Visibility is continuous work
BOD 23-01 requires agencies to improve asset visibility and vulnerability detection on federal networks, including automated discovery cadence. In practice, the hard part is not buying another scanner—it is reconciling the inventories you already have.
Where programs break
- EDR sees endpoints the CMDB never enrolled
- Cloud accounts spawn assets outside the traditional network scan
- OT and IoT devices appear only in specialized tools
- Duplicate identities inflate "coverage" metrics that collapse under audit
What a useful package looks like
A CAASM-oriented work package should leave the prime with:
- A reconciled asset inventory method, not a one-off spreadsheet
- Coverage metrics tied to CDM or agency dashboard expectations
- Clear ownership for resolving conflicts
- A path from visibility into risk-based remediation under BOD 26-04
How we engage
We take a defined boundary, put a named principal on it, and produce artifacts your proposal and delivery teams can reuse. We will not claim an infinite bench to "staff the whole visibility program."
