|
controlRA-5

Vulnerability Monitoring and Scanning (RA-5)

Monitor and scan for vulnerabilities in the system and hosted applications [organization-defined] and when new vulnerabilities potentially affecting the system are identified and reported; Employ vulnerability monitoring tools and techniques that facilitate interoperability among tools and automate parts of the vulnerability management process by using standards for: Analyze vulnerability scan reports and results from vulnerability monitoring; Remediate legitimate vulnerabilities [organization-d

Security Baselines

LOWMODERATEHIGH
risk-assessmentvulnerabilitythreat

Why These Connect

Maps To13

These are equivalent or closely aligned requirements in other frameworks.

Baselined In3

This control is included in the linked security baseline (LOW, MODERATE, or HIGH).

Supports42

These related controls work together — a change to one may affect the others.

Enhances11

These enhancements add specific capabilities or refinements to the base control.

Cross-Framework Mappings(13)

GV.SC-10GV.SC-10Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ID.RA-01ID.RA-01Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ID.RA-08ID.RA-08Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ID.IM-01ID.IM-01Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ID.IM-02ID.IM-02Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ID.IM-03ID.IM-03Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ISO 27001ISO/IEC 27001:20221 mappingFinal
NIST OLIR informative reference — SP 800-53 Rev 5 to ISO/IEC 27001:2022
GV.SC-10GV.SC-10Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ID.RA-01ID.RA-01Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ID.RA-08ID.RA-08Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ID.IM-01ID.IM-01Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ID.IM-02ID.IM-02Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ID.IM-03ID.IM-03Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5

Organization-Defined Parameters(4)

Assignmentorganization-defined frequency and/or randomly in accordance with organization-defined process
Assignmentorganization-defined frequency and/or randomly in accordance with organization-defined process
Assignmentorganization-defined response times
Assignmentorganization-defined personnel or roles

Control Enhancements(11)