Meeting M-24-04 IoT/OT Inventory and Reporting Requirements

Meeting M-24-04 IoT/OT Inventory and Reporting Requirements

This solution brief breaks down the new OMB FISMA requirements for 2024, explains why asset inventory in IoT and OT environments poses fundamentally different challenges than in traditional IT, and shows how the Nozomi Networks platform streamlines M-24-04 and CDM reporting so federal agencies can meet compliance deadlines with confidence.

Meeting M-24-04 IoT/OT Inventory and Reporting Requirements

WHITE PAPER

Meeting New OMB M-24-04 FISMA IoT and OT Inventory and Reporting Requirements in FY2024 1

M-24-04, the yearly reporting guidance from the U.S. Office

of Management and Budget’s Federal Information Security

Modernization Act (OMB FISMA) stepped out of the shadows

to provide a more comprehensive focus in 2024 than previous

years. The memorandum requires agency CIOs and CISOs to not

only engage more closely with the Continuous Diagnostics and

Mitigation (CDM) program, but mandates closer alignment with

BOD 23-01 by requiring OT and IoT asset inventory reporting by the

end of Fiscal Year 2024.

Many agencies are struggling with how to tackle the very different

asset inventory challenges between IoT/OT and IT environments.

This document outlines the new requirements and challenges, as

well how the Nozomi Networks platform streamlines this process,

including comprehensive and easy-to-automate M-24-04 and CDM

dashboards and reporting.

Introduction

MAPPING GUIDE

Meeting New OMB M-24-04 FISMA IoT and OT Inventory and Reporting Requirements in FY2024

https://www.whitehouse.gov/wp-content/uploads/2023/12/M-24-04-FY24-FISMA-Guidance.pdf https://www.cisa.gov/news-events/directives/bod-23-01-improving-asset-visibility-and-vulnerability-detection-federal-networks

WHITE PAPER

Meeting New OMB M-24-04 FISMA IoT and OT Inventory and Reporting Requirements in FY2024 2

The new FISMA guidance requires increasing

coordination with and visibility of CDM capabilities, as

well as the inclusion of IoT assets:

• Increasing coordination with and visibility of CDM

capabilities: Agencies are required to report at least

90 percent of Government furnished equipment

(GFE) through the CDM program, as articulated

in previous FISMA guidance and consistent with

the requirements of BOD 23-01, Improving Asset

Visibility and Vulnerability Detection on Federal

Networks. M-24-04 mandates agencies must

meet all the CDM Federal Dashboard reporting

requirements and in 2022, BOD 23-01 made it

compulsory for all FCEB agencies’ OT and IoT IP

addressable assets be integrated into the CDM

dashboard by April 2023.

• IoT inclusion: M-24-04 mandates agencies must

establish an enterprise-wide inventory of their

agency’s covered IoT assets by the end of FY 24.

Agencies must have a clear understanding of the

devices connected within their information systems

to gauge cybersecurity risk to their missions and

operations. This includes the interconnected devices

that interact with the physical world—from building

maintenance systems, to environmental sensors, to

specialized equipment in hospitals and laboratories.

New FISMA Requirements

Why Meeting M-24-04 Reporting Requirements with Legacy IT Tools Is a Challenge

Effectively managing OT and IoT assets presents unique

challenges. The nuances in process environments,

such as safety considerations, legacy or unmanageable

systems with long lifecycles, and proprietary protocols

across multiple vendor systems with known product

vulnerabilities make these assets increasingly complex

and interdependent. The potential impacts resulting

from operational risk, incidents or accidents can be

severe and unplanned for.

IoT devices are increasingly being deployed in federal

networks:

• To monitor critical functions, diagnose potential

issues, analyze and report on machine and

environment status updates

• Closely connected to real-time controllers that measure

the temperature of a cooling system, the efficacy of a

safety system, or the pressure in a pipeline

y As controlling elements incorporated into Building

Management Systems (BMS)

Many federal sectors are moving to adopt new levels

of connectivity between systems, networks, and

devices. Operating across distributed locations, they

are simultaneously implementing increasingly complex

SCADA architectures and IoT deployments to streamline

operations. The propagation of automated hacking and

botnets are a constant threat to the fidelity of IoT/OT

devices.

Creating an accurate asset inventory and keeping it

current can be difficult and extremely time-consuming.

Federal networks with OT and IoT devices contain many

devices from multiple vendors which may have security

vulnerabilities that may not be widely known as well as

proprietary communications protocols. Keeping track

of these OT and IoT devices, their status, configurations,

vulnerabilities, and more across cyber-physical

environments can be extremely challenging without

the right tools.

https://www.cisa.gov/news-events/directives/bod-23-01-improving-asset-visibility-and-vulnerability-detection-federal-networks https://www.cisa.gov/news-events/directives/bod-23-01-improving-asset-visibility-and-vulnerability-detection-federal-networks https://www.cisa.gov/news-events/directives/bod-23-01-improving-asset-visibility-and-vulnerability-detection-federal-networks

WHITE PAPER

Meeting New OMB M-24-04 FISMA IoT and OT Inventory and Reporting Requirements in FY2024 3

Nozomi Networks’ IoT and OT asset inventory

management solution automates device discovery,

validates details, and provides precise descriptions to

support effective risk mitigations. It collects information

such as:

• Device name, type, serial number, firmware version

and components

• Asset and subpart properties: site, name, IP address,

MAC address and state

• Embedded devices such as PLCs and their inner

components

• Logical node subsystems such as circuit breakers and

switches

• Measurement points

• PC operating system and installed software apps with

version numbers

• Endpoint configurations and behavior, including USB

activity, user activity and log file changes

Unlike other solutions on the market, our platform uses

a variety of data collection methods, including network

monitoring, endpoint monitoring and smart polling, to

provide continuous visibility into all your assets and their

risk levels, even when they aren’t actively communicating.

Our Asset Intelligence subscription enhances asset

information from millions of known device profiles,

enabling teams to make informed decisions about the

maintenance and security of their OT and IoT assets.

What New Devices Are in Scope for the FISMA 2024 Asset Inventory Requirement? Inventorying agency IoT assets, including those that

qualify as OT, is critical for ensuring the cybersecurity

posture of an enterprise, as these assets are increasingly

interconnected with IT hardware and software

Using National Institute of Standards and Technology

(NIST) definitions, OMB included both IoT and OT in

scope for inclusion in asset inventory requirements:

• Operational Technology (OT) as “programmable

systems or devices that interact with the physical

environment (or manage devices that interact

with the physical environment). These systems/

devices detect or cause a direct change through the

monitoring and/or control of devices, processes, and

events.” Examples include industrial control systems,

building management systems, fire control systems,

and physical access control mechanisms.

• Internet of Things (IoT) devices as those that have

at least one transducer (sensor or actuator) for

interacting directly with the physical world and at

least one network interface for interfacing with the

digital world.

WHITE PAPER

Meeting New OMB M-24-04 FISMA IoT and OT Inventory and Reporting Requirements in FY2024 4

How Nozomi Helps Agencies Meet M-24-04 IoT and OT Inventory Requirements

M-24-04 Requirements How Nozomi Networks Helps

1. Asset Identification: All devices and systems that meet the provided definition of covered IoT assets.

Nozomi’s IoT and OT asset inventory management solution automates device discovery, validates details, and provides precise descriptions to support effective risk mitigations.

2. Asset Description: Including make, model and any relevant specifications or configurations. Each asset should have a unique identifier, such as a serial or asset tag, to distinguish it from other assets.

Out of the box, Nozomi provides make, model, details and specific configurations. Although each asset is tagged with a unique identifier, Nozomi allows you to add your own tags to meet your naming conventions.

3. Asset Categorization: Factor in the device’s function, location, and criticality. Include the following information:

Nozomi has a flexible database that allows users to add new asset fields and tags to meet agency reporting requirements. Nozomi uses AI and machine learning along with our asset intelligence to classify assets by behavior and appearance.

a. Identification and/or description of specific agency FISMA and HVA systems associated with the asset; and

Nozomi provides flexible fields and add FISMA and HVA tags to every asset.

b. The physical location of the asset (e.g., building, floor, or room number).

Nozomi allows you to define fields like physical location to add information to meet M-24-04.

4. Owner/Point of Contact: The individual or office responsible for the asset’s management, administration, maintenance, and security.

Nozomi allows you to tag your assets based on your agency naming convention and specific information.

5. Vendor/Manufacturer Information: Details about the vendor or manufacturer (e.g., contact information and support channels.)

Nozomi identifies and reports vendor/manufacturer information for every asset it discovers.

6. Software and Firmware Versions: Where available, record the installed software and firmware versions, including relevant patches or updates applied to the asset.

With Nozomi’s deep packet inspection, we passively identify all firmware and software broadcasting on the wire and provide targeted smart polling and/or a lightweight endpoint agent to capture all data not displayed on the network.

7. Network Connectivity, Integrations and API Information: Include any static IP addresses and interconnective communication with other devices (e.g., uncommon ports, protocols).

Nozomi provides a graphical representation of the network connectivity for each asset we discover.

8. Security Controls: Describe alignment to requirements and controls, such as NIST SP 800- 213, SP 800-82, SP 800-53, and other standards and protocols.

With flexible tagging, Nozomi puts the ability to include any information required by M-24-04.

WHITE PAPER

Meeting New OMB M-24-04 FISMA IoT and OT Inventory and Reporting Requirements in FY2024 5

nozominetworks.com/demo

Let's get started To see the Nozomi Networks platform for yourself, schedule a demo.

Custom Demo

Nozomi Networks and the CDM Program

Nozomi Networks protects the world’s critical infrastructure from cyber threats. Our platform

uniquely combines network and endpoint visibility, threat detection, and AI-powered analysis

for faster, more effective incident response. Customers rely on us to minimize risk and

complexity while maximizing operational resilience.

© 2024 Nozomi Networks, Inc. | All Rights Reserved.

NN-M-24-04-MG-8.5x11-001

nozominetworks.com

The Cybersecurity and Infrastructure Security

Agency’s (CISA) CDM Program dynamically fortifies

the cybersecurity of civilian government networks and

systems with real-time risk monitoring and defense.

The CDM program provides cybersecurity tools,

integration services, and dashboards to participating

federal agencies to support them in improving their

respective security posture.

Available on the CDM APL, Nozomi Networks products

align perfectly with the CDM program’s goals by

delivering exceptional network and asset visibility,

threat detection, and insights for critical infrastructure

environments. Our solutions help reduce the threat

surface, speed response, and streamline reporting. Our

platform provides real-time, up-to-date continuous OT

and IoT asset inventory and has an API backend that

can be used to provide relevant data for ingestion into

the CDM dashboard.

Recognized as the market leader in OT and IoT security,

Nozomi Networks is valued for superior operational

visibility, advanced OT and IoT threat detection and

highly scalable deployments. Nozomi Networks

solutions support more than 105 million devices in

thousands of installations across government agencies

and critical infrastructure organizations worldwide.

Nozomi Networks has streamlined the process of

meeting M-24-04 inventory requirements with a

comprehensive dashboard and report for an agency’s

IoT and OT assets. This information can be automated

to integrate directly from Nozomi into the CDM

dashboard or a middlware collection tool.

https://www.nozominetworks.com/contact https://www.nozominetworks.com/demo


Item Type: pdf