Visibility · 2026-07-01

CISA BOD 23-01 and the asset visibility problem that never stays solved

Automated asset discovery every seven days sounds simple until EDR, CMDB, cloud, and OT inventories disagree.

Visibility is continuous work

BOD 23-01 requires agencies to improve asset visibility and vulnerability detection on federal networks, including automated discovery cadence. In practice, the hard part is not buying another scanner—it is reconciling the inventories you already have.

Where programs break

  • EDR sees endpoints the CMDB never enrolled
  • Cloud accounts spawn assets outside the traditional network scan
  • OT and IoT devices appear only in specialized tools
  • Duplicate identities inflate "coverage" metrics that collapse under audit

What a useful package looks like

A CAASM-oriented work package should leave the prime with:

  • A reconciled asset inventory method, not a one-off spreadsheet
  • Coverage metrics tied to CDM or agency dashboard expectations
  • Clear ownership for resolving conflicts
  • A path from visibility into risk-based remediation under BOD 26-04

How we engage

We take a defined boundary, put a named principal on it, and produce artifacts your proposal and delivery teams can reuse. We will not claim an infinite bench to "staff the whole visibility program."

Related work package

Need this mapped into a scoped subcontract?

We usually price by work package after a short no-cost scoping call.

Experience described reflects work performed by Legate Solutions principals while employed by other organizations. It is provided to show individual qualifications and is not represented as corporate past performance of Legate Solutions LLC or as an endorsement by any agency named. Corporate past performance and references are available where applicable; where no relevant corporate record exists, Legate requests evaluation consistent with FAR 15.305(a)(2)(iv).