Skip to content

BOD 25-01, Implementing Secure Practices for Cloud Services

In effectCISA · Binding Operational Directive · December 17, 2024

Summary

Requires agencies to list their Microsoft 365 cloud tenants by February 21, 2025, run CISA's configuration assessment tools by April 25, 2025, and apply CISA's mandatory secure configuration settings by June 20, 2025.

Read it on www.cisa.gov

What FedXchange has recorded

No changes recorded. The watch records a new document and any change in its status.

Issuer
Cybersecurity and Infrastructure Security Agency (CISA)
Type
Binding Operational Directive
Number
BOD 25-01
Issued
December 17, 2024
Status
In effect

Still in force, possibly with amendments.

Get new governance by email

A weekly email on Fridays, an alert on the day the watch finds something new, or both. Free.

Send me

We use your address only to send what you choose, and every email has a one-click unsubscribe. Read the privacy notice.