CISA vulnerability directive designed to ‘buy back time’ against hackers | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


A top CISA official acknowledged the BOD is a major cultural shift, but says it should give security teams more time to focus on work that matters.

A top Cybersecurity and Infrastructure Security Agency official acknowledged CISA’s recent directive on prioritizing software patches based on risk is a major cultural shift, but said it’s designed to give agency security teams time to focus on being more resilient against targeted cyber attacks.

Jay Gazlay, acting associate director for vulnerability management at CISA, said the June 10 binding operational directive, which is mandatory for federal agencies to follow, is about “correcting some mistakes we made with previous BODs.”

The BOD tells agencies to use a tailored approach to software patching, directing them to patch the most urgent vulnerabilities on CISA’s Known Exploited Vulnerabilities list faster, while allowing for more regular patch cycles for some of the lower-risk vulnerabilities.

The directive was driven in large part by advancements in the ability of artificial intelligence models to identify and exploit cyber vulnerabilities.

“We, for many years, have talked to agencies about how they should prioritize patching, and even though we made the best decisions we possibly could, several years ago, we were telling them to do things that were really inefficient,” Gazlay said during an Aug. 27 LinkedIn event hosted by CISA. “So what we’re doing here is we’re articulating where they should spend their time patching, and more importantly, where they shouldn’t spend their time patching.”

The directive is focused on accelerating patches for devices that are connected to the internet, which are considered “exposed” to hackers.

Agencies will have to patch the highest-risk vulnerabilities within three days. Historically, federal patching deadlines have averaged between two and three weeks. But for less risky vulnerabilities, such as those that are present only on internal systems, agencies will generally have more time to make patches under CISA’s new rules.

Gazlay, a former systems administrator, said spending less time and effort on patches that “don’t matter” should make life easier for security teams.

“Taking those off the table makes a certain group of people really happy,” Gazlay said. “Other folks – information system managers, the [Government Accountability Office], [Office of Inspector General], compliance folks, [it’s a] big shift. And so there’s been a lot of creative tension between operators and our compliance organizations, and there’s been a really healthy dialog. They seem to be buying in so far, and we’re happy to continue it.”

Gazlay said CISA is helping agencies implement the risk management approach through the Continuous Diagnostics and Mitigation (CDM) dashboards and automated services.

Meanwhile, CISA recently announced that the Treasury Department’s new AI vulnerability clearinghouse, “Gold Eagle,” is augmenting the cyber agency’s Vulnerability Information and Coordinated Environment (VINCE) platform.

“With the increased volume of AI-discovered vulnerabilities, we will adapt and create new tooling that supports the core VINCE platform,” CISA said in a fact sheet. “Gold Eagle serves as a powerful additional source of vulnerability reporting at scale.”

Gazlay commented that AI models will only continue to improve, while cyber threat groups will also continue to gain stronger capabilities to target U.S. networks.

“We want to have people have more time to make sure they have the right monitoring coverage,” Gazlay said. “We want to make sure that entities and organizations have more time back to work on making sure they have a good identity platform. We want to make sure organizations have more time back in their outage windows to maybe do some backup and restore testing… Incidents happen to all of us, all the time. How do you be resilient against them? It’s the only thing at this point.”

Copyright
© 2026 Federal News Network. All rights reserved. This website is not intended for users located within the European Economic Area.



——————————————————-


Click Here For The Original Source.