← Controls / RA

RA-05 Vulnerability Monitoring and Scanning

Risk Assessment

Low Moderate High

Description

a. Monitor and scan for vulnerabilities in the system and hosted applications [Assignment: organization-defined frequency and/or randomly in accordance with organization-defined process] and when new vulnerabilities potentially affecting the system are identified and reported; b. Employ vulnerability monitoring tools and techniques that facilitate interoperability among tools and automate parts of the vulnerability management process by using standards for: 1. Enumerating platforms, software flaws, and improper configurations; 2. Formatting checklists and test procedures; and 3. Measuring vulnerability impact; c. Analyze vulnerability scan reports and results from vulnerability monitoring; d. Remediate legitimate vulnerabilities [Assignment: organization-defined response times] in accordance with an organizational assessment of risk; e. Share information obtained from the vulnerability monitoring process and control assessments with [Assignment: organization-defined personnel or roles] to help eliminate similar vulnerabilities in other systems; and f. Employ vulnerability monitoring tools that include the capability to readily update the vulnerabilities to be scanned.

Supplemental Guidance

Security categorization of information and systems guides the frequency and comprehensiveness of vulnerability monitoring (including scans). Organizations determine the required vulnerability monitoring for system components, ensuring that the potential sources of vulnerabilities—such as infrastructure components (e.g., switches, routers, guards, sensors), networked printers, scanners, and copiers—are not overlooked. The capability to readily update vulnerability monitoring tools as new vulnerabilities are discovered and announced and as new scanning methods are developed helps to ensure that new vulnerabilities are not missed by employed vulnerability monitoring tools. The vulnerability monitoring tool update process helps to ensure that potential vulnerabilities in the system are identified and addressed as quickly as possible. Vulnerability monitoring and analyses for custom software may require additional approaches, such as static analysis, dynamic analysis, binary analysis, or a hybrid of the three approaches. Organizations can use these analysis approaches in source code reviews and in a variety of tools, including web-based application scanners, static analysis tools, and binary analyzers. Vulnerability monitoring includes scanning for patch levels; scanning for functions, ports, protocols, and services that should not be accessible to users or devices; and scanning for flow control mechanisms that are improperly configured or operating incorrectly. Vulnerability monitoring may also include continuous vulnerability monitoring tools that use instrumentation to continuously analyze components. Instrumentation-based tools may improve accuracy and may be run throughout an organization without scanning. Vulnerability monitoring tools that facilitate interoperability include tools that are Security Content Automated Protocol (SCAP)-validated. Thus, organizations consider using scanning tools that express vulnerabilities in the Common Vulnerabilities and Exposures (CVE) naming convention and that employ the Open Vulnerability Assessment Language (OVAL) to determine the presence of vulnerabilities. Sources for vulnerability information include the Common Weakness Enumeration (CWE) listing and the National Vulnerability Database (NVD). Control assessments, such as red team exercises, provide additional sources of potential vulnerabilities for which to scan. Organizations also consider using scanning tools that express vulnerability impact by the Common Vulnerability Scoring System (CVSS). Vulnerability monitoring includes a channel and process for receiving reports of security vulnerabilities from the public at-large. Vulnerability disclosure programs can be as simple as publishing a monitored email address or web form that can receive reports, including notification authorizing good-faith research and disclosure of security vulnerabilities. Organizations generally expect that such research is happening with or without their authorization and can use public vulnerability disclosure channels to increase the likelihood that discovered vulnerabilities are reported directly to the organization for remediation. Organizations may also employ the use of financial incentives (also known as "bug bounties") to further encourage external security researchers to report discovered vulnerabilities. Bug bounty programs can be tailored to the organization’s needs. Bounties can be operated indefinitely or over a defined period of time and can be offered to the general public or to a curated group. Organizations may run public and private bounties simultaneously and could choose to offer partially credentialed access to certain participants in order to evaluate security vulnerabilities from privileged vantage points.

Changes from Rev 4

Title changed from 'Vulnerability Scanning' Control text adds requirement to employ vulnerability monitoring tools that include the capability to readily update the vulnerabilities to be scanned Discussion expanded to explain vulnerability monitoring Incorporates withdrawn control RA-05(1)

Enhancements (8)

What NIST adds to this control. Select one to read its statement.

RA-05(02) Update Vulnerabilities to Be Scanned LowModerateHigh

Update the system vulnerabilities to be scanned [Selection (one or more): [Assignment: organization-defined frequency]; prior to a new scan; when new vulnerabilities are identified and reported].

RA-05(03) Breadth and Depth of Coverage

Define the breadth and depth of vulnerability scanning coverage.

RA-05(04) Discoverable Information High

Determine information about the system that is discoverable and take [Assignment: organization-defined corrective actions].

RA-05(05) Privileged Access ModerateHigh

Implement privileged access authorization to [Assignment: organization-defined system components] for [Assignment: organization-defined vulnerability scanning activities].

RA-05(06) Automated Trend Analyses

Compare the results of multiple vulnerability scans using [Assignment: organization-defined automated mechanisms].

RA-05(08) Review Historic Audit Logs

Review historic audit logs to determine if a vulnerability identified in a [Assignment: organization-defined system] has been previously exploited within an [Assignment: organization-defined time period].

RA-05(10) Correlate Scanning Information

Correlate the output from vulnerability scanning tools to determine the presence of multi-vulnerability and multi-hop attack vectors.

RA-05(11) Public Disclosure Program LowModerateHigh

Establish a public reporting channel for receiving reports of vulnerabilities in organizational systems and system components.

Withdrawn by NIST:

  • RA-05(01) Update Tool Capability, now in RA-05
  • RA-05(07) Automated Detection and Notification of Unauthorized Components, now in CM-08
  • RA-05(09) Penetration Testing and Analyses, now in CA-08

MITRE ATT&CK Techniques (107)

ATT&CK v16.1

Techniques mitigated by this control, mapped via CTID.

Initial Access 8 Execution 12 Persistence 33 Privilege Escalation 26 Defense Evasion 38 Credential Access 9 Discovery 2 Lateral Movement 10 Collection 9 Command & Control 1 Exfiltration 3
Show all 107 techniques grouped by tactic

Persistence

Privilege Escalation

Defense Evasion

Compliance Mappings

ISO 27001:2022

8.2A.5.7A.8.8

ISO 27002:2022

5.78.8

COBIT 2019

APO12

CIS Controls v8

CIS 7CIS 7.1CIS 7.5CIS 7.6CIS 7.7CIS 16.2CIS 16.6CIS 18CIS 18.4

NIST CSF 2.0

GV.SC-10ID.IM-01ID.IM-02ID.IM-03ID.RA-01ID.RA-08

SOC 2 TSC

CC7.1CC9.2-POF13

PCI DSS v4.0.1

6.311.3

CSA CCM v4

AIS-05AIS-07TVM-01TVM-03TVM-05TVM-06TVM-07TVM-08TVM-09TVM-10

CSA AICM v1

AIS-05AIS-07AIS-10MDS-03MDS-08TVM-01TVM-03TVM-05TVM-06TVM-07TVM-08TVM-09TVM-10TVM-11TVM-12TVM-13

FINOS CCC

CCC-C10

ISO 42001:2023

A.6.2.4

IEC 62443

2-1 4.3

NIS2 Directive

Art. 21(2)(e)

MAS TRM

13

APRA CPS 234

Para 19-20

ASD Essential Eight

E8-2E8-2 ML1E8-2 ML2E8-2 ML3E8-6E8-6 ML1

ANSSI

Hygiene.31Hygiene.33SecNumCloud.13.6

FINMA Circular 2023/1

IV.B.c(54)IV.B.c(56)IV.B.c(57)IV.D(75)IV.D(76)

OSFI B-13

B-13.2.4B-13.3.1

EU GDPR

Art.32(1)(d)

EU DORA

Art.9(3)Art.13(1)Art.25(1)

BIO2

5.78.8

RBI CSF

Annex1.7Annex1.18ITGRCA.26

FISC Security Guidelines

FISC.O12

LGPD + BCB 4893

BCB.Art.6BCB.Art.10BCB.Art.19

HKMA TM-E-1

TME1.7.4

MLPS 2.0

8.1.4.48.1.10.3

DNB Good Practice

DNB.4.2DNB.16.1DNB.19.2DNB.22.1

EU CRA

CRA.I.2aCRA.II.1CRA.II.2CRA.II.3CRA.Info.5

SWIFT CSCF

SWIFT.2.7SWIFT.7.3A

SAMA CSF

1.81.93.5

NCA ECC

1-52-102-115-1

UAE IA

T2T7

CBB TM

TM-4TM-11

Qatar NIA

OSRM

CBUAE

CR-7CR-10

CBE CSF

CRM-1CTO-9OVM-3

SA JS2

JS2-6.2JS2-7.2JS2-7.7JS2-8.5

CBN CSF

Part2.3Part3.3

BoG CISD

CISD-VICISD-X

POPIA

s19

BoM CTRM

2.14.14.3

IOSCO Cyber Resilience

DET-3ID-3SA-1SA-3TEST-1

CPMI-IOSCO PFMI

CG.DECG.IDCG.SACG.TEPFMI.P17

FFIEC IS

II.AII.A.2II.C.11III.AIV.AIV.A.2

NYDFS 500

500.5500.9

HIPAA Security Rule

§164.308(a)(1)(ii)(A)§164.308(a)(8)

ECB CROE

CROE.2.2.1CROE.2.4CROE.2.6.1CROE.2.6.2CROE.2.7.1

EBA ICT Guidelines

3.4.6

SEBI CSCRF

DE.DPDE.VAID.RAVAPT

BOT Cyber Resilience

Ch3.2

CMMC 2.0

RASI

NERC CIP

CIP-010-4CIP-014-3

10 CFR 73.54

RG5.71-B-CMRG5.71-C-PL

TSA Pipeline SD

SD-1 Sec 3SD-2 Sec DSD-2 Sec G

DOE C2M2 v2.1

THREAT

API 1164

Sec 4

AWIA

Sec 2013(a)

IAEA NSS 17-T

Sec 4

FIPS 140-3

FIPS 140-3 §7.12

CBEST

CBEST.2CBEST.6

TIBER-EU

TIBER.GTLTIBER.RTTIBER.TTI

Common Criteria

CC Part 3 — SAR

Solvency II

DR.266

Lloyd's Minimum Standards

CRM.2MS8.11MS10.2

NAIC Insurance Data Security

4-monitoring4A

FCA SYSC 13

SYSC 13.5.3

HITRUST CSF v11

03.a06.c09.c10.e

FDA Cybersecurity Guidance

524B-2CRA-1MON-1MON-2SBOM-3ST-1ST-2ST-3ST-4TM-1

ISO 27799

12.518.4H.3

NHS DSPT

NDG-8.1NDG-8.2NDG-9.8NDG-9.9

OWASP MASVS v2.1

MASVS-CODE-3

CCSS v9.0

2.01.12.01.2

MiCA

Art.35(1)

Basel SCO60

SCO60.4SCO60.13SCO60.14SCO60.21SCO60.23SCO60.51SCO60.52SCO60.64SCO60.65SCO60.74

BSSC Standards

GSP-02GSP-08GSP-15NOS-10TIS-02

SEC Custody (Digital Assets)

SEC-CD-09

India DPDPA

Act.8(5)Rules.Sch1.B.7

ISO 17799 (legacy)

12.6.1

COBIT 4.1 (legacy)

PO9.3DS5.5