Branch (FCEB) agencies to maintain current asset visibility, routinely enumerate vulnerabilities, measure scanning performance, and send results to the Continuous Diagnostics and Mitigation (CDM) Federal Dashboard. The directive was issued October 3, 2022, with April 3, 2023 set as the principal deadline for core capabilities. It is a federal requirement, not a voluntary security recommendation.

What BOD 23-01 is

“Improving Asset Visibility and Vulnerability Detection on Federal Networks” is a binding operational directive issued by the Cybersecurity and Infrastructure Security Agency (CISA) under federal authorities. It applies to covered FCEB unclassified information systems, including systems operated by another organization on an agency’s behalf when they handle agency information.

The directive excludes statutorily defined national security systems and certain systems operated by the Department of Defense or the Intelligence Community. It also does not make every cloud service or short-lived workload a reportable asset.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

CISA explains the purpose plainly: “Asset visibility is not an end in itself, but is necessary for updates, configuration management, and other security and lifecycle management activities that significantly reduce cybersecurity risk, along with exigent activities like vulnerability remediation.”

Which assets and systems are covered

The directive’s asset definition focuses on non-ephemeral information-technology and operational-technology assets with an IPv4 or IPv6 address reachable across the agency’s networks. Examples include:

  • Servers and workstations
  • Virtual machines
  • Routers, switches, firewalls and other network appliances
  • Network-connected printers
  • On-premises, roaming and cloud-deployed assets

Roaming laptops and other devices outside agency premises are included when the agency can discover and enumerate them. Ephemeral assets such as containers, and third-party-managed software-as-a-service solutions, are excluded from the directive’s asset definition.

Systems operated by contractors or other providers

Delegating operation does not automatically remove a system from scope. If the system is an FCEB unclassified information system and collects, processes, stores, transmits, disseminates or otherwise maintains agency information, the agency must account for it under the directive’s applicability rules.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Discovery and vulnerability enumeration are different jobs

Asset discovery

Discovery identifies network-addressable assets and their host IP addresses. CISA characterizes it as non-intrusive and generally not requiring special logical-access privileges. Possible approaches include active scanning, passive flow monitoring, log queries and API queries into software-defined infrastructure.

Vulnerability enumeration

Enumeration examines discovered assets to determine their attributes and suspected vulnerability posture. It can collect operating-system and application details, open ports, missing updates, outdated software, configuration weaknesses and matches to known vulnerabilities. Appropriate privileges are important; CISA identifies credentialed network scans and endpoint clients or agents as ways to obtain the necessary information.

Discovery therefore answers “what is connected?” Enumeration answers “what is running on it, and what weaknesses can be identified?” Meeting one requirement does not satisfy the other.

Required compliance cadence and deadlines

Requirement Required timing What agencies should be able to demonstrate
Automated asset discovery At least every 7 days Coverage of the agency’s entire IPv4 space, with reportable assets identified
Vulnerability-enumeration cycle Initiate every 14 days All discovered assets, including discovered roaming devices, enter the process
Detection-signature updates No more than 24 hours after a vendor releases an update Scanning content remains current rather than relying on stale signatures
CDM vulnerability-result ingestion Within 72 hours after discovery completes, or after a new cycle begins when the prior full cycle has not completed Automated transfer to the agency’s CDM Dashboard
CISA-requested on-demand work Initiate discovery and enumeration within 72 hours of a request Available results provided within 7 days
Performance-data collection Within 6 months after CISA publishes its performance-data requirements Reporting of relevant cadence, rigor and completeness measures to the CDM Dashboard

CISA recognizes that a complete enterprise vulnerability scan can take longer than 14 days. The obligation is still to start the process at least every 14 days so that scanning proceeds on a regular cadence within the required window; agencies should not wait for a previous long-running cycle to finish before initiating the next one.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The directive set April 3, 2023 for the principal asset-discovery, enumeration, ingestion and on-demand-capability actions. It also called for an updated CDM Dashboard configuration that would let CISA analysts access object-level vulnerability-enumeration data by that date. That historical deadline does not establish whether any particular agency is compliant today.

Credentialed, mobile and off-premises coverage

Where technology supports it, agencies must use privileged credentials for managed endpoints and network devices to the maximum extent possible. A credentialed network scan or an installed client/agent can satisfy this intent. Agencies must also perform equivalent enumeration on mobile and other off-premises devices when the capability is available.

In practice, an agency’s evidence should show which assets are covered by privileged or client-based methods, which are unreachable, and why a different method is necessary. Specialized equipment or systems that cannot use privileged credentials may use an alternative discovery or enumeration method only with CISA approval.

How CDM reporting fits into compliance

The CDM Agency Dashboard is the required reporting destination for automated vulnerability results. Agencies need an ingestion path that can meet the 72-hour timing rule and preserve enough asset and finding detail for federal oversight. A scanner that produces useful local reports but cannot deliver results to CDM on time does not meet the complete workflow.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Agencies should track at least:

  • When each discovery and enumeration cycle started and finished
  • Which address ranges and asset classes were included
  • Whether roaming, mobile and cloud assets were reached
  • Whether privileged or client-based collection was used
  • When signatures were updated relative to vendor release
  • When results entered the CDM Dashboard and whether ingestion failed
  • Exceptions, approved alternatives and remediation of coverage gaps

Responding to a CISA request

  1. Trigger the capability within 72 hours. Start on-demand asset discovery and vulnerability enumeration when CISA requests it.
  2. Continue the enterprise process even if it is lengthy. A scan that cannot finish within the requested interval should still begin promptly; CISA requires available results within seven days.
  3. Preserve the evidence. Keep timestamps, scope, methods, exclusions, partial results and delivery records so the agency can explain what was and was not available.

Performance oversight and agency reporting

The directive identifies cadence, rigor and completeness as performance dimensions. Within six months after CISA publishes the applicable performance-data requirements, agencies must begin collecting and reporting the relevant measures through the CDM Dashboard.

At six, 12 and 18 months after issuance, agencies were expected either to provide CISA a CyberScope progress report covering obstacles, dependencies, issues and expected completion dates, or to use the CDM program review process to identify and resolve gaps. CISA also stated that it would monitor compliance, provide assistance on request, publish common-schema performance requirements, review the directive within 18 months and report implementation status to federal leadership.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Choosing an implementation approach

BOD 23-01 is outcome-based. It does not mandate a particular vendor or one scanning technique. Agencies can compare approaches against the requirements that matter:

  • Coverage: entire IPv4 space, IPv6 assets where applicable, roaming and mobile devices, cloud deployments and reportable OT
  • Collection quality: privileged network scanning or client-based detection where feasible
  • Cadence: seven-day discovery, 14-day enumeration initiation and 24-hour signature currency
  • Integration: reliable automated delivery to the CDM Agency Dashboard within 72 hours
  • Response: ability to start requested work within 72 hours and supply available results within seven days
  • Exceptions: documented CISA approval for alternative methods used on specialized or incompatible systems

The directive describes capabilities and results, not a required hardware purchase or software product. An agency can meet the technical outcomes with different combinations of scanners, endpoint clients, passive monitoring, log analysis and infrastructure APIs.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Common compliance mistakes

  • Treating a once-per-quarter inventory as satisfying the seven-day discovery requirement
  • Counting a network ping or unauthenticated scan as full vulnerability enumeration
  • Ignoring laptops and mobile devices because they are often off the agency network
  • Allowing signatures to remain unchanged after a vendor publishes updates
  • Completing scans locally but missing the 72-hour CDM-ingestion deadline
  • Assuming a long-running scan excuses failure to initiate the next 14-day cycle
  • Using an unapproved alternative method for specialized equipment
  • Assuming the 2023 deadline alone proves present-day compliance

What agencies should verify now

  1. Map the directive’s scope to the agency’s FCEB unclassified systems and document exclusions.
  2. Confirm automated discovery covers at least the complete IPv4 space every seven days.
  3. Verify that vulnerability enumeration starts at least every 14 days and includes all discovered assets.
  4. Test credentialed or client-based collection on managed endpoints and network devices.
  5. Measure mobile, roaming, cloud and off-premises coverage rather than assuming it.
  6. Confirm signatures are updated within 24 hours of vendor release.
  7. Test CDM ingestion timing and investigate failed or partial transfers.
  8. Run an on-demand exercise that demonstrates the 72-hour start and seven-day result windows.
  9. Record performance measures, exceptions and CISA approvals in an audit-ready evidence set.

What BOD 23-01 does not establish

The directive does not prescribe a single commercial product, guarantee a particular reduction in incidents, or publish an agency-by-agency current compliance score. CISA’s directive index lists separate implementation guidance intended to help agencies interpret the requirements, but detailed answers in that guidance should be checked against the current CISA publication before being treated as controlling agency policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.