BOD 23-01: Improving Asset Visibility & Vulnerability Detection on Federal Networks
A binding operational directive (BOD) is a compulsory direction to federal, executive branch departments and agencies for purposes of safeguarding federal information and information systems. CISA has issued BOD 23-01 with requirements that focus on two core activities essential to improving operational visibility for a successful cybersecurity program: asset discovery and vulnerability enumeration.

1 SOLUTION BRIEF
Binding Operational Directive 23-01
SOLUTION BRIEF
Binding Operational Directive 23-01 Improving Asset Visibility and Vulnerability Detection on Federal Networks
Overview
Scope
A binding operational directive (BOD) is a compulsory
direction to federal, executive branch, departments
and agencies for purposes of safeguarding federal
information and information systems. CISA has issued
BOD 23-01 with requirements that focus on two core
activities essential to improving operational visibility for
a successful cybersecurity program: asset discovery
and vulnerability enumeration.
This directive applies to all IP-addressable networked
assets that can be reached over IPv4 and IPv6 protocols.
For the purpose of this directive, an IP-addressable
networked asset is defined as any reportable (i.e., non-
ephemeral) information technology or operational
technology asset that is assigned an IPv4 or IPv6
address and accessible over IPv4 or IPv6 networks,
regardless of the environment it operates in.
By April 3, 2023, all FCEB agencies are
required to take the following actions
on all federal information systems in
scope of this directive:
Read the Directive ›
a. Perform automated asset discovery
every 7 days.
b. Initiate vulnerability enumeration across
all discovered assets, including all
discovered nomadic/roaming devices
(e.g., laptops), every 14 days.
c. Initiate automated ingestion of
vulnerability enumeration results (i.e.,
detected vulnerabilities) into the CDM
Agency Dashboard within 72 hours of
discovery completion.
d. Develop and maintain the operational
capability to initiate on-demand asset
discovery and vulnerability enumeration
to identify specific assets or subsets of
vulnerabilities within 72 hours of receiving a
request from CISA and provide the available
results to CISA within 7 days of request.
https://www.cisa.gov/binding-operational-directive-23-01
2 SOLUTION BRIEF
Binding Operational Directive 23-01
Most agencies have worked for many years to understand their
IT assets and vulnerabilities, but few have focused on OT and
IoT asset and vulnerability discovery. BOD 23-01 has now made
it compulsory to understand all FCEB agency OT and IoT IP
addressable assets by April 2023.
We Deliver Cybersecurity and Analytics for All Your
Connected Devices
Nozomi Networks provides unparalleled OT and IoT visibility
and tracks vulnerabilities across all your ICS, OT and IoT devices.
Our visibility and security solutions provide immediate value
right out of the box—identifying all assets and protocols on the
network, with fewer false alarms than comparable solutions.
We deliver deeper insights based on AI, with more inherent
knowledge of devices, protocols and processes for pinpoint
accuracy. Because our solutions are purpose-built for OT and IoT
environments, we are able to provide insights and actionable
intelligence that are very pertinent to your environment. It’s also
easier to add sites and devices for faster time to resiliency and a
truly scalable solution for the largest organizations.
As validated by the largest number of customer reviews on Gartner Peer Insights, we
are the most trusted single source of truth for integrated OT, IT and IoT security and
insight. Our solution allows customers to anticipate interruptions, diagnose security
and process anomalies and respond to risks that could lead to operational and
business disruption, reputational damage and negative financial impact.
How Nozomi Networks Meets BOD 23-01 Requirements for OT and IoT
© 2022 Nozomi Networks, Inc. | All Rights Reserved.
NN-FEDGOV-SB-001
nozominetworks.com
BOD 23-01 Required Action How Nozomi Networks Meets It
a. Perform automated asset discovery every 7 days. Nozomi Networks provides always-on continuous OT
and IoT asset inventory that is always up-to-date.
b. Initiate vulnerability enumeration across all discovered assets,
including all discovered nomadic/roaming devices (e.g., laptops),
every 14 days.
Nozomi Networks provides always-on continuous
OT and IoT vulnerability scanning that is always
up-to-date.
c. Initiate automated ingestion of vulnerability enumeration results
(i.e., detected vulnerabilities) into the CDM Agency Dashboard within
72 hours of discovery completion.
Nozomi Networks has an open API backend that
can be used to provide relevant data for ingestion
into the CDM Dashboard.
d. Develop and maintain the operational capability to initiate on-demand
asset discovery and vulnerability enumeration to identify specific assets
or subsets of vulnerabilities within 72 hours of receiving a request from
CISA and provide the available results to CISA within 7 days of request.
Nozomi Networks provides always-on continuous
asset inventory vulnerability enumeration but also
has an on-demand active smart polling capability.
Nozomi Networks is an In-Q-Tel portfolio company.