WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Community Partnerships Binding Operational Directive 23-02: Mitigating the Risk from Internet-Exposed Management Interfaces
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Directory
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Binding Operational Directive 23-02: Mitigating the Risk from Internet-Exposed Management Interfaces

Author: Jennifer Walker

Created: Tuesday, June 13, 2023 - 18:10

Categories: Cybersecurity, Security Preparedness

Today, the Cybersecurity and Infrastructure Security Agency (CISA) announced a new Binding Operational Directive (BOD) 23-02: Mitigating the Risk from Internet-Exposed Management Interfaces. The BOD instructs federal agencies to reduce the attack surface created by insecure or misconfigured remote management interfaces exposed to the internet. While BODs are mandatory for federal agencies, all organizations – private, industry, and state, local, tribal and territorial (SLTT) governments – are strongly encouraged to review and implement recommendations from this guidance. This BOD is designed to address recently reported threat activity of actors evading detection by compromising improperly configured devices that support underlying network infrastructure.

This directive applies to dedicated remote management interfaces belonging to routers, switches, firewalls, VPN concentrators, proxies, load balancers, and out of band server management interfaces (such as iLo and iDRAC) that are accessible over the internet. Specifically, the BOD mandates the removal of identified networked management interfaces from exposure to the internet or the protection of them with Zero-Trust capabilities that implement a policy enforcement point separate from the interface itself. Members are highlgy encouraged to have systems administrators review this BOD and address accordingly. Review Binding Operational Directive 23-02 at CISA.

Related Resources

Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated May 1, 2026)

May 1, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness

Tip of the Week – April 30, 2026

Apr 30, 2026 in Cybersecurity, Security Preparedness

(TLP:CLEAR) Cyber Readiness Institute Joins WaterISAC as a Community Partner to Strengthen Cyber Readiness Across the Water Sector

Apr 30, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar