C5 (Germany)
C5: Operations

C5 (Germany) C5-OPS-18: Managing Vulnerabilities, Malfunctions and Errors - Concept

Publish technical and organisational rules for vulnerability handling requiring regular identification of vulnerabilities, assessment of their severity, prioritised remediation or mitigation within defined timelines, and a defined treatment for components where no timely fix will be applied.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 78 controls across 28 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

CIS Controls v8 · 8 controls

  • CIS-12.1 Ensure Network Infrastructure is Up-to-Date
  • CIS-16.5 Use Up-to-Date and Trusted Third-Party Software Components
  • CIS-2.2 Ensure Authorized Software is Currently Supported
  • CIS-7.1 Establish and Maintain a Vulnerability Management Process
  • CIS-7.2 Establish and Maintain a Remediation Process
  • CIS-7.3 Perform Automated Operating System Patch Management
  • CIS-7.4 Perform Automated Application Patch Management
  • CIS-7.5 Perform Automated Vulnerability Scans of Internal Enterprise Assets

FedRAMP High · 5 controls

  • RA-5 Vulnerability Monitoring and Scanning
  • RA-5(2) Update Vulnerabilities to be Scanned
  • RA-5(5) Privileged Access
  • SI-1 Policy and Procedures
  • SI-2 Flaw Remediation

FedRAMP Moderate · 5 controls

  • RA-5 Vulnerability Monitoring and Scanning
  • RA-5(2) Update Vulnerabilities to be Scanned
  • RA-5(5) Privileged Access
  • SI-1 Policy and Procedures
  • SI-2 Flaw Remediation

ACSC Essential Eight · 4 controls

  • E8-PATCHAPP-ML1 Patch Applications (ML1)
  • E8-PATCHAPP-ML3 Patch Applications (ML3)
  • E8-PATCHOS-ML1 Patch Operating Systems (ML1)
  • E8-PATCHOS-ML2 Patch Operating Systems (ML2)
  • SEC01-BP04 Stay up to date with security threats and recommendations
  • SEC04-BP04 Initiate remediation for non-compliant resources
  • SEC06-BP01 Perform vulnerability management
  • SEC06-BP05 Automate compute protection

NIST SP 800-218 · 4 controls

PCI DSS 4.0 · 4 controls

  • 11.3.1 11.3.1 Quarterly internal vulnerability scans
  • 11.3.2 11.3.2 Quarterly ASV external vulnerability scans
  • 6.3.1 6.3.1 Vulnerability identification and risk ranking
  • 6.3.3 6.3.3 Timely installation of security patches
  • ASBv3-GS-5 Define and implement security posture management strategy
  • ASBv3-PV-6 Rapidly and automatically remediate vulnerabilities
  • PV-5 Perform vulnerability assessments

CMMC 2.0 · 3 controls

  • CCM-TVM-01 Threat and Vulnerability Management Policy and Procedures
  • CCM-TVM-05 External Library Vulnerabilities
  • CCM-TVM-07 Vulnerability Identification
  • NIST-CSF-DE.CM-09 Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events
  • NIST-CSF-ID.RA-01 Vulnerabilities in assets are identified, validated, and recorded
  • NIST-CSF-PR.PS-02 Software is maintained, replaced, and removed commensurate with risk

NIST SP 800-171 Rev 3 · 3 controls

NIST SP 800-53 Rev 5 · 3 controls

UK Cyber Essentials · 3 controls

  • CE-SU.1 Software Licensed and Supported
  • CE-SU.3 Critical and High Updates within 14 Days
  • CE-SU.4 Remove Out-of-Support Software
  • ANSSI-HYG-34 Define an Update Policy for Information System Components
  • ANSSI-HYG-35 Anticipate the End of Maintenance of Software and Systems

APRA CPS 234 · 2 controls

  • CPS234-21 Implementation of Information Security Controls
  • CPS234-P17 Active Maintenance of Capability Against Change
  • ASD37-02 Patch applications (Essential)
  • ASD37-19 Patch operating systems (Essential)
  • CFTC-SS-21 Remediation of Vulnerabilities and Deficiencies
  • CFTC-SS-4 Systems Operations Category

HIPAA Security Rule · 2 controls

ISO 27001:2022 · 2 controls

  • 5.7 Threat intelligence
  • 8.8 Management of technical vulnerabilities

ISO 27002:2022 · 2 controls

  • 5.7 Threat intelligence
  • 8.8 Management of technical vulnerabilities

NIST SP 800-161 Rev 1 · 2 controls

NIST SP 800-66 Rev 2 · 2 controls

  • CPS230-P31 Remediation of Material Operational Risk Weaknesses
  • AUCDR-IS-4 Formal vulnerability management program

DORA · 1 control

NIS2 Directive · 1 control

  • Art.21.2.e Security in acquisition, development and maintenance, including vulnerability handling and disclosure

SOC 2 · 1 control

  • SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in C5: Operations

You are reading one control. How much of C5 (Germany) have you already done?

C5 (Germany) C5-OPS-18 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of C5 (Germany) your existing evidence covers. Hold Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 and 95 of 121 C5 (Germany) controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 pair alone.

Query this from an agent

The graph holds this control, the 78 it maps to, and the evidence behind each claim, over MCP and REST.