BOD 22-01
CISA Binding Operational Directive 22-01, which requires U.S. Federal Civilian Executive Branch agencies to remediate vulnerabilities listed in the Known Exploited Vulnerabilities catalog by a set deadline. CISA shortens the deadline when exploitation is widespread.