It's here. On August 20, CISA dropped the Logging Reference Architecture (LRA) a practitioner's guide that operationalizes OMB M-26-14 and the countdown just got real. In this episode of The GIST of Govt IT, Brian and Sean break down the aggressive timeline it sets: agencies have 90 days to inventory their environment and submit a plan in Cyberscope (the week before Thanksgiving), then about 30 more to hit Baseline 1 maturity (the week before Christmas). Surprisingly, or not, Sean's read is refreshingly positive, this guide was written by practitioners for practitioners, with concrete advice, outcome-focused questions to ask your teams, and clear thresholds: 70% of assets inventoried, 50% logging coverage, 50% actionable alerts, six-month retention.
The conversation digs into why IoT and OT are the hard part (segmented networks, third-party-managed devices, systems you can't actively scan), why the LRA deliberately doesn't mandate AI, and a practical path forward: assign a single LRA owner, reconcile your CMDB against your property book, deploy passive OT listening kits rather than scanning fragile systems, and use end-of-fiscal-year funds now to close gaps you can't fill over the holidays. The clock is ticking and agencies are going to have to build the airplane while they fly.
Resources Mentioned in This Episode
The Core Documents
• CISA Logging Reference Architecture (LRA), released August 20
• OMB M-26-14 (the logging mandate the LRA operationalizes)
• CyberScope (where agencies submit their plans)
The Baseline 1 Thresholds
• Inventory visibility: 70% of assets captured in a centralized inventory
• Collection coverage: 50% of inventoried assets logging
• Collection operations: 50% of logs producing actionable alerts
• Data retention: minimum six months (per M-26-14; the LRA guide notes a slightly different figure)
• Timeline: plan ~Nov 18, Baseline 1 ~mid-December
Frameworks & Technical References
• MITRE ATT&CK (adversary behavior models)
• CISA Zero Trust Maturity Model
• NIST SP 800-92 (log management guidance)
The Threat Backdrop
• DOJ/FBI seizure of Chinese state-sponsored hacking infrastructure (August 26)
• CISA advisory on edge-device compromise and lateral movement
• Anthropic and OpenAI on the narrowing window to defend against AI cyber threats
From Swish / GIST 360
• Swish LRA planning assessmen
• “When the Perimeter Disappears” breakfast briefing recap
Related Episodes
• Episode 13: Fed Christmas in July? The OMB M-26-14 Holiday Rush Begins!
• Episode 15: Billion Dollar Pilots and Boil Water Notices: Securing OT Environments
• Episode 7: Iran Came for the Dams and We Got Lucky: Frontline Insights into the OT Fight
The Hosts & Show
• Swish
• GIST 360
