1 of 4
CISA Issues Rule
- CISA issued BOD 26-04 on June 10, imposing a 72-hour deadline and a rule that triggers when a flaw meets three of four criteria—public-internet exposure, known-exploited status, automated attack path, or attacker control, requiring agencies to verify prior compromise if four apply.
- It replaces a 15-day guidance, gives agencies 60 days to revise and 180 days to adopt, permits vendors to market tools for flagging, automating remediation, and patchless mitigation.
1 / 4
