{"id":3455,"date":"2024-05-07T15:50:29","date_gmt":"2024-05-07T20:50:29","guid":{"rendered":"https:\/\/www.darkreading.com\/vulnerabilities-threats\/cisa-kev-catalog-speed-up-remediation"},"modified":"2024-05-07T15:50:29","modified_gmt":"2024-05-07T20:50:29","slug":"does-cisas-kev-catalog-speed-up-remediation","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/05\/07\/does-cisas-kev-catalog-speed-up-remediation\/","title":{"rendered":"Does CISA&#8217;s KEV Catalog Speed Up Remediation?"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt47623d372b5fd637\/64f16dee8762bfbaf76b8ee3\/bug-Federico-Caputo-Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/does-cisas-kev-catalog-speed-up-remediation.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/does-cisas-kev-catalog-speed-up-remediation.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">RSA CONFERENCE 2023 \u2013 San Francisco \u2013 <\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">When the Cybersecurity and Infrastructure Security Agency first introduced the Known Exploited Vulnerabilities (KEV) list in 2021, the intent was to provide government agencies and enterprises with a heads up about the most risky threats out in the wild. Nearly three years later, research shows the KEV list is speeding up remediation times, but there&#8217;s more work to be done.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Former Congressman Jim Langevin was behind the CISA Binding Operational Directive legislation 22-01 that created the KEV list, and explains to Dark Reading that the intent was to provide enterprises with the same information being shared with government agencies about which vulnerabilities posed the greatest risk, and should therefore be prioritized for remediation. Vulnerabilities added to the KEV list are required to the mitigated for the federal government, not so for enterprises.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In order for <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/exploited-vulnerabilities-can-take-months-to-make-kev-list\" rel=\"noopener\">a flaw to be added to the KEV list<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, it must have an assigned CVE, be known to have been exploited in the wild, and have a remediation available. Deadlines imposed by CISA to remediate among federal agencies varies from one week to six months, with ransomware vulnerabilities being treated with the most urgency, according to data from a new report from Bitsight that wanted to evaluate whether the list is working effectively.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Severity Scores Help Patch Prioritization\">Severity Scores Help Patch Prioritization<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Bitsight reported that 35% organizations experienced a KEV in 2023 \u2014 66% of which had more than one, 25% of which had more than five, and 10% of which had more than 10.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Among medium-severity vulnerabilities, there is almost no difference in remediation speed,&#8221; the report said. &#8220;However, the median <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/application-security\/critical-gitlab-bug-exploit-account-takeover-cisa\" rel=\"noopener\">critical KEV<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> is remediated 2.6 times faster than a non-KEV counterpart, with high-severity KEVs remediated 1.8 times faster than non-KEVs.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Langevin is encouraged by the uptick in remediation timelines, however, many organizations are still struggling. Bugs that are being used in ransomware campaigns appear to get top priority for remediation among enterprise teams, the data showed.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;If we average out the relative drops, ransomware KEVs are fixed 2.5x faster (on average) than KEVs not known to be used in ransomware,&#8221; the report added.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Meanwhile, non-profits and NGOs are the slowest to remediate, while tech companies and insurance and financial firms win the speed race.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Federal agencies also often struggle to meet stated CISA deadlines, but remediate a full 65% faster than all other sectors, Bitsight found. About 40% of vulnerabilities on the KEV list get fixed by the deadline, the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.bitsight.com\/resources\/slicing-through-cisas-kev-catalog\" rel=\"noopener\">report <\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">added.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">To get faster, it&#8217;s necessary for enterprises to stand up an effective <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/application-security\/security-teams-overwhelmed-bugs-patch-prioritization\" rel=\"noopener\">vulnerability management system<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> at the corporate level, gather context about the threat using the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/exploited-vulnerabilities-can-take-months-to-make-kev-list\" rel=\"noopener\">KEV list<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> and other sources. Importantly, the Bitsight researchers urge organizations focus on measuring remediation rates with accountability for moving too slowly.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">At its most fundamental, Langevin views the KEV list as an information source to provide context around the threat landscape.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Bitsight&#8217;s VP of government affairs Jake Olcott adds the KEV list should help teams identify which bugs should be elevated to the highest levels of the business.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;KEVs are exactly the kind of vulns that should be discussed at the board level,&#8221; Olcott explains to Dark Reading. &#8220;It helps articulate not just the cyber risk, but the business risk.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/cisa-kev-catalog-speed-up-remediation\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>RSA CONFERENCE 2023 \u2013 San Francisco \u2013 When the Cybersecurity<\/p>\n","protected":false},"author":12,"featured_media":3456,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-3455","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/does-cisas-kev-catalog-speed-up-remediation-scaled.jpg?fit=2560%2C1772&ssl=1",2560,1772,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/does-cisas-kev-catalog-speed-up-remediation-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/does-cisas-kev-catalog-speed-up-remediation-scaled.jpg?fit=300%2C208&ssl=1",300,208,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/does-cisas-kev-catalog-speed-up-remediation-scaled.jpg?fit=640%2C443&ssl=1",640,443,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/does-cisas-kev-catalog-speed-up-remediation-scaled.jpg?fit=640%2C443&ssl=1",640,443,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/does-cisas-kev-catalog-speed-up-remediation-scaled.jpg?fit=1536%2C1063&ssl=1",1536,1063,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/does-cisas-kev-catalog-speed-up-remediation-scaled.jpg?fit=2048%2C1418&ssl=1",2048,1418,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/does-cisas-kev-catalog-speed-up-remediation-scaled.jpg?fit=1024%2C709&ssl=1",1024,709,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/does-cisas-kev-catalog-speed-up-remediation-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/does-cisas-kev-catalog-speed-up-remediation-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/does-cisas-kev-catalog-speed-up-remediation-scaled.jpg?fit=2560%2C1772&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3455","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3455"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3455\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/3456"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3455"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3455"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3455"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}