CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0
Vulnerability Management

CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 CPG-5.A: Vulnerability Disclosure Program

Maintain a public vulnerability disclosure policy for external researchers.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 103 controls across 69 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO/IEC 30111:2019 · 5 controls

  • 30111-1 Scope
  • 30111-3 Terms and definitions
  • 30111-6.5 Remediation Strategy Selection
  • 30111-7.3 Quality assurance of remediation
  • 30111-8.1 Post-release monitoring
  • CISABD-2 Embrace Radical Transparency and Accountability
  • CISABD-3 Build Organizational Structure and Leadership for Secure Outcomes
  • SBD-DEV-07 Dependency Management and SBOM
  • CPSC-STD.2 UL 5500 Remote Update Compliance
  • CPSC-SW.2 Software Update Safety Verification
  • CPSC-SW.3 Remote Update Security
  • FTC-Safeguards-IR-Plan-BoardReporting-FTC-Notification Written Incident Response Plan + Board Reporting + FTC Breach Notification (16 CFR 314.4(h), (i), (j))
  • FTC-Safeguards-ServiceProvider-Evaluation Service Provider Oversight + Program Evaluation + Personnel Training (16 CFR 314.4(d-g))

ISO/IEC 29147:2018 · 2 controls

  • 29147-5.6 Advisory Content and Quality
  • 29147-7.8 Remediation information

NIST SP 800-53 Rev 5 · 2 controls

South Korea ISMS-P · 2 controls

  • ISMSP-SYS-01 System Hardening and Patch Management
  • ISMSP-SYS-04 Vulnerability Management

API 1164 · 1 control

  • API1164-11 Logging and Monitoring

BSI IT-Grundschutz · 1 control

  • BSI-14 Vulnerability scanning and management
  • CAT-D3-3 Corrective controls

FISMA · 1 control

  • FISMA-CIRCIA-ZTA-EO14028 CIRCIA, Zero Trust Architecture, EO 14028 + 14110 + OMB Memoranda

FedRAMP Rev 5 · 1 control

  • FedRAMP-ConMon Continuous Monitoring (ConMon) and Significant Change Requests
  • GhCSA-Implementation-Roadmap Implementation Roadmap - Organizational Roles, Tooling and Metrics
  • HKMA-CRAF-Domain3-4-Protection-Detection HKMA C-RAF Domain 3 (Protection) + Domain 4 (Detection) - Access, Data, Infrastructure, Application, Monitoring, Testing, Threat Intel

IEC 62443 · 1 control

  • IEC62443-11 Security patch management for OT

IEEE 1686 · 1 control

  • IEEE1686-Section5.5-5.6-5.7-5.8-Firmware-ConfigSW-TimeSync-DataAtRest IEEE 1686 Section 5.5-5.8 - Firmware Quality + Configuration Software Security + Time Synchronisation + Data Protection at Rest + Patch + Malware + Hardening + Vulnerability

ISMAP (Japan) · 1 control

ISO/IEC 27011:2024 · 1 control

  • 27011-8.5 Vulnerability and malware management

ISO/IEC 27019:2024 · 1 control

  • ISO27019-11 Security patch management for OT

ISO/IEC 27043:2015 · 1 control

  • ISO27043-25 Technical vulnerability management

ISO/IEC 27400:2022 · 1 control

  • 27400-6.3 Secure Update Mechanism

ISO/IEC 29134:2023 · 1 control

  • 29134-9.2 Report findings and recommendations

ISO/SAE 21434 · 1 control

  • ISO21434-25 Technical vulnerability management
  • JP-FSA-CYB-Cybersecurity-Exercises-Drills-Annual-Tabletop-Industry-Wide-Exercise-Delta-Wall-FSA-Coordinated-Sector Japan FSA Cybersecurity Exercises + Drills + Annual Tabletop + Industry-Wide Exercise + Delta Wall + FSA Coordinated Sector-Wide + FISC Drills + Cross-Sector Crisis Coordination + International Exercises + Cyber Range

MITRE ATT&CK · 1 control

MITRE D3FEND · 1 control

MTCS (Singapore) · 1 control

  • MTCS-Acquisition-Development-Maintenance-Supplier-Vulnerability-DevSecOps-SBOM-SDLC-SCA-API-Container MTCS Acquisition + Development + Maintenance + Supplier + Vulnerability + DevSecOps + SBOM + SDLC + SCA
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)

NIST SP 1800-32 · 1 control

  • NISTSP115-3 Target Identification and Analysis - Network Discovery, Port and Service ID, Vuln Scanning

NIST SP 800-123 · 1 control

  • NISTSP123-5 Server Operations - Patching, Malware, Logging, Backup

NIST SP 800-137 · 1 control

  • NISTSP137-5 Vulnerability + Patch + Configuration Status Monitoring

NIST SP 800-144 · 1 control

  • NISTSP144-7 Cloud Workload Protection, Containers, Serverless, and Configuration

NIST SP 800-145 · 1 control

  • NISTSP145-7 Cloud Procurement Standards Aligned to NIST SP 800-145 Definition

NIST SP 800-146 · 1 control

NIST SP 800-190 · 1 control

  • NISTSP61-5 Containment, Eradication, and Recovery

NIST SP 800-63-4 · 1 control

  • NISTSP63R4-8 Operational Audit, Session Management, Recovery, and Cross-cutting Controls
  • NISTSP82-5 OT Configuration Management, Patching, Vulnerability Management, and Malware Protection

NIST SP 800-88 · 1 control

  • NISTSP88-7 Verification, Audit, Training, and Environmental/Safety Controls

NIST SP 800-92 · 1 control

  • NISTSP92-5 Log Analysis: Correlation, Baselining, Anomaly Detection, Alerting, Manual Review
  • NRFCS-2 Risk Assessment, Customer Data Inventory, Classification, and Retail Threat Model
  • NGCB-6 Incident Response, 72-Hour NGCB Notification, and Independent Investigation
  • NZISM-5 Network Security, System Hardening, and Application Security
  • ORANWG11-1 O-RAN Threat Model, Risk Management, and Security Architecture
  • DSOMM-1 Culture, Organization, Education, and Governance

OWASP MASVS · 1 control

  • OWASPMASVS-6 MASVS-CODE: Code Quality, Build Settings, and Updates

OWASP SAMM · 1 control

  • OWASPSAMM-4 Verification: Architecture Assessment, Requirements-Driven Testing, Security Testing

OpenSSF Scorecard · 1 control

  • OSSFSC-2 Dependency Management, Pinning, Updates, Vulnerability Tracking
  • PASONE-6 Incident Management, Audit, Handover, Operational Phase, Decommissioning

PTES · 1 control

  • PTESPHASE-4 Vulnerability Analysis
  • SAEIGHT-1 Child Labour and Young Worker Protection
  • PICERL-E1 Threat Removal
  • SHAREASSESS-4 Vulnerability Management, Patching, Application Security

SLSA · 1 control

  • SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule
  • SSAE18-CC7.4 CC7.4 - Incident Response
  • SOCI-S30CU Vulnerability assessments
  • SCA-S26 Licensing Framework
  • IM8-SEC.4 Vulnerability Management
  • TSAPIPE-1 Cybersecurity Implementation Plan and Coordinator
  • UKOPRES-4 Incident Management, Lessons Learned, Comms
  • UNGPBHR-2 Pillar II: Corporate Responsibility to Respect Human Rights

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Vulnerability Management

Query this from an agent

The graph holds this control, the 103 it maps to, and the evidence behind each claim, over MCP and REST.