As cited
Copy frozen at (site build).
vulnerabilities
CISA BOD 26-04: Frequently asked questions about the new risk-based patching directive
CISA issued BOD 26-04, replacing the previous flat-deadline patching directive with a four-variable risk-based model that assigns remediation timelines ranging from three days for the highest-risk vulnerabilities to full deferral for the lowest-risk ones. The directive applies to federal civilian agencies and uses asset exposure, exploitation evidence, adversary automation capability, and technical impact severity to create a 16-tier remediation matrix. While mandatory only for federal agencies, CISA encourages private sector adoption, and the framework is expected to become an industry standard similar to its predecessor BOD 22-01.
Why it matters: Federal agencies must implement risk-based patching workflows immediately to meet the three-day remediation timeline for critical vulnerabilities, while private sector organizations should adopt the framework proactively as it becomes the de facto prioritization standard across industries.
- Source published
- First seen by Cybersecurity Tracker