Meeting M-24-04 IoT/OT Inventory and Reporting Requirements
This solution brief breaks down the new OMB FISMA requirements for 2024, explains why asset inventory in IoT and OT environments poses fundamentally different challenges than in traditional IT, and shows how the Nozomi Networks platform streamlines M-24-04 and CDM reporting so federal agencies can meet compliance deadlines with confidence.

WHITE PAPER
Meeting New OMB M-24-04 FISMA IoT and OT Inventory and Reporting Requirements in FY2024 1
M-24-04, the yearly reporting guidance from the U.S. Office
of Management and Budget’s Federal Information Security
Modernization Act (OMB FISMA) stepped out of the shadows
to provide a more comprehensive focus in 2024 than previous
years. The memorandum requires agency CIOs and CISOs to not
only engage more closely with the Continuous Diagnostics and
Mitigation (CDM) program, but mandates closer alignment with
BOD 23-01 by requiring OT and IoT asset inventory reporting by the
end of Fiscal Year 2024.
Many agencies are struggling with how to tackle the very different
asset inventory challenges between IoT/OT and IT environments.
This document outlines the new requirements and challenges, as
well how the Nozomi Networks platform streamlines this process,
including comprehensive and easy-to-automate M-24-04 and CDM
dashboards and reporting.
Introduction
MAPPING GUIDE
Meeting New OMB M-24-04 FISMA IoT and OT Inventory and Reporting Requirements in FY2024
https://www.whitehouse.gov/wp-content/uploads/2023/12/M-24-04-FY24-FISMA-Guidance.pdf https://www.cisa.gov/news-events/directives/bod-23-01-improving-asset-visibility-and-vulnerability-detection-federal-networks
WHITE PAPER
Meeting New OMB M-24-04 FISMA IoT and OT Inventory and Reporting Requirements in FY2024 2
The new FISMA guidance requires increasing
coordination with and visibility of CDM capabilities, as
well as the inclusion of IoT assets:
• Increasing coordination with and visibility of CDM
capabilities: Agencies are required to report at least
90 percent of Government furnished equipment
(GFE) through the CDM program, as articulated
in previous FISMA guidance and consistent with
the requirements of BOD 23-01, Improving Asset
Visibility and Vulnerability Detection on Federal
Networks. M-24-04 mandates agencies must
meet all the CDM Federal Dashboard reporting
requirements and in 2022, BOD 23-01 made it
compulsory for all FCEB agencies’ OT and IoT IP
addressable assets be integrated into the CDM
dashboard by April 2023.
• IoT inclusion: M-24-04 mandates agencies must
establish an enterprise-wide inventory of their
agency’s covered IoT assets by the end of FY 24.
Agencies must have a clear understanding of the
devices connected within their information systems
to gauge cybersecurity risk to their missions and
operations. This includes the interconnected devices
that interact with the physical world—from building
maintenance systems, to environmental sensors, to
specialized equipment in hospitals and laboratories.
New FISMA Requirements
Why Meeting M-24-04 Reporting Requirements with Legacy IT Tools Is a Challenge
Effectively managing OT and IoT assets presents unique
challenges. The nuances in process environments,
such as safety considerations, legacy or unmanageable
systems with long lifecycles, and proprietary protocols
across multiple vendor systems with known product
vulnerabilities make these assets increasingly complex
and interdependent. The potential impacts resulting
from operational risk, incidents or accidents can be
severe and unplanned for.
IoT devices are increasingly being deployed in federal
networks:
• To monitor critical functions, diagnose potential
issues, analyze and report on machine and
environment status updates
• Closely connected to real-time controllers that measure
the temperature of a cooling system, the efficacy of a
safety system, or the pressure in a pipeline
y As controlling elements incorporated into Building
Management Systems (BMS)
Many federal sectors are moving to adopt new levels
of connectivity between systems, networks, and
devices. Operating across distributed locations, they
are simultaneously implementing increasingly complex
SCADA architectures and IoT deployments to streamline
operations. The propagation of automated hacking and
botnets are a constant threat to the fidelity of IoT/OT
devices.
Creating an accurate asset inventory and keeping it
current can be difficult and extremely time-consuming.
Federal networks with OT and IoT devices contain many
devices from multiple vendors which may have security
vulnerabilities that may not be widely known as well as
proprietary communications protocols. Keeping track
of these OT and IoT devices, their status, configurations,
vulnerabilities, and more across cyber-physical
environments can be extremely challenging without
the right tools.
https://www.cisa.gov/news-events/directives/bod-23-01-improving-asset-visibility-and-vulnerability-detection-federal-networks https://www.cisa.gov/news-events/directives/bod-23-01-improving-asset-visibility-and-vulnerability-detection-federal-networks https://www.cisa.gov/news-events/directives/bod-23-01-improving-asset-visibility-and-vulnerability-detection-federal-networks
WHITE PAPER
Meeting New OMB M-24-04 FISMA IoT and OT Inventory and Reporting Requirements in FY2024 3
Nozomi Networks’ IoT and OT asset inventory
management solution automates device discovery,
validates details, and provides precise descriptions to
support effective risk mitigations. It collects information
such as:
• Device name, type, serial number, firmware version
and components
• Asset and subpart properties: site, name, IP address,
MAC address and state
• Embedded devices such as PLCs and their inner
components
• Logical node subsystems such as circuit breakers and
switches
• Measurement points
• PC operating system and installed software apps with
version numbers
• Endpoint configurations and behavior, including USB
activity, user activity and log file changes
Unlike other solutions on the market, our platform uses
a variety of data collection methods, including network
monitoring, endpoint monitoring and smart polling, to
provide continuous visibility into all your assets and their
risk levels, even when they aren’t actively communicating.
Our Asset Intelligence subscription enhances asset
information from millions of known device profiles,
enabling teams to make informed decisions about the
maintenance and security of their OT and IoT assets.
What New Devices Are in Scope for the FISMA 2024 Asset Inventory Requirement? Inventorying agency IoT assets, including those that
qualify as OT, is critical for ensuring the cybersecurity
posture of an enterprise, as these assets are increasingly
interconnected with IT hardware and software
Using National Institute of Standards and Technology
(NIST) definitions, OMB included both IoT and OT in
scope for inclusion in asset inventory requirements:
• Operational Technology (OT) as “programmable
systems or devices that interact with the physical
environment (or manage devices that interact
with the physical environment). These systems/
devices detect or cause a direct change through the
monitoring and/or control of devices, processes, and
events.” Examples include industrial control systems,
building management systems, fire control systems,
and physical access control mechanisms.
• Internet of Things (IoT) devices as those that have
at least one transducer (sensor or actuator) for
interacting directly with the physical world and at
least one network interface for interfacing with the
digital world.
WHITE PAPER
Meeting New OMB M-24-04 FISMA IoT and OT Inventory and Reporting Requirements in FY2024 4
How Nozomi Helps Agencies Meet M-24-04 IoT and OT Inventory Requirements
M-24-04 Requirements How Nozomi Networks Helps
1. Asset Identification: All devices and systems that meet the provided definition of covered IoT assets.
Nozomi’s IoT and OT asset inventory management solution automates device discovery, validates details, and provides precise descriptions to support effective risk mitigations.
2. Asset Description: Including make, model and any relevant specifications or configurations. Each asset should have a unique identifier, such as a serial or asset tag, to distinguish it from other assets.
Out of the box, Nozomi provides make, model, details and specific configurations. Although each asset is tagged with a unique identifier, Nozomi allows you to add your own tags to meet your naming conventions.
3. Asset Categorization: Factor in the device’s function, location, and criticality. Include the following information:
Nozomi has a flexible database that allows users to add new asset fields and tags to meet agency reporting requirements. Nozomi uses AI and machine learning along with our asset intelligence to classify assets by behavior and appearance.
a. Identification and/or description of specific agency FISMA and HVA systems associated with the asset; and
Nozomi provides flexible fields and add FISMA and HVA tags to every asset.
b. The physical location of the asset (e.g., building, floor, or room number).
Nozomi allows you to define fields like physical location to add information to meet M-24-04.
4. Owner/Point of Contact: The individual or office responsible for the asset’s management, administration, maintenance, and security.
Nozomi allows you to tag your assets based on your agency naming convention and specific information.
5. Vendor/Manufacturer Information: Details about the vendor or manufacturer (e.g., contact information and support channels.)
Nozomi identifies and reports vendor/manufacturer information for every asset it discovers.
6. Software and Firmware Versions: Where available, record the installed software and firmware versions, including relevant patches or updates applied to the asset.
With Nozomi’s deep packet inspection, we passively identify all firmware and software broadcasting on the wire and provide targeted smart polling and/or a lightweight endpoint agent to capture all data not displayed on the network.
7. Network Connectivity, Integrations and API Information: Include any static IP addresses and interconnective communication with other devices (e.g., uncommon ports, protocols).
Nozomi provides a graphical representation of the network connectivity for each asset we discover.
8. Security Controls: Describe alignment to requirements and controls, such as NIST SP 800- 213, SP 800-82, SP 800-53, and other standards and protocols.
With flexible tagging, Nozomi puts the ability to include any information required by M-24-04.
WHITE PAPER
Meeting New OMB M-24-04 FISMA IoT and OT Inventory and Reporting Requirements in FY2024 5
nozominetworks.com/demo
Let's get started To see the Nozomi Networks platform for yourself, schedule a demo.
Custom Demo
Nozomi Networks and the CDM Program
Nozomi Networks protects the world’s critical infrastructure from cyber threats. Our platform
uniquely combines network and endpoint visibility, threat detection, and AI-powered analysis
for faster, more effective incident response. Customers rely on us to minimize risk and
complexity while maximizing operational resilience.
© 2024 Nozomi Networks, Inc. | All Rights Reserved.
NN-M-24-04-MG-8.5x11-001
nozominetworks.com
The Cybersecurity and Infrastructure Security
Agency’s (CISA) CDM Program dynamically fortifies
the cybersecurity of civilian government networks and
systems with real-time risk monitoring and defense.
The CDM program provides cybersecurity tools,
integration services, and dashboards to participating
federal agencies to support them in improving their
respective security posture.
Available on the CDM APL, Nozomi Networks products
align perfectly with the CDM program’s goals by
delivering exceptional network and asset visibility,
threat detection, and insights for critical infrastructure
environments. Our solutions help reduce the threat
surface, speed response, and streamline reporting. Our
platform provides real-time, up-to-date continuous OT
and IoT asset inventory and has an API backend that
can be used to provide relevant data for ingestion into
the CDM dashboard.
Recognized as the market leader in OT and IoT security,
Nozomi Networks is valued for superior operational
visibility, advanced OT and IoT threat detection and
highly scalable deployments. Nozomi Networks
solutions support more than 105 million devices in
thousands of installations across government agencies
and critical infrastructure organizations worldwide.
Nozomi Networks has streamlined the process of
meeting M-24-04 inventory requirements with a
comprehensive dashboard and report for an agency’s
IoT and OT assets. This information can be automated
to integrate directly from Nozomi into the CDM
dashboard or a middlware collection tool.
https://www.nozominetworks.com/contact https://www.nozominetworks.com/demo