# CISA BOD 26-04: Frequently asked questions about the new risk-based patching directive

> Quelle: Tenable Research — https://www.tenable.com/blog/cisa-bod-26-04-FAQ-vulnerability-remediation-impact

## Maßnahmen

- [ ] Betroffenheit im eigenen Stack prüfen: Versionen/Komponenten abgleichen.
- [ ] Originalquelle / Hersteller-Advisory lesen: https://www.tenable.com/blog/cisa-bod-26-04-FAQ-vulnerability-remediation-impact
- [ ] Priorität HOCH: laut CISA-KEV aktiv ausgenutzt – bevorzugt patchen.
- [ ] Verfügbaren Patch oder Workaround einspielen und dokumentieren.
- [ ] Erkennung: Logs und Indikatoren (IoCs) auf Ausnutzung prüfen.
