
Loading

Loading
We use strictly necessary cookies to run this site, and analytics cookies to understand how it's used. See our Privacy Policy for details.
The Department of Homeland Security Inspector General takes a close look at implementation of a 2024 binding operational directive on cloud security issued by the Cybersecurity and Infrastructure Security Agency, in a recent report which found significant implementation delays and a lack of resources to meet the requirements.
Summary
“The Cybersecurity and Infrastructure Security Agency’s (CISA) efforts helped the Federal Civilian Executive Branch (FCEB) secure information in cloud environments through the Secure Cloud Business Applications (SCuBA) project,” the DHS IG report says. The IG report found, “However, 86 percent of FCEB agencies did not meet the June 2025 Binding Operational Directive deadline for implementing SCuBA policies, which leaves assets at risk of otherwise preventable cyberattacks and data losses.” The report was published Sept. 21.
CISA issued the BOD in December 2024, directing agencies to meet a set of deadlines to improve cloud security. The SCuBA project was initially launched by CISA in 2022 in an effort to ensure agencies use cloud-based business applications that are securely configured and mitigate threats. The first deadline gave agencies approximately two months to identify all cloud tenants, followed by an April 2025 deadline for FCEB agencies to deploy all SCuBA assessment tools and begin continuous monitoring.
Agencies had until June 20, 2025 to implement all mandatory SCuBA policies, according to the IG report. The report acknowledges that “CISA has undertaken several initiatives to help FCEB agencies implement the BOD.” It says, “For example, CISA conducted more than 80 engagements with more than 1,000 participants and promoted downloads of its assessment tools to over 130,000 requesters.” “In addition, CISA guided 17 agencies in the initial use of the assessment tools to improve the tools’ usability and functionality, and to help them reduce risk by adapting to new threats and vulnerabilities,” according to the DHS IG. However, the DHS IG provides stark numbers over compliance with the deadlines.
The report specifically highlights: 40 of 102 agencies (39 percent) did not provide CISA with the names of all their cloud tenants by February 21, 2025, which may result in FCEB agencies being unable to verify which required tenants had SCuBA assessment tools downloaded to their network. 53 of 102 agencies (52 percent) did not deploy all SCuBA assessment tools to their in scope cloud tenants to begin continuous reporting by April 25, 2025. When FCEB agencies do not use and report on the assessment tools, their vulnerability and configuration management programs, as well as risk assessments, may be less effective.
88 of 102 agencies (86 percent) did not implement all mandatory SCuBA policies by June 20, 2025, which impacts the overall security of the agencies’ cloud environments. The DHS IG adds, “As of February 12, 2026, compliance with BOD 25-01 had not improved. A total of 78 out of 102 (76 percent) FCEB agencies were still not in compliance with implementing all mandatory SCuBA policies.” The report also brings up how CISA doesn’t have the authorities to enforce security requirements.
“The Federal Information Security Modernization Act of 2014 authorizes the Secretary of Homeland Security to develop and oversee the implementation of operational directives requiring agencies to adopt standards and guidelines developed by the OMB Director,” the report says. The DHS IG says, “The policies help safeguard Federal information and systems against known or suspected information security threats, vulnerabilities, and risks.
KazaSec's take
A newly disclosed vulnerability is only a real risk to your organization once it's confirmed present and exploitable in your own environment — not every CVE applies equally to every network. Knowing the difference is exactly what a proper vulnerability assessment is for.
Coverage details
Relevant from KazaSec
More security news
We help organizations find and fix the gaps before they make headlines.