BOD 23-01: Improving Asset Visibility & Vulnerability Detection on Federal Networks

BOD 23-01: Improving Asset Visibility & Vulnerability Detection on Federal Networks

A binding operational directive (BOD) is a compulsory direction to federal, executive branch departments and agencies for purposes of safeguarding federal information and information systems. CISA has issued BOD 23-01 with requirements that focus on two core activities essential to improving operational visibility for a successful cybersecurity program: asset discovery and vulnerability enumeration.

BOD 23-01: Improving Asset Visibility & Vulnerability Detection on Federal Networks

1 SOLUTION BRIEF

Binding Operational Directive 23-01

SOLUTION BRIEF

Binding Operational Directive 23-01 Improving Asset Visibility and Vulnerability Detection on Federal Networks

Overview

Scope

A binding operational directive (BOD) is a compulsory

direction to federal, executive branch, departments

and agencies for purposes of safeguarding federal

information and information systems. CISA has issued

BOD 23-01 with requirements that focus on two core

activities essential to improving operational visibility for

a successful cybersecurity program: asset discovery

and vulnerability enumeration.

This directive applies to all IP-addressable networked

assets that can be reached over IPv4 and IPv6 protocols.

For the purpose of this directive, an IP-addressable

networked asset is defined as any reportable (i.e., non-

ephemeral) information technology or operational

technology asset that is assigned an IPv4 or IPv6

address and accessible over IPv4 or IPv6 networks,

regardless of the environment it operates in.

By April 3, 2023, all FCEB agencies are

required to take the following actions

on all federal information systems in

scope of this directive:

Read the Directive ›

a. Perform automated asset discovery

every 7 days.

b. Initiate vulnerability enumeration across

all discovered assets, including all

discovered nomadic/roaming devices

(e.g., laptops), every 14 days.

c. Initiate automated ingestion of

vulnerability enumeration results (i.e.,

detected vulnerabilities) into the CDM

Agency Dashboard within 72 hours of

discovery completion.

d. Develop and maintain the operational

capability to initiate on-demand asset

discovery and vulnerability enumeration

to identify specific assets or subsets of

vulnerabilities within 72 hours of receiving a

request from CISA and provide the available

results to CISA within 7 days of request.

https://www.cisa.gov/binding-operational-directive-23-01

2 SOLUTION BRIEF

Binding Operational Directive 23-01

Most agencies have worked for many years to understand their

IT assets and vulnerabilities, but few have focused on OT and

IoT asset and vulnerability discovery. BOD 23-01 has now made

it compulsory to understand all FCEB agency OT and IoT IP

addressable assets by April 2023.

We Deliver Cybersecurity and Analytics for All Your

Connected Devices

Nozomi Networks provides unparalleled OT and IoT visibility

and tracks vulnerabilities across all your ICS, OT and IoT devices.

Our visibility and security solutions provide immediate value

right out of the box—identifying all assets and protocols on the

network, with fewer false alarms than comparable solutions.

We deliver deeper insights based on AI, with more inherent

knowledge of devices, protocols and processes for pinpoint

accuracy. Because our solutions are purpose-built for OT and IoT

environments, we are able to provide insights and actionable

intelligence that are very pertinent to your environment. It’s also

easier to add sites and devices for faster time to resiliency and a

truly scalable solution for the largest organizations.

As validated by the largest number of customer reviews on Gartner Peer Insights, we

are the most trusted single source of truth for integrated OT, IT and IoT security and

insight. Our solution allows customers to anticipate interruptions, diagnose security

and process anomalies and respond to risks that could lead to operational and

business disruption, reputational damage and negative financial impact.

How Nozomi Networks Meets BOD 23-01 Requirements for OT and IoT

© 2022 Nozomi Networks, Inc. | All Rights Reserved.

NN-FEDGOV-SB-001

nozominetworks.com

BOD 23-01 Required Action How Nozomi Networks Meets It

a. Perform automated asset discovery every 7 days. Nozomi Networks provides always-on continuous OT

and IoT asset inventory that is always up-to-date.

b. Initiate vulnerability enumeration across all discovered assets,

including all discovered nomadic/roaming devices (e.g., laptops),

every 14 days.

Nozomi Networks provides always-on continuous

OT and IoT vulnerability scanning that is always

up-to-date.

c. Initiate automated ingestion of vulnerability enumeration results

(i.e., detected vulnerabilities) into the CDM Agency Dashboard within

72 hours of discovery completion.

Nozomi Networks has an open API backend that

can be used to provide relevant data for ingestion

into the CDM Dashboard.

d. Develop and maintain the operational capability to initiate on-demand

asset discovery and vulnerability enumeration to identify specific assets

or subsets of vulnerabilities within 72 hours of receiving a request from

CISA and provide the available results to CISA within 7 days of request.

Nozomi Networks provides always-on continuous

asset inventory vulnerability enumeration but also

has an on-demand active smart polling capability.

Nozomi Networks is an In-Q-Tel portfolio company.


Item Type: pdf