Security1 publisher3 min readPublished
CISA's KEV triage guidance tells agencies to collect RAM before they patch
New implementation guidance for BOD 26-04 sets forensic triage steps that begin when a CVE hits the KEV catalog: evidence first, patching second, containment only after both.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- CISA published implementation guidance for Binding Operational Directive (BOD) 26-04 establishing forensic triage steps for agencies to execute prompt vulnerability response actions aligning with BOD 26-04 requirements.
- The steps provide baseline guidance; in some cases the KEV catalog may include specific triage steps for a CVE ID, and in those cases agencies should follow the KEV Catalog guidance.
- The forensic triage steps aim to enable agencies to rapidly scope vulnerability notifications, gather sufficient evidence, implement containment, take control actions, perform analysis, and subsequently determine the need for response effort escalation.
- CISA initiates the first step by adding the CVE entry to the KEV Catalog, with a target timeline of within the first two hours of KEV addition for the agency actions that follow.
- Agencies must identify whether the vulnerability meets the remediation threshold in fewer than three days and requires forensic triage to assess whether the systems or network infrastructure have been impacted or compromised.
Compiled by The WatchSomething wrong?How this is made
Why it matters
CISA has published implementation guidance for Binding Operational Directive 26-04 laying out forensic triage steps agencies are to execute when a vulnerability is added to the Known Exploited Vulnerabilities catalog [1]. The consequence is in the ordering: evidence collection comes before patching, and containment comes after both [11][13], so the question a federal defender has to answer is no longer only whether the fix is deployed but whether the hole was already used.
The guidance calls itself baseline, and says that where the KEV catalog carries triage steps for a specific CVE ID, agencies should follow the KEV entry instead [2]. Its stated purpose is to let agencies rapidly scope vulnerability notifications, gather sufficient evidence, implement containment, take control actions, perform analysis, and then decide whether to escalate [3].
The clock starts with CISA, which initiates the process by adding the CVE to KEV [4]. Within a target of two hours, agencies are to identify whether the vulnerability meets the remediation threshold of fewer than three days and therefore requires forensic triage to assess whether systems or network infrastructure have been compromised [5]. In the same window: activate the forensic triage response team, scope the affected boundaries, systems and services, and stand up a dedicated out-of-band communication channel that does not rely on potentially compromised infrastructure [6]. On the arithmetic, that determination consumes roughly three percent of the remediation window it feeds [2].
Evidence collection targets two to 24 hours, with volatile data first, meaning registries, cache and RAM, all of it lost at power-off [7]. Systems are not to be altered or remediated before collection where possible [8]. The collection is deliberately narrow: because of time constraints, agencies are told not to gather data beyond the scope of the incident or alert [9]. Each item collected gets logged with its source system, the date and time, and the collector's name [10].
Patching sits in the same two-to-24-hour band but explicitly follows evidence collection, because patching may jeopardise the availability of artifacts [11]. Agencies are told to work with internal teams to stabilise critical business systems disrupted by the patching itself [12]. Containment targets six to 24 hours and begins only after initial evidence collection, since premature containment can destroy vital evidence [13]. It must also be done without alerting the threat actor, who may otherwise take further steps to conceal and keep access [14]. Isolation should follow CISA's Cybersecurity Incident and Vulnerability Response Playbooks and be documented internally [15]. The earliest permitted containment start therefore trails the earliest permitted patch start by four hours [1], which makes the sequence a dependency chain rather than a schedule.
Two caveats matter. The hours are recommended best practice; what BOD 26-04 actually requires is that an adequate forensic triage analysis is performed, not that it happens on that timeline [16]. And the real burden is preparatory: agencies are told to build an internal plan for managing critical assets when KEV additions trigger triage, and to document explicit, transparent risk decisions weighing mission needs, especially the availability and integrity of high value assets and mission critical functions, against the potential impacts of exploitation [17].
Watch the later stages. The material available cuts off mid-sentence at a step targeted for 24 to 48 hours after KEV addition, beginning with evidence work [18], and CISA says it will keep updating the page with the latest implementation information [19]. Watch also whether KEV entries routinely start carrying per-CVE triage instructions [2], because that is where the generic checklist becomes specific instruction. An "adequate forensic triage analysis" with no binding timeline is a standard somebody eventually has to grade, and the grading rubric is the part not yet written down.