BOD 18-01, Enhance Email and Web Security
In effectCISA · Binding Operational Directive · October 16, 2017
Summary
Required agencies to set up email authentication that rejects spoofed messages within one year, encrypt mail in transit, and serve all public websites only over encrypted connections, dropping weak encryption protocols.
What FedXchange has recorded
No changes recorded. The watch records a new document and any change in its status.
- Issuer
- Cybersecurity and Infrastructure Security Agency (CISA)
- Type
- Binding Operational Directive
- Number
- BOD 18-01
- Issued
- October 16, 2017
- Status
- In effect
Still in force, possibly with amendments.
Still in force; DHS granted a temporary exception on September 20, 2018 for one mail-server encryption requirement.
Get new governance by email
A weekly email on Fridays, an alert on the day the watch finds something new, or both. Free.