Federal Cybersecurity

BOD

Binding Operational Directive, a compulsory instruction CISA issues under 44 U.S.C. 3553(b) to federal civilian executive branch agencies for the purpose of safeguarding federal information and information systems. BODs carry the force of law for FCEB agencies and are time-bound: each directive includes specific actions and deadlines (BOD 22-01 set 14-day and 21-day remediation windows for vulnerabilities in the KEV Catalog, for example). BODs are the standing mechanism CISA uses for sustained programs; Emergency Directives address acute, time-critical threats.

The Authority Brief

One compliance analysis per week from Josef Kamara, CPA, CISSP, CISA. Federal and private compliance, written for practitioners.