CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

OMB M-26-14: Why federal agencies must fix asset visibility first

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2084

As cited

Copy frozen at (site build).

vulnerabilities

OMB M-26-14: Why federal agencies must fix asset visibility first

OMB Memorandum M-26-14 replaces the previous logging directive with a five-level maturity model that ties logging progress to asset visibility, requiring federal agencies to demonstrate 70-95% IT, OT, and IoT asset capture across increasingly stringent timelines. The directive organizes logging around continuous event monitoring and threat hunting, with overall maturity calculated using a lowest-watermark approach where incomplete inventory visibility caps an agency's entire rating regardless of other achievements. Agencies must close asset-inventory gaps immediately to meet strict deadlines, with level 1 maturity due 120 days after CISA publishes the logging reference architecture.

Why it matters: Federal agencies and their vendors must prioritize asset discovery now; incomplete inventory visibility will prevent any agency from advancing past level 1 maturity and delaying remediation creates compounding compliance risk under the lowest-watermark scoring model.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary