CISA Vulnerability Directive Designed to ‘Buy Back Time’ Against Hackers

Federal News Network – A top Cybersecurity and Infrastructure Security Agency official acknowledged that CISA’s recent directive on prioritizing software patches based on risk is a major cultural shift, but said it’s designed to give agency security teams time to focus on being more resilient against targeted cyberattacks. Jay Gazlay, acting associate director for vulnerability management at CISA, discussed the June 10 binding operational directive, which is mandatory for federal agencies to follow.

🔒 Members Only · Cyber & AI BriefYou’ve reached the member portion of this brief.Members read the full analysis and the source documents in every Brief, six days a week.