Cloud Security

CISA Issues Binding Operational Directive for Improved Cloud Security

CISA’s Binding Operational Directive 25-01 requires federal agencies to align cloud environments with SCuBA secure configuration baselines.

The US cybersecurity agency CISA on Tuesday announced a new Binding Operational Directive requiring federal agencies to follow security control baselines for their cloud environments.

The ‘Binding Operational Directive 25-01: Implementing Secure Practices for Cloud Services’ is meant to help federal agencies reduce their attack surface and improve resilience against cyberattacks.

“Recent cybersecurity incidents highlight the significant risks posed by misconfigurations and weak security controls, which attackers can use to gain unauthorized access, exfiltrate data, or disrupt services. This Directive will further reduce the attack surface of the federal government networks,” CISA notes.

Per BOD 25-01, federal agencies are required to identify cloud tenants, implement assessment tools, and bring their cloud environments in line with CISA’s Secure Cloud Business Applications (SCuBA) secure configuration baselines.

By February 21, 2025, the directive mandates, all federal agencies should create and provide an inventory of cloud tenants, which should be updated annually.

It also requires that, by April 25, 2025, the agencies deploy SCuBA assessment tools for in-scope cloud tenants and begin continuous reporting on the directive’s requirements.

Advertisement. Scroll to continue reading.

By June 20, 2025, federal agencies should implement all mandatory SCuBA policies effective as of BOD 25-01’s issuance, namely the final SCuBA Secure Cloud Configuration Baselines for Microsoft Office 365, as detailed on CISA’s list of required configurations.

“In the future, CISA may release additional SCuBA Secure Configuration Baselines for other cloud products. Upon issuance of applicable Baselines, such products will fall under the scope of this Directive. Any baselines not updated within one year will automatically fall out of scope and will be removed from the SCuBA Secure Configuration Baseline catalog,” CISA explains.

BOD 25-01 requires federal agencies to implement future updates to mandatory SCuBA policies, in line with timetables published on the required configurations website, to monitor for new cloud tenants after implementing the mandatory baselines, and to “identify and explain deviations in the output of the SCuBA assessment tools when reported to CISA”.

Per the directive, the cybersecurity agency will maintain and update the list of in-scope policies; notify agencies of policy changes; provide them with instructions, assistance, and support; review and resolve deviations; and assess agency progress and report it to the DHS, OMB, and ONCD.

“Although BOD 25-01 only requires action by Federal Civilian Executive Branch agencies, CISA strongly recommends all stakeholders implement these policies and leverage CISA’s SCuBA assessment tool and the information on this page. Doing so will reduce significant risk and enhance collective resilience across the cybersecurity community,” CISA notes.

Related: CISA Seeking Public Comment on Updated National Cyber Incident Response Plan

Related: US Water Facilities Urged to Secure Access to Internet-Exposed HMIs

Related: Senators Push Overhaul of Classification Rules After Trump, Biden Cases

Related: Microsoft Rolls Out Default NTLM Relay Attack Mitigations

Related Content

Artificial Intelligence

When the AI Act comes into force, AI companies will be required to make clear to consumers with labels or digital watermarks that chatbots...

ICS/OT

CISA is urging water and wastewater utilities to lock down internet-exposed controllers, days after intrusions hit dozens of Minnesota systems.

Application Security

Five years after the initial release, the refresh introduces new elements, removes others, and updates terminology.

ICS/OT

An updated advisory from federal agencies provides information on the techniques used to hack programmable logic controllers.

Compliance

Industry professionals broadly agree that the suspension pauses third-party CMMC audits but not the underlying legal obligation to protect CUI.

Government

Chinese cybersecurity firms are facing action from the country’s military, but it’s not due to product or technical failures.

Risk Management

Three vulnerabilities are actively exploited in attacks, including two that have been targeted as zero-days.

Artificial Intelligence

The new program stems from an AI-focused Executive Order signed by President Trump on June 2.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version