CMMC 2.0
Risk Assessment

CMMC 2.0 RA.L2-3.11.2: Vulnerability Scan

Scan systems and applications for vulnerabilities periodically and again when new vulnerabilities affecting them are identified.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 77 controls across 27 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 16 controls

  • 1.2.6 1.2.6 Security features for insecure services in use
  • 11.2.1 11.2.1 Detect authorized and rogue wireless access points
  • 11.3.1 11.3.1 Quarterly internal vulnerability scans
  • 11.3.1.2 11.3.1.2 Authenticated internal vulnerability scanning
  • 11.3.1.3 11.3.1.3 Internal scans after significant change
  • 11.3.2 11.3.2 Quarterly ASV external vulnerability scans
  • 11.3.2.1 11.3.2.1 External scans after significant change
  • 11.4.2 11.4.2 Internal penetration testing annually and after change
  • 11.4.3 11.4.3 External penetration testing annually and after change
  • 11.4.5 11.4.5 Annual segmentation penetration testing
  • 2.2.1 2.2.1 System configuration standards maintained
  • 6.4.1 6.4.1 Public web application review or automated protection
  • 5.2.1 5.2.1 Anti-malware deployed on all system components
  • 6.3.1 6.3.1 Vulnerability identification and risk ranking
  • 6.3.2 6.3.2 Inventory of bespoke software and components
  • 6.3.3 6.3.3 Timely installation of security patches

CIS Controls v8 · 10 controls

  • CIS-12.1 Ensure Network Infrastructure is Up-to-Date
  • CIS-16.13 Conduct Application Penetration Testing
  • CIS-16.2 Establish and Maintain a Process to Accept and Address Software Vulnerabilities
  • CIS-16.5 Use Up-to-Date and Trusted Third-Party Software Components
  • CIS-18.2 Perform Periodic External Penetration Tests
  • CIS-18.5 Perform Periodic Internal Penetration Tests
  • CIS-7.1 Establish and Maintain a Vulnerability Management Process
  • CIS-7.5 Perform Automated Vulnerability Scans of Internal Enterprise Assets
  • CIS-7.6 Perform Automated Vulnerability Scans of Externally-Exposed Enterprise Assets
  • CIS-7.7 Remediate Detected Vulnerabilities

SOC 2 · 6 controls

  • SOC2-CC3.2 CC3.2 Identifying and analysing risks to objectives (COSO principle 7)
  • SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16)
  • SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11)
  • SOC2-CC6.8 CC6.8 Preventing and detecting unauthorised or malicious software
  • SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities
  • SOC2-CC7.2 CC7.2 Monitoring system components for anomalies

NIST SP 800-218 · 4 controls

  • SEC06-BP01 Perform vulnerability management
  • SEC11-BP02 Automate testing throughout the development and release lifecycle
  • SEC11-BP03 Perform regular penetration testing

C5 (Germany) · 3 controls

  • C5-OPS-18 Managing Vulnerabilities, Malfunctions and Errors - Concept
  • C5-OPS-22 Testing and Documentation of known Vulnerabilities
  • C5-PSS-02 Identification of Vulnerabilities of the Cloud Service

FedRAMP High · 3 controls

  • RA-5 Vulnerability Monitoring and Scanning
  • RA-5(2) Update Vulnerabilities to be Scanned
  • RA-5(5) Privileged Access

FedRAMP Moderate · 3 controls

  • RA-5 Vulnerability Monitoring and Scanning
  • RA-5(2) Update Vulnerabilities to be Scanned
  • RA-5(5) Privileged Access

NIST SP 800-53 Rev 5 · 3 controls

  • NIST800-PM-31 PM-31 Continuous Monitoring Strategy
  • NIST800-RA-5 RA-5 Vulnerability Monitoring and Scanning
  • SP800-53-RA Risk Assessment Family

ACSC Essential Eight · 2 controls

  • E8-PATCHAPP-ML1 Patch Applications (ML1)
  • E8-PATCHOS-ML1 Patch Operating Systems (ML1)

APRA CPS 234 · 2 controls

  • CPS234-22 Systematic Control Testing Program
  • CPS234-P17 Active Maintenance of Capability Against Change
  • ASD37-02 Patch applications (Essential)
  • ASD37-19 Patch operating systems (Essential)
  • DS-2 Ensure software supply chain security
  • PV-5 Perform vulnerability assessments

HIPAA Security Rule · 2 controls

NIST SP 800-66 Rev 2 · 2 controls

  • ANSSI-HYG-38 Carry Out Regular Security Checks and Audits and Apply the Corrective Actions
  • AUCDR-IS-4 Formal vulnerability management program

ISO 27001:2022 · 1 control

  • 8.8 Management of technical vulnerabilities

ISO 27002:2022 · 1 control

  • 8.8 Management of technical vulnerabilities

ISO 27701:2019 · 1 control

  • 6.9.6 Technical vulnerability management

ISO/IEC 42001:2023 · 1 control

  • 9.1 Monitoring, measurement, analysis and evaluation
  • 03.11.02 Vulnerability Monitoring and Scanning

NIST SP 800-172 · 1 control

  • 3.12.1e Penetration Testing by Independent Agents

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Risk Assessment

You are reading one control. How much of CMMC 2.0 have you already done?

CMMC 2.0 RA.L2-3.11.2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of CMMC 2.0 your existing evidence covers. Hold FedRAMP Moderate and 108 of 110 CMMC 2.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 1 were rejected on the FedRAMP Moderate pair alone.

Query this from an agent

The graph holds this control, the 77 it maps to, and the evidence behind each claim, over MCP and REST.