CIS Controls v8
CIS Control 7: Continuous Vulnerability Management

CIS Controls v8 CIS-7.7: Remediate Detected Vulnerabilities

Fix vulnerabilities found in software, using processes and tools in line with the remediation process, at least once a month.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 62 controls across 28 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 8 controls

  • 11.3.1 11.3.1 Quarterly internal vulnerability scans
  • 11.3.1.1 11.3.1.1 Lower-risk vulnerabilities handled per risk analysis
  • 11.3.1.3 11.3.1.3 Internal scans after significant change
  • 11.3.2 11.3.2 Quarterly ASV external vulnerability scans
  • 11.3.2.1 11.3.2.1 External scans after significant change
  • 12.6.1 12.6.1 Formal security awareness program
  • 6.3.1 6.3.1 Vulnerability identification and risk ranking
  • 6.3.3 6.3.3 Timely installation of security patches

FedRAMP High · 5 controls

  • CA-5 Plan of Action and Milestones
  • RA-5 Vulnerability Monitoring and Scanning
  • SI-2 Flaw Remediation
  • SI-2(2) Automated Flaw Remediation Status
  • SI-2(3) Flaw Remediation | Time to Remediate Flaws and Benchmarks for Corrective Actions (SI-2(3))

FedRAMP Moderate · 5 controls

  • CA-5 Plan of Action and Milestones
  • RA-5 Vulnerability Monitoring and Scanning
  • SI-2 Flaw Remediation
  • SI-2(2) Automated Flaw Remediation Status
  • SI-2(3) Flaw Remediation | Time to Remediate Flaws and Benchmarks for Corrective Actions (SI-2(3))

SOC 2 · 5 controls

  • SOC2-CC4.2 CC4.2 Evaluating and communicating control deficiencies (COSO principle 17)
  • SOC2-CC6.8 CC6.8 Preventing and detecting unauthorised or malicious software
  • SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities
  • SOC2-CC7.2 CC7.2 Monitoring system components for anomalies
  • SOC2-CC8.1 CC8.1 Managing changes to procedures, software, data and infrastructure
  • NIST-CSF-GV.OV-03 Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed
  • NIST-CSF-ID.IM-02 Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties
  • NIST-CSF-ID.RA-06 Risk responses are chosen, prioritized, planned, tracked, and communicated
  • NIST-CSF-PR.PS-02 Software is maintained, replaced, and removed commensurate with risk

CMMC 2.0 · 3 controls

NIST SP 800-171 Rev 3 · 3 controls

  • ASD37-02 Patch applications (Essential)
  • ASD37-19 Patch operating systems (Essential)
  • ISM-1692 Critical patches for user-facing applications within 48 hours
  • ISM-1696 Critical OS patches for internal systems within 48 hours

ISO 27701:2019 · 2 controls

  • 6.9 Operations security
  • 6.9.6 Technical vulnerability management

NIST SP 800-161 Rev 1 · 2 controls

NIST SP 800-53 Rev 5 · 2 controls

  • E8-PATCHAPP-ML1 Patch Applications (ML1)
  • ANSSI-HYG-38 Carry Out Regular Security Checks and Audits and Apply the Corrective Actions

APRA CPS 234 · 1 control

  • CPS234-P17 Active Maintenance of Capability Against Change
  • AUCDR-IS-4 Formal vulnerability management program
  • ASBv3-PV-6 Rapidly and automatically remediate vulnerabilities

C5 (Germany) · 1 control

  • C5-OPS-22 Testing and Documentation of known Vulnerabilities
  • CFTC-SS-21 Remediation of Vulnerabilities and Deficiencies

HIPAA Security Rule · 1 control

ISO 27001:2022 · 1 control

  • 8.8 Management of technical vulnerabilities

ISO 27002:2022 · 1 control

  • 8.8 Management of technical vulnerabilities

NIS2 Directive · 1 control

  • Art.21.4 Take corrective measures without undue delay on finding that the measures are not met

NIST SP 800-218 · 1 control

UK Cyber Essentials · 1 control

  • CE-SU.3 Critical and High Updates within 14 Days

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CIS Control 7: Continuous Vulnerability Management

You are reading one control. How much of CIS Controls v8 have you already done?

CIS Controls v8 CIS-7.7 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of CIS Controls v8 your existing evidence covers. Hold ISO 27001:2022 and 102 of 153 CIS Controls v8 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 240 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 62 it maps to, and the evidence behind each claim, over MCP and REST.