Topic
CISA Guidance and Directives
Reference hub on CISA directives, the KEV catalog, and the Zero Trust Maturity Model 2.0, read for what each implies about enforcement placement.
14 posts
CISA, the Cybersecurity and Infrastructure Security Agency, is the United States civilian cyber defense agency. It maintains the Known Exploited Vulnerabilities (KEV) catalog, issues binding operational directives to federal civilian agencies, and publishes zero trust and secure by design guidance that is used well beyond government.
Teams treat KEV as a patch queue and stop there. The pattern in the catalog says something else: the exploited product is frequently the control that was supposed to be the trust boundary, including VPN concentrators, file transfer appliances, network controllers, and endpoint agents. When that component falls, every protection layered behind it inherits the failure.
Posts under this hub read individual KEV entries for what they imply about enforcement placement, and work through the CISA Zero Trust Maturity Model 2.0, its Data pillar in particular, along with CISA guidance on operational technology and secure by design commitments. The Data pillar is the one where architecture, not procurement, decides the maturity stage.
Frequently asked questions
What is the CISA KEV catalog?
The Known Exploited Vulnerabilities catalog is the CISA list of vulnerabilities with confirmed active exploitation. Binding Operational Directive 22-01 requires federal civilian executive branch agencies to remediate listed vulnerabilities by the due date CISA assigns. Other organizations use it voluntarily as a prioritization signal, since entries reflect observed attacks rather than theoretical severity scores.
What are the pillars of the CISA Zero Trust Maturity Model?
The CISA Zero Trust Maturity Model 2.0 defines five pillars: Identity, Devices, Networks, Applications and Workloads, and Data. Three capabilities cut across all five: visibility and analytics, automation and orchestration, and governance. Each pillar is assessed against four maturity stages, running from Traditional through Initial and Advanced to Optimal.
Is patching a KEV vulnerability enough?
Patching closes one vulnerability. It does not change what an attacker reaches if the compromised component was the only thing standing between them and readable data. When a file transfer appliance or VPN concentrator is the trust boundary, its compromise exposes everything behind it, so the durable change moves enforcement onto the data object itself.
What does CISA Secure by Design ask software vendors to do?
Secure by Design asks vendors to own customer security outcomes rather than shipping hardening guidance and leaving the work to buyers. Its voluntary pledge sets goals covering multifactor authentication, elimination of default passwords, reduction of whole vulnerability classes, timely patching, vulnerability disclosure policies, and accurate CVE records. Signatories commit to showing measurable progress publicly.