LIVE · cybersecurity feed
Live wire
federal governmenthigh

OMB M-26-14: Why federal agencies must fix asset visibility first

The U.S. Office of Management and Budget (OMB) has issued Memorandum M-26-14, a new directive for federal agencies focused on improving logging and network visibility. This memo replaces previous mandates with a five-level maturity model for logging, where progress is directly tied to an agency's ability to discover and inventory its IT, OT, and IoT assets. Achieving higher maturity levels requires progressively higher percentages of asset capture, making comprehensive asset visibility the foundational step for compliance.

zeroday.news · 25d ago

The Office of Management and Budget (OMB) has released Memorandum M-26-14, a significant update to federal agency cybersecurity requirements, focusing on enhanced logging and network visibility. This new directive supersedes M-21-31, shifting away from broad data retention mandates towards a more structured, risk-based approach.

M-26-14 introduces a five-level logging maturity model, ranging from Level 0 to Level 4. Agencies must progress through these levels according to a strict timeline, which begins once the Cybersecurity and Infrastructure Security Agency (CISA) publishes its logging reference architecture (LRA). Each maturity level is contingent upon an agency's success in identifying and cataloging its assets.

Specifically, the directive mandates that agencies must achieve certain percentages of IT, OT, and IoT asset capture to meet each maturity level. Level 1 requires 70% asset visibility, Level 2 requires 80%, Level 3 requires 90%, and the optimal Level 4 requires 95%. This dependency highlights that effective log collection and analysis are impossible for assets that remain undiscovered.

The scope of M-26-14 explicitly includes operational technology (OT) and internet-of-things (IoT) devices, even those lacking native logging capabilities. This broad inclusion necessitates the use of passive asset discovery tools, as actively scanning some OT/IoT devices can be risky or impractical.

Agencies must reach Level 1 within 120 days, Level 2 within 180 days, and Level 3 within 320 days of the LRA's publication. A critical aspect of the maturity model is that an agency's overall rating is determined by its lowest-performing element, meaning a weakness in asset inventory can prevent advancement even if other areas are strong.

This foundational requirement for asset visibility addresses what is known as the 'denominator problem.' Since log coverage is measured as a percentage of the total asset inventory, an incomplete inventory directly limits an agency's ability to demonstrate adequate log coverage. This challenge is often exacerbated by administrative silos, air-gapped networks, and legacy systems that are difficult to inventory.

Vendors like Tenable, already integrated with federal systems through the Continuous Diagnostics and Mitigation (CDM) program, offer solutions that align with M-26-14's requirements. Their platforms provide comprehensive asset discovery across IT, OT, and cloud environments, serving as a crucial data source for meeting the inventory visibility milestones.

The directive also emphasizes the connection between asset visibility and the CISA Zero Trust Maturity Model, positioning visibility and analytics as key enablers for all zero-trust pillars. Furthermore, historical vulnerability data, provided by tools like Tenable's, can offer essential forensic context for post-incident investigations, complementing log data.

federal governmentcybersecurityasset managementloggingcompliance
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

Hermes AI agent used to automate attack on Thai Finance Ministry

A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance. [...]

security

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages. [...]

security

BGP ORIGIN attribute manipulation and its impact on the Internet

By doing in-depth testing, we found nearly 70% of BGP paths experience ORIGIN attribute rewrites by transit providers seeking traffic advantages. We examine the global impact of this practice and argue for deprecating ORIGIN in route selection.

security

Andy Burnham signals continuity on UK cyber policy, reappoints minister despite scrapping ministry

The new British prime minister is retaining Liz Lloyd in a cyber policy role, making her one of the few Keir Starmer allies remaining in government.

security

'Wrench' attacks against crypto holders appear to be on the rise

There are more reports than ever before of strong-arm tactics like home invasions and kidnappings against cryptocurrency holders, researchers say.

vulnerability

Microsoft blames massive Microsoft 365 outage on maintenance bug

Microsoft says a bug in its automated network maintenance request system caused Thursday's massive outage by mistakenly removing IP routes from more devices than intended, disrupting Azure and Microsoft 365 services. [...]