Skip to content

BOD 18-01, Enhance Email and Web Security

In effectCISA · Binding Operational Directive · October 16, 2017

Summary

Required agencies to set up email authentication that rejects spoofed messages within one year, encrypt mail in transit, and serve all public websites only over encrypted connections, dropping weak encryption protocols.

Read it on www.cisa.gov

What FedXchange has recorded

No changes recorded. The watch records a new document and any change in its status.

Issuer
Cybersecurity and Infrastructure Security Agency (CISA)
Type
Binding Operational Directive
Number
BOD 18-01
Issued
October 16, 2017
Status
In effect

Still in force, possibly with amendments.

Still in force; DHS granted a temporary exception on September 20, 2018 for one mail-server encryption requirement.

Get new governance by email

A weekly email on Fridays, an alert on the day the watch finds something new, or both. Free.

Send me

We use your address only to send what you choose, and every email has a one-click unsubscribe. Read the privacy notice.