CISA retires record number of emergency directives, marking shift in federal cyber defense
In a move set to advance federal cyber resilience and build stronger, safer digital infrastructure for America’s future, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) announced on Thursday the retirement of ten Emergency Directives issued between 2019 to 2024. This marks a significant milestone in federal cybersecurity, with the highest number of Emergency Directives retired by the agency at one time. These directives achieved their mission to mitigate urgent and imminent risks to Federal Civilian Executive Branch (FCEB) agencies.
Since their issuance, CISA has partnered closely with federal agencies to drive remediation, embed best practices, and overcome systemic challenges, establishing a stronger, more resilient digital infrastructure for a more secure America.
“As the operational lead for federal cybersecurity, CISA leverages its authorities to strengthen federal systems and defend against unacceptable risks, especially those related to hostile nation-state actors. When the threat landscape demands it, CISA mandates swift, decisive action by Federal Civilian Executive Branch (FCEB) agencies and continues to issue directives as needed to drive timely cyber risk reduction across federal enterprise,” Madhu Gottumukkala, CISA acting director, said in a media statement. “The closure of these ten Emergency Directives reflects CISA’s commitment to operational collaboration across the federal enterprise. Every day, CISA’s exceptional team works collaboratively with partners to eliminate persistent access, counter emerging threats, and deliver real-time mitigation guidance.”
Looking ahead, Gottumukkala indicated that the CISA continues to advance Secure by Design principles, vastly prioritizing transparency, configurability, and interoperability, so every organization can better defend their diverse environments.
The Emergency Directives that have now formally closed include the Emergency Directive 19-01 that addresses the mitigation of DNS infrastructure tampering. Emergency Directive 20-02 focused on mitigating Windows vulnerabilities disclosed during the January 2020 Patch Tuesday release. Emergency Directive 20-03 targeted the mitigation of a Windows DNS Server vulnerability from the July 2020 Patch Tuesday update. Emergency Directive 20-04 addressed the mitigation of a Netlogon elevation of privilege vulnerability disclosed in August 2020.
Emergency Directive 21-01 focused on mitigating the SolarWinds Orion code compromise. Emergency Directive 21-02 addressed vulnerabilities affecting Microsoft Exchange on-premises products. Emergency Directive 21-03 covered the mitigation of Pulse Connect Secure product vulnerabilities, while Emergency Directive 21-04 focused on mitigating a vulnerability in the Windows Print Spooler service. Emergency Directive 22-03 addressed the mitigation of VMware vulnerabilities. Most recently, Emergency Directive 24-02 focused on mitigating the significant risk posed by a nation-state compromise of Microsoft’s corporate email system.
Furthermore, Emergency Directives tied to specific Common Vulnerabilities and Exposures (CVEs) have been retired because those vulnerabilities are now included in CISA’s Known Exploited Vulnerabilities (KEV) catalog . These directives include EDs 2002, 2003, 2004, 2102, 2103, 2104, and 2203. For EDs 1901, 2101, and 2402, CISA determined that their objectives were achieved, requirements no longer align with the current risk posture, and changes in practices have rendered the directives obsolete.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
