Azure Security Benchmark
Posture and Vulnerability Management

Azure Security Benchmark ASBv3-PV-6: Rapidly and automatically remediate vulnerabilities

Deploy patches and updates rapidly and automatically to remediate vulnerabilities in cloud resources, prioritising by risk so severe vulnerabilities on high value assets are addressed first.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 76 controls across 27 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

CIS Controls v8 · 8 controls

  • CIS-12.1 Ensure Network Infrastructure is Up-to-Date
  • CIS-16.2 Establish and Maintain a Process to Accept and Address Software Vulnerabilities
  • CIS-18.3 Remediate Penetration Test Findings
  • CIS-2.2 Ensure Authorized Software is Currently Supported
  • CIS-7.2 Establish and Maintain a Remediation Process
  • CIS-7.3 Perform Automated Operating System Patch Management
  • CIS-7.4 Perform Automated Application Patch Management
  • CIS-7.7 Remediate Detected Vulnerabilities

FedRAMP Moderate · 7 controls

  • CA-5 Plan of Action and Milestones
  • CA-7(4) Continuous Monitoring | Risk Monitoring (CA-7(4))
  • SA-22 Unsupported System Components (SA-22)
  • SI-2 Flaw Remediation
  • SI-2(2) Automated Flaw Remediation Status
  • SI-2(3) Flaw Remediation | Time to Remediate Flaws and Benchmarks for Corrective Actions (SI-2(3))
  • RA-7 Risk Response

ACSC Essential Eight · 6 controls

  • E8-PATCHAPP-ML1 Patch Applications (ML1)
  • E8-PATCHAPP-ML2 Patch Applications (ML2)
  • E8-PATCHAPP-ML3 Patch Applications (ML3)
  • E8-PATCHOS-ML1 Patch Operating Systems (ML1)
  • E8-PATCHOS-ML2 Patch Operating Systems (ML2)
  • E8-PATCHOS-ML3 Patch Operating Systems (ML3)

FedRAMP High · 6 controls

  • CA-5 Plan of Action and Milestones
  • CA-7(4) Continuous Monitoring | Risk Monitoring (CA-7(4))
  • SA-22 Unsupported System Components (SA-22)
  • SI-2 Flaw Remediation
  • SI-2(2) Automated Flaw Remediation Status
  • SI-2(3) Flaw Remediation | Time to Remediate Flaws and Benchmarks for Corrective Actions (SI-2(3))

NIST SP 800-171 Rev 3 · 5 controls

NIST SP 800-53 Rev 5 · 5 controls

CMMC 2.0 · 3 controls

PCI DSS 4.0 · 3 controls

  • 11.3.1.1 11.3.1.1 Lower-risk vulnerabilities handled per risk analysis
  • 11.4.4 11.4.4 Correct exploitable findings from penetration tests
  • 6.3.3 6.3.3 Timely installation of security patches

UK Cyber Essentials · 3 controls

  • CE-SU.2 Automatic Updates Enabled Where Possible
  • CE-SU.3 Critical and High Updates within 14 Days
  • CE-SU.5 Firmware Updates
  • ANSSI-HYG-34 Define an Update Policy for Information System Components
  • ANSSI-HYG-38 Carry Out Regular Security Checks and Audits and Apply the Corrective Actions
  • CPS230-P25 Information and Technology Capability and Asset Health
  • CPS230-P31 Remediation of Material Operational Risk Weaknesses

APRA CPS 234 · 2 controls

  • CPS234-21 Implementation of Information Security Controls
  • CPS234-P17 Active Maintenance of Capability Against Change
  • ASD37-02 Patch applications (Essential)
  • ASD37-19 Patch operating systems (Essential)

C5 (Germany) · 2 controls

  • C5-OPS-18 Managing Vulnerabilities, Malfunctions and Errors - Concept
  • C5-OPS-22 Testing and Documentation of known Vulnerabilities
  • CFTC-SS-21 Remediation of Vulnerabilities and Deficiencies
  • CFTC-SS-4 Systems Operations Category
  • NIST-CSF-ID.RA-06 Risk responses are chosen, prioritized, planned, tracked, and communicated
  • NIST-CSF-PR.PS-02 Software is maintained, replaced, and removed commensurate with risk

NIST SP 800-218 · 2 controls

  • AUCDR-IS-4 Formal vulnerability management program

HIPAA Security Rule · 1 control

ISO 27001:2022 · 1 control

  • 8.8 Management of technical vulnerabilities

ISO 27002:2022 · 1 control

  • 8.8 Management of technical vulnerabilities

ISO 27701:2019 · 1 control

  • 6.9.6 Technical vulnerability management

SOC 2 · 1 control

  • SOC2-CC8.1 CC8.1 Managing changes to procedures, software, data and infrastructure

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Posture and Vulnerability Management

You are reading one control. How much of Azure Security Benchmark have you already done?

Azure Security Benchmark ASBv3-PV-6 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of Azure Security Benchmark your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 71 of 85 Azure Security Benchmark controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 76 it maps to, and the evidence behind each claim, over MCP and REST.