banner Expire 1 July 2024
Ad Ends 13 April 2024
banner Expire 15 July 2024
banner Expire 18 April 2024
ad End 18 October 2024
Ad Ends 13 July 2023
banner Expire 20 May 2024
What's new
Ad expire at 5 May 2024
UniCvv
CrdCrew.cc Carding forum
Western union transfer
banner expire at 21 August

Carding.pw carding forum
adv exp at 23 may

DHS ORDERS FEDERAL AGENCIES TO PATCH CRITICAL FLAWS WITHIN 15 DAYS

Daniel

TRUSTED VERIFIED SELLER
Staff member
Joined
Jun 13, 2020
Messages
6,486
Reaction score
890
Points
212
Awards
2
  • trusted user
  • Rich User



In recent years, we have seen how hackers prey on those too lazy or ignorant to install security patches, which, if applied on time, would have prevented some devastating cyber attacks and data breaches that happened in major organisations.

The United States Department of Homeland Security (DHS) has ordered government agencies to more swiftly plug the critical security vulnerabilities found on their networks within 15 calendar days since the initial detection, a reduction from 30 days.

DHS's Cybersecurity and Infrastructure Security Agency (CISA) this week issued a new Binding Operational Directive (BOD) 19-02 instructing federal agencies and departments to address "critical" rated vulnerabilities within 15 days and "high" severity flaws within 30 days of initial detection.

The countdown to patch a security vulnerability will start when it was initially detected during CISA's weekly Cyber Hygiene vulnerability scanning, rather than it was the first report to the affected agencies.
"As federal agencies continue to expand their Internet presence through increased deployment of Internet-accessible systems, and operate interconnected and complex systems, it is more critical than ever for federal agencies to rapidly remediate vulnerabilities that otherwise could allow malicious actors to compromise federal networks through exploitable, externally-facing systems," reads the memo from CISA Director Chris Krebs.
"Recent reports from government and industry partners indicate that the average time between discovery and exploitation of a vulnerability is decreasing as today’s adversaries are more skilled, persistent, and able to exploit known vulnerabilities."
Therefore, to minimize the risk of unauthorized access to any federal information internal system and reduce the overall attack surface, the CISA wants government agencies to review and remediate critical vulnerabilities on Internet-facing systems before hackers and cybercriminals exploit them.

The recently created CISA agency provides regular reports to the federal agencies on Cyber Hygiene scanning results and current status, informing them of the detected vulnerabilities, classified based on their CVSSv2 score.

Agencies who do not complete their remediation within the allotted time period, CISA will send an additional reminder to agencies, asking them to submit the complete remediation plan within three working days to CISA.
BOD 19-02 replaces BOD 15-01—Critical Vulnerability Mitigation Requirement for Federal Civilian Executive Branch Departments and Agencies' Internet-Accessible Systems (May 21, 2015)—which gave federal agencies 30 days to patch critical vulnerabilities.
 
Ad End 1 July 2024
Top