The Cybersecurity and Infrastructure Security Agency has canned 10 emergency directives, issued between 2019 and 2024, after concluding they are no longer needed due to improved vulnerability tracking and remediation efforts, according to The Record, a news site by cybersecurity firm Recorded Future.CISA said the directives, which were issued under both Trump and Biden administrations, had served their purpose of addressing urgent cyber risks facing Federal Civilian Executive Branch agencies. Emergency directives are typically used to force agencies to quickly patch actively exploited flaws or halt risky activity. Following a review, CISA found that some directives were successfully implemented, while others became redundant after the related bugs were added to the Known Exploited Vulnerabilities catalog.Retired directives include those tied to several Microsoft flaws and one affecting VMware products. Three others were closed because their goals were met, and the risk environment had changed. All 10 directives are now marked as closed on CISA's website.
Critical Infrastructure Security, Vulnerability Management, Patch/Configuration Management
Multiple emergency directives retired by CISA after risk review
(Adobe Stock)
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
