Canada ITSP.10.033 Security and Privacy Controls and Assurance Activities Catalogue
RA: Risk assessment – Canada ITSP.10.033 Security and Privacy Controls and Assurance Activities Catalogue

Canada ITSP.10.033 Security and Privacy Controls and Assurance Activities Catalogue RA-05: RA-05 Vulnerability monitoring and scanning

The organisation monitors and scans for vulnerabilities in the system and hosted applications at a set frequency or randomly and when new relevant vulnerabilities are reported, uses interoperable tools based on standards for enumerating platforms, flaws and misconfigurations, formatting checklists and measuring impact, analyses scan and monitoring results, remediates legitimate vulnerabilities within set response times based on risk, shares findings with defined roles to fix similar weaknesses elsewhere, and uses tools that can readily update the vulnerabilities scanned. 11 enhancements.

Maintained by Gerard Blokdyk

Other controls in RA: Risk assessment – Canada ITSP.10.033 Security and Privacy Controls and Assurance Activities Catalogue

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.