Frameworks / CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 / CPG-5.A What else in your programme already covers this This control maps to 103 controls across 69 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
30111-1 Scope 30111-3 Terms and definitions 30111-6.5 Remediation Strategy Selection 30111-7.3 Quality assurance of remediation 30111-8.1 Post-release monitoring CISABD-2 Embrace Radical Transparency and Accountability CISABD-3 Build Organizational Structure and Leadership for Secure Outcomes SBD-DEV-07 Dependency Management and SBOM CPSC-STD.2 UL 5500 Remote Update Compliance CPSC-SW.2 Software Update Safety Verification CPSC-SW.3 Remote Update Security FTC-Safeguards-IR-Plan-BoardReporting-FTC-Notification Written Incident Response Plan + Board Reporting + FTC Breach Notification (16 CFR 314.4(h), (i), (j)) FTC-Safeguards-ServiceProvider-Evaluation Service Provider Oversight + Program Evaluation + Personnel Training (16 CFR 314.4(d-g)) 29147-5.6 Advisory Content and Quality 29147-7.8 Remediation information ISMSP-SYS-01 System Hardening and Patch Management ISMSP-SYS-04 Vulnerability Management API1164-11 Logging and Monitoring AWWA-4.2 Patch Management BSI-14 Vulnerability scanning and management CAT-D3-3 Corrective controls FISMA-CIRCIA-ZTA-EO14028 CIRCIA, Zero Trust Architecture, EO 14028 + 14110 + OMB Memoranda FedRAMP-ConMon Continuous Monitoring (ConMon) and Significant Change Requests GhCSA-Implementation-Roadmap Implementation Roadmap - Organizational Roles, Tooling and Metrics HKMA-CRAF-Domain3-4-Protection-Detection HKMA C-RAF Domain 3 (Protection) + Domain 4 (Detection) - Access, Data, Infrastructure, Application, Monitoring, Testing, Threat Intel IEC62443-11 Security patch management for OT IEEE1686-Section5.5-5.6-5.7-5.8-Firmware-ConfigSW-TimeSync-DataAtRest IEEE 1686 Section 5.5-5.8 - Firmware Quality + Configuration Software Security + Time Synchronisation + Data Protection at Rest + Patch + Malware + Hardening + Vulnerability 27011-8.5 Vulnerability and malware management ISO27019-11 Security patch management for OT ISO27043-25 Technical vulnerability management 27400-6.3 Secure Update Mechanism 29134-9.2 Report findings and recommendations ISO21434-25 Technical vulnerability management JP-FSA-CYB-Cybersecurity-Exercises-Drills-Annual-Tabletop-Industry-Wide-Exercise-Delta-Wall-FSA-Coordinated-Sector Japan FSA Cybersecurity Exercises + Drills + Annual Tabletop + Industry-Wide Exercise + Delta Wall + FSA Coordinated Sector-Wide + FISC Drills + Cross-Sector Crisis Coordination + International Exercises + Cyber Range MTCS-Acquisition-Development-Maintenance-Supplier-Vulnerability-DevSecOps-SBOM-SDLC-SCA-API-Container MTCS Acquisition + Development + Maintenance + Supplier + Vulnerability + DevSecOps + SBOM + SDLC + SCA NISTPF-8 Protect-P Information Protection Processes (PR.PO-P) NISTSP115-3 Target Identification and Analysis - Network Discovery, Port and Service ID, Vuln Scanning NISTSP123-5 Server Operations - Patching, Malware, Logging, Backup NISTSP137-5 Vulnerability + Patch + Configuration Status Monitoring NISTSP144-7 Cloud Workload Protection, Containers, Serverless, and Configuration NISTSP145-7 Cloud Procurement Standards Aligned to NIST SP 800-145 Definition NISTSP61-5 Containment, Eradication, and Recovery NISTSP63R4-8 Operational Audit, Session Management, Recovery, and Cross-cutting Controls NISTSP82-5 OT Configuration Management, Patching, Vulnerability Management, and Malware Protection NISTSP88-7 Verification, Audit, Training, and Environmental/Safety Controls NISTSP92-5 Log Analysis: Correlation, Baselining, Anomaly Detection, Alerting, Manual Review NRFCS-2 Risk Assessment, Customer Data Inventory, Classification, and Retail Threat Model NGCB-6 Incident Response, 72-Hour NGCB Notification, and Independent Investigation NZISM-5 Network Security, System Hardening, and Application Security ORANWG11-1 O-RAN Threat Model, Risk Management, and Security Architecture DSOMM-1 Culture, Organization, Education, and Governance OWASPMASVS-6 MASVS-CODE: Code Quality, Build Settings, and Updates OWASPSAMM-4 Verification: Architecture Assessment, Requirements-Driven Testing, Security Testing OSSFSC-2 Dependency Management, Pinning, Updates, Vulnerability Tracking PASONE-6 Incident Management, Audit, Handover, Operational Phase, Decommissioning PTESPHASE-4 Vulnerability Analysis RMI-DD-4 Due Diligence Reporting SAEIGHT-1 Child Labour and Young Worker Protection SHAREASSESS-4 Vulnerability Management, Patching, Application Security SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule SSAE18-CC7.4 CC7.4 - Incident Response SOCI-S30CU Vulnerability assessments SCA-S26 Licensing Framework IM8-SEC.4 Vulnerability Management TSAPIPE-1 Cybersecurity Implementation Plan and Coordinator UKOPRES-4 Incident Management, Lessons Learned, Comms UNGPBHR-2 Pillar II: Corporate Responsibility to Respect Human Rights VES-3 Penetration Testing Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in Vulnerability Management Query this from an agent The graph holds this control, the 103 it maps to, and the evidence behind each claim, over MCP and REST.