CISA Orders Federal Agencies To Prioritize Patching Based On Cyber Risk
By CU Today Staff —
WASHINGTON—The Cybersecurity and Infrastructure Security Agency has issued a new directive requiring federal civilian agencies to overhaul how they prioritize software vulnerabilities, directing them to focus remediation efforts on the systems that pose the greatest cybersecurity risk.
The new Binding Operational Directive 26-04 replaces and updates earlier federal vulnerability-management requirements by requiring agencies to evaluate security flaws based on four factors: asset exposure, known exploited vulnerability status, exploit automation and the potential technical impact of a successful attack. CISA said the approach is designed to help agencies concentrate resources on the most dangerous vulnerabilities while reducing unnecessary patching efforts.
The agency said the directive reflects a threat environment in which cybercriminals and nation-state actors increasingly exploit unpatched vulnerabilities and may use artificial intelligence tools to accelerate attacks. The directive also adds new expectations for agencies to determine whether systems were already compromised before patches were applied, noting that installing a patch alone does not remove an attacker who has already gained access.
“CISA is empowering federal civilian agencies to focus their efforts on the areas of highest risk and defer patching lower priority vulnerabilities,” Acting CISA Director Nick Andersen said in a statement.
The agency said the directive supports the Trump Administration's executive order on advancing AI innovation and security and encourages organizations beyond the federal government to adopt similar risk-based vulnerability management practices.
Originally reported by CU Today.