BOD 19-02, Vulnerability Remediation Requirements for Internet-Accessible Systems
SupersededCISA · Binding Operational Directive · April 29, 2019
Summary
Required agencies to fix critical vulnerabilities on internet-facing systems within 15 days and high vulnerabilities within 30 days of detection by CISA scanning, and to send CISA a remediation plan when they missed a deadline.
Replaces
Replaced by
What FedXchange has recorded
No changes recorded. The watch records a new document and any change in its status.
- Issuer
- Cybersecurity and Infrastructure Security Agency (CISA)
- Type
- Binding Operational Directive
- Number
- BOD 19-02
- Issued
- April 29, 2019
- Status
- Superseded
Replaced by a newer document or edition.
Revoked and replaced by BOD 26-04 on June 10, 2026.
Get new governance by email
A weekly email on Fridays, an alert on the day the watch finds something new, or both. Free.