CISA Binding Operational Directive (BOD) 23-01

View as Markdown

What is CISA Binding Operational Directive 23-01?

The Cybersecurity and Infrastructure Security Agency, part of the United States Department of Homeland Security, issued Binding Operational Directive (BOD) 23-01 in October 2022 to “make measurable progress toward enhancing visibility into agency assets and associated vulnerabilities.” BOD 23-01 has two primary objectives: asset discovery and vulnerability enumeration.

Who is the intended audience?

The Directive applies to all Federal Civilian Executive Branch (FCEB) departments and agencies of the United States government, and to any FCEB unclassified federal information systems.

Where can I find more information?

These resources are on the Cybersecurity and Infrastructure Security Agency website:

How can runZero help me with these controls?

BOD 23-01 requires FCEB departments and agencies to perform automated asset discovery every 7 days. This covers all IP-addressable assets across both IT and OT networks, on premises and in the cloud. runZero can continually discover assets across IT and OT networks with unauthenticated active scanning. It is especially suited to scanning critical IoT and OT systems because it uses only RFC standard traffic (no malformed packets) and does not attempt to exploit vulnerabilities, and you can adjust the scan rate for low bandwidth networks and legacy devices. runZero also integrates with Amazon Web Services, Google Cloud Platform, and Microsoft Azure to ingest compute instances, load balancers, and other cloud-based assets, giving you one view of every asset within the scope of BOD 23-01.

BOD 23-01 also calls for FCEB departments and agencies to initiate vulnerability enumeration across all discovered assets every 14 days. runZero integrates with vulnerability management platforms to ingest vulnerability data for every asset, so you get a single view of all discovered assets and their vulnerabilities. It can also help you find gaps in your vulnerability scanning, such as assets that have not been scanned for vulnerabilities in the last 14 days.

Related runZero resources

Updated