The U.S. Office of Management and Budget (OMB) has issued Memorandum M-26-14, a new directive for federal agencies focused on improving logging and network visibility. This memo replaces previous mandates with a five-level maturity model for logging, where progress is directly tied to an agency's ability to discover and inventory its IT, OT, and IoT assets. Achieving higher maturity levels requires progressively higher percentages of asset capture, making comprehensive asset visibility the foundational step for compliance.

The Office of Management and Budget (OMB) has released Memorandum M-26-14, a significant update to federal agency cybersecurity requirements, focusing on enhanced logging and network visibility. This new directive supersedes M-21-31, shifting away from broad data retention mandates towards a more structured, risk-based approach.
M-26-14 introduces a five-level logging maturity model, ranging from Level 0 to Level 4. Agencies must progress through these levels according to a strict timeline, which begins once the Cybersecurity and Infrastructure Security Agency (CISA) publishes its logging reference architecture (LRA). Each maturity level is contingent upon an agency's success in identifying and cataloging its assets.
Specifically, the directive mandates that agencies must achieve certain percentages of IT, OT, and IoT asset capture to meet each maturity level. Level 1 requires 70% asset visibility, Level 2 requires 80%, Level 3 requires 90%, and the optimal Level 4 requires 95%. This dependency highlights that effective log collection and analysis are impossible for assets that remain undiscovered.
The scope of M-26-14 explicitly includes operational technology (OT) and internet-of-things (IoT) devices, even those lacking native logging capabilities. This broad inclusion necessitates the use of passive asset discovery tools, as actively scanning some OT/IoT devices can be risky or impractical.
Agencies must reach Level 1 within 120 days, Level 2 within 180 days, and Level 3 within 320 days of the LRA's publication. A critical aspect of the maturity model is that an agency's overall rating is determined by its lowest-performing element, meaning a weakness in asset inventory can prevent advancement even if other areas are strong.
This foundational requirement for asset visibility addresses what is known as the 'denominator problem.' Since log coverage is measured as a percentage of the total asset inventory, an incomplete inventory directly limits an agency's ability to demonstrate adequate log coverage. This challenge is often exacerbated by administrative silos, air-gapped networks, and legacy systems that are difficult to inventory.
Vendors like Tenable, already integrated with federal systems through the Continuous Diagnostics and Mitigation (CDM) program, offer solutions that align with M-26-14's requirements. Their platforms provide comprehensive asset discovery across IT, OT, and cloud environments, serving as a crucial data source for meeting the inventory visibility milestones.
The directive also emphasizes the connection between asset visibility and the CISA Zero Trust Maturity Model, positioning visibility and analytics as key enablers for all zero-trust pillars. Furthermore, historical vulnerability data, provided by tools like Tenable's, can offer essential forensic context for post-incident investigations, complementing log data.



Anthropic pointed Claude Mythos Preview at 281 open-source projects and collected 23,019 candidate vulnerabilities. External security firms reviewed 1,900 of them. Maintainers received 1,596 reports and acknowledged 1,451; 97 fixes landed upstream, and 88 findings became published security advisories, with counts current as of May 22, 2026. The other 21,119 candidates have not been reviewed by any

Here’s a look at the most interesting products from the past week, featuring releases from BugBase, F5 Networks, Ping Identity, and Superna. F5 speeds up virtual patching to counter AI-driven threats With new features such as anomaly detection and agentic threat intelligence, F5’s AI-powered web application firewall (WAF) is capable in delivering real-time protections because of its strategic posi

Three critical vulns demand your attention, one a make-me-root mess in Nexus 9000 Series Switches that you can mitigate, not fix

Daybreak program brings subsidized models, training, and support to under-resourced teams