Search
Background

CISA Releases Directives On Asset Discovery And Vulnerability Enumeration

On the 4th of October 2022 CISA released a binding operational directive 23-01 for improving asset visibility and vulnerability detection on federal networks. It can be seen here

The guidance is robust and focuses on frequency and coverage. It requires federal organisations to do the following, but the recommendations are applicable to all companies.

Implementation guidance is here

Below is a short mapping of the CISA directive and how Edgescan delivers its features.

Chickens come home to roost.
It’s clear that this should be a baseline approach to not just federal organisations but a minimum requirement for any business. When we review the past few years, most ransomware attacks were a result of a simple breach of systems like remote working services or unpatched firewalls (Exposed unmanaged services). This approach is an attempt to reduce the risk of breach via continuous visibility and vulnerability detection. Something Edgescan has been delivering since 2016!!

If you want to learn more about Edgescan, click the button below:

Related Articles

One of the first questions we get about Atomic is how we allow autonomous testing without giving an AI unrestricted …

Autonomous penetration testing raises a question before it raises interest. If an AI system is testing your applications and deciding …

Security does not stop after a penetration test. Applications keep evolving, attack surfaces keep growing, and yet confidence tends to …

Ready for security that is fast, accurate and quiet?
Experience the hybrid advantage of AI Scale + Human Validation.