# RA-05 Vulnerability Monitoring and Scanning

NIST SP 800-53 control. Family: RA Risk Assessment. Function: detective. Baselines: low, moderate, high. Mapping licence: CC BY-SA 4.0.

Statement: a. Monitor and scan for vulnerabilities in the system and hosted applications [Assignment: organization-defined frequency and/or randomly in accordance with organization-defined process] and when new vulnerabilities potentially affecting the system are identified and reported; b. Employ vulnerability monitoring tools and techniques that facilitate interoperability among tools and automate parts of the vulnerability management process by using standards for: 1. Enumerating platforms, software flaws, and improper configurations; 2. Formatting checklists and test procedures; and 3. Measuring vulnerability impact; c. Analyze vulnerability scan reports and results from vulnerability monitoring; d. Remediate legitimate vulnerabilities [Assignment: organization-defined response times] in accordance with an organizational assessment of risk; e. Share information obtained from the vulnerability monitoring process and control assessments with [Assignment: organization-defined personnel or roles] to help eliminate similar vulnerabilities in other systems; and f. Employ vulnerability monitoring tools that include the capability to readily update the vulnerabilities to be scanned.
Guidance: Security categorization of information and systems guides the frequency and comprehensiveness of vulnerability monitoring (including scans). Organizations determine the required vulnerability monitoring for system components, ensuring that the potential sources of vulnerabilities—such as infrastructure components (e.g., switches, routers, guards, sensors), networked printers, scanners, and copiers—are not overlooked. The capability to readily update vulnerability monitoring tools as new vulnerabilities are discovered and announced and as new scanning methods are developed helps to ensure that new vulnerabilities are not missed by employed vulnerability monitoring tools. The vulnerability monitoring tool update process helps to ensure that potential vulnerabilities in the system are identified and addressed as quickly as possible. Vulnerability monitoring and analyses for custom software may require additional approaches, such as static analysis, dynamic analysis, binary analysis, or a hybrid of the three approaches. Organizations can use these analysis approaches in source code reviews and in a variety of tools, including web-based application scanners, static analysis tools, and binary analyzers. Vulnerability monitoring includes scanning for patch levels; scanning for functions, ports, protocols, and services that should not be accessible to users or devices; and scanning for flow control mechanisms that are improperly configured or operating incorrectly. Vulnerability monitoring may also include continuous vulnerability monitoring tools that use instrumentation to continuously analyze components. Instrumentation-based tools may improve accuracy and may be run throughout an organization without scanning. Vulnerability monitoring tools that facilitate interoperability include tools that are Security Content Automated Protocol (SCAP)-validated. Thus, organizations consider using scanning tools that express vulnerabilities in the Common Vulnerabilities and Exposures (CVE) naming convention and that employ the Open Vulnerability Assessment Language (OVAL) to determine the presence of vulnerabilities. Sources for vulnerability information include the Common Weakness Enumeration (CWE) listing and the National Vulnerability Database (NVD). Control assessments, such as red team exercises, provide additional sources of potential vulnerabilities for which to scan. Organizations also consider using scanning tools that express vulnerability impact by the Common Vulnerability Scoring System (CVSS). Vulnerability monitoring includes a channel and process for receiving reports of security vulnerabilities from the public at-large. Vulnerability disclosure programs can be as simple as publishing a monitored email address or web form that can receive reports, including notification authorizing good-faith research and disclosure of security vulnerabilities. Organizations generally expect that such research is happening with or without their authorization and can use public vulnerability disclosure channels to increase the likelihood that discovered vulnerabilities are reported directly to the organization for remediation. Organizations may also employ the use of financial incentives (also known as "bug bounties") to further encourage external security researchers to report discovered vulnerabilities. Bug bounty programs can be tailored to the organization’s needs. Bounties can be operated indefinitely or over a defined period of time and can be offered to the general public or to a curated group. Organizations may run public and private bounties simultaneously and could choose to offer partially credentialed access to certain participants in order to evaluate security vulnerabilities from privileged vantage points.

## Enhancements (8)
- RA-05(02) Update Vulnerabilities to Be Scanned. Baselines: low, moderate, high
- RA-05(03) Breadth and Depth of Coverage
- RA-05(04) Discoverable Information. Baselines: high
- RA-05(05) Privileged Access. Baselines: moderate, high
- RA-05(06) Automated Trend Analyses
- RA-05(08) Review Historic Audit Logs
- RA-05(10) Correlate Scanning Information
- RA-05(11) Public Disclosure Program. Baselines: low, moderate, high
Withdrawn by NIST: RA-05(01) (now in RA-05); RA-05(07) (now in CM-08); RA-05(09) (now in CA-08).
Each enhancement's statement: /api/v1/controls/RA-05?fields=enhancements

## Patterns that use it (28)
- Critical (8): SP-008 Public Web Server Pattern; SP-012 Secure Software Development Lifecycle; SP-016 DMZ Module; SP-026 PCI Full Environment; SP-028 Secure DevOps Pipeline Pattern; SP-035 Offensive Security Testing; SP-038 Vulnerability Management and Patching; SP-046 External Attack Surface Management
- Important (15): SP-001 Client Module; SP-002 Server Module; SP-006 Wireless- Private Network Pattern; SP-007 Wireless- Public Hotspot Pattern; SP-019 Secure Ad-Hoc File Exchange Pattern; SP-023 Industrial Control Systems; SP-025 Advanced Monitoring and Detection; SP-029 Zero Trust Architecture; SP-030 API Security; SP-031 Security Monitoring and Response; SP-036 Incident Response; SP-043 Security Metrics and Measurement; SP-047 Secure Agentic AI Frameworks; SP-048 Offensive AI and Deepfake Defence (draft); SP-054 CBDC and Digital Currency Infrastructure (draft)
- Standard (5): SP-021 Realtime Collaboration Pattern; SP-037 Privileged User Management; SP-042 Third Party Risk Management; SP-050 Mobile Security Architecture (draft); SP-053 Zero-Knowledge Proof Architecture (draft)

## Clauses by framework (78 frameworks)
- iso_27001_2022: 8.2, A.5.7, A.8.8. OSA's own, not in NIST's crosswalk: 8.2, A.5.7
- iso_27002_2022: 5.7, 8.8
- cobit_2019: APO12
- pci_dss_v4: 6.3, 11.3
- nist_csf_2: GV.SC-10, ID.IM-01, ID.IM-02, ID.IM-03, ID.RA-01, ID.RA-08
- cis_controls_v8: CIS 7, CIS 7.1, CIS 7.5, CIS 7.6, CIS 7.7, CIS 16.2, CIS 16.6, CIS 18, CIS 18.4
- soc2_tsc: CC7.1, CC9.2-POF13
- finos_ccc: CCC-C10
- iso_42001_2023: A.6.2.4
- iec_62443: 2-1 4.3
- asd_e8: E8-2, E8-2 ML1, E8-2 ML2, E8-2 ML3, E8-6, E8-6 ML1
- nis2: Art. 21(2)(e)
- apra_cps_234: Para 19-20
- mas_trm: 13
- anssi: Hygiene.31, Hygiene.33, SecNumCloud.13.6
- osfi_b13: B-13.2.4, B-13.3.1
- finma_circular: IV.B.c(54), IV.B.c(56), IV.B.c(57), IV.D(75), IV.D(76)
- gdpr: Art.32(1)(d)
- dora: Art.9(3), Art.13(1), Art.25(1)
- bio2: 5.7, 8.8
- rbi_csf: Annex1.7, Annex1.18, ITGRCA.26
- fisc: FISC.O12
- lgpd_bcb: BCB.Art.6, BCB.Art.10, BCB.Art.19
- hkma_tme1: TME1.7.4
- mlps_2: 8.1.4.4, 8.1.10.3
- dnb_good_practice: DNB.4.2, DNB.16.1, DNB.19.2, DNB.22.1
- cra: CRA.I.2a, CRA.II.1, CRA.II.2, CRA.II.3, CRA.Info.5
- swift_cscf: SWIFT.2.7, SWIFT.7.3A
- cbb_tm: TM-4, TM-11
- cbuae: CR-7, CR-10
- nca_ecc: 1-5, 2-10, 2-11, 5-1
- qatar_nia: OS, RM
- sama_csf: 1.8, 1.9, 3.5
- uae_ia: T2, T7
- bog_cisd: CISD-VI, CISD-X
- bom_ctrm: 2.1, 4.1, 4.3
- cbe_csf: CRM-1, CTO-9, OVM-3
- cbn_csf: Part2.3, Part3.3
- popia: s19
- sa_js2: JS2-6.2, JS2-7.2, JS2-7.7, JS2-8.5
- bot_cyber: Ch3.2
- cpmi_pfmi: CG.DE, CG.ID, CG.SA, CG.TE, PFMI.P17
- eba_ict: 3.4.6
- ecb_croe: CROE.2.2.1, CROE.2.4, CROE.2.6.1, CROE.2.6.2, CROE.2.7.1
- ffiec_is: II.A, II.A.2, II.C.11, III.A, IV.A, IV.A.2
- hipaa_sr: §164.308(a)(1)(ii)(A), §164.308(a)(8)
- iosco_cyber: DET-3, ID-3, SA-1, SA-3, TEST-1
- nydfs_500: 500.5, 500.9
- sebi_cscrf: DE.DP, DE.VA, ID.RA, VAPT
- cmmc_2: RA, SI
- nerc_cip: CIP-010-4, CIP-014-3
- nrc_73_54: RG5.71-B-CM, RG5.71-C-PL
- tsa_psd: SD-1 Sec 3, SD-2 Sec D, SD-2 Sec G
- doe_c2m2: THREAT
- api_1164: Sec 4
- awia: Sec 2013(a)
- iaea_nss: Sec 4
- fips_140: FIPS 140-3 §7.12
- cbest: CBEST.2, CBEST.6
- tiber_eu: TIBER.GTL, TIBER.RT, TIBER.TTI
- common_criteria: CC Part 3 — SAR
- fca_sysc_13: SYSC 13.5.3
- fda_cyber: 524B-2, CRA-1, MON-1, MON-2, SBOM-3, ST-1, ST-2, ST-3, ST-4, TM-1
- hitrust_csf: 03.a, 06.c, 09.c, 10.e
- iso_27799: 12.5, 18.4, H.3
- lloyds_ms: CRM.2, MS8.11, MS10.2
- naic_ds: 4-monitoring, 4A
- nhs_dspt: NDG-8.1, NDG-8.2, NDG-9.8, NDG-9.9
- solvency_ii: DR.266
- owasp_masvs_v2: MASVS-CODE-3
- csa_ccm_v4: AIS-05, AIS-07, TVM-01, TVM-03, TVM-05, TVM-06, TVM-07, TVM-08, TVM-09, TVM-10
- csa_aicm: AIS-05, AIS-07, AIS-10, MDS-03, MDS-08, TVM-01, TVM-03, TVM-05, TVM-06, TVM-07, TVM-08, TVM-09, TVM-10, TVM-11, TVM-12, TVM-13
- ccss_v9: 2.01.1, 2.01.2
- mica: Art.35(1)
- basel_sco60: SCO60.4, SCO60.13, SCO60.14, SCO60.21, SCO60.23, SCO60.51, SCO60.52, SCO60.64, SCO60.65, SCO60.74
- bssc: GSP-02, GSP-08, GSP-15, NOS-10, TIS-02
- sec_custody_digital: SEC-CD-09
- dpdpa: Act.8(5), Rules.Sch1.B.7
OSA's mapping for iso_27001_2022 and nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/RA-05
- Clauses only: /api/v1/controls/RA-05?fields=mappings
- Page for people: /controls/ra-05/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
