
BOD 26-04 Risk Tiering
ContributedComputes CISA BOD 26-04 remediation tiers for Tenable vulnerability findings using the directive's 4-variable model.
Powered by Hexa AI, Part of Tenable One
BOD 26-04 Risk Tiering is powered by Tenable Hexa AI
Hexa AI is the agentic engine of Tenable One — the AI-powered exposure management platform. See it in action.
Request a Demo →This skill automates CISA BOD 26-04 compliance for federal agencies and organizations managing Tenable vulnerability data. It computes remediation tiers using the directive’s four-variable risk model: Publicly Exposed × In KEV × Automatable × Technical Impact.
What it does
Takes Tenable One/TVM vulnerability findings and produces BOD 26-04-compliant remediation tiers with specific deadlines:
- 3-day + forensic triage (actively exploited KEV on public-facing assets)
- 3-day (high-risk KEV)
- 14-day (medium-risk KEV)
- 60-day (lower-risk)
- Fix-on-upgrade (maintenance window)
Pulls data directly from Tenable via Hexa MCP, enriches with CISA Vulnrichment for automation/impact assessments, applies Table 1 logic, and generates action queues with countdown timers from first-seen dates.
How it works
The skill extracts KEV dates from Tenable Workbench, handles Windows patch bundles by extracting individual CVEs, fetches CISA SSVC assessments via Vulnrichment API, computes tiers using BOD 26-04’s 16-row lookup table, and outputs multiple report formats (JSON for automation, CSV for leadership, text for humans). Includes forensic triage flags for potential active breaches and coverage statistics showing CISA data availability.
Production-tested on 500 assets with 539 KEV vulnerabilities, achieving 64.3% CISA coverage. Zero external dependencies (Python stdlib only). 21 unit tests covering all Table 1 rows and edge cases.
