Comply with CISA Binding Operational
Directive (BOD) 23-01
Sepio’s Asset Risk Management Platform helps you to painlessly fulfill the BOD 23-01 requirements.
CISA Binding Operational Directive (BOD) 23-01
The Cybersecurity and Infrastructure Security Agency (CISA) issued a Binding Operational Directive (BOD) on October 3, 2022 that requires all Federal Civilian Executive Branch (FCEB) agencies to improve asset visibility and vulnerability detection on federal networks. This directive is an extension of the President’s Executive Order on Cybersecurity (14028).
All FCEB agencies must take action and report to CISA by April 3, 2023.
How can Sepio help you with the required CISA BOD 23-01 controls?
By April 3, 2023, all FCEB agencies must deploy an updated continuous diagnostics and mitigation (CDM) Dashboard configuration that enables access to object-level vulnerability enumeration data for CISA analysts. Agencies must demonstrate their ability to:
- Perform automated asset discovery of all IP-addressable assets every 7 days
- Initiate vulnerability enumeration every 14 days
- Upload vulnerability results into the Continuous Diagnostics and Mitigation (CDM) Agency Dashboard within 72 hours
- Initiate asset discovery and vulnerability on demand as required within 72 hours
Sepio’s Asset Risk Management (ARM) platform fulfills all of the above controls in an easily deployed solution, at scale.
CISA leverages the CDM Program’s DEFEND A vehicle to procure Sepio.
Learn more about Cybersecurity Asset Management
Take Control of Your Network Assets.
Sepio delivers physical‑layer AssetDNA and real‑time vulnerability detection – giving you unmatched control over your network devices.