Frameworks / ISO 27001:2022 / 8.8 ISO 27001:2022
Technological controls – ISO 27001:2022
ISO 27001:2022 8.8: Management of technical vulnerabilities The organization is to gather information about technical vulnerabilities in the information systems it uses, assess how exposed it is, and take suitable action. Purpose (stated in ISO/IEC 27002:2022): prevents exploitation of technical vulnerabilities. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.8.
Maintained by Gerard Blokdyk · Verified against the published standard 18 August 2026 · Control text last updated 25 September 2026 What else in your programme already covers this This control maps to 172 controls across 33 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
1.2.6 1.2.6 Security features for insecure services in use 11.3.1 11.3.1 Quarterly internal vulnerability scans 11.3.1.1 11.3.1.1 Lower-risk vulnerabilities handled per risk analysis 11.3.1.2 11.3.1.2 Authenticated internal vulnerability scanning 11.3.1.3 11.3.1.3 Internal scans after significant change 11.3.2 11.3.2 Quarterly ASV external vulnerability scans 11.3.2.1 11.3.2.1 External scans after significant change 11.4.1 11.4.1 Penetration testing methodology defined and implemented 11.4.2 11.4.2 Internal penetration testing annually and after change 11.4.3 11.4.3 External penetration testing annually and after change 11.4.4 11.4.4 Correct exploitable findings from penetration tests 11.4.6 11.4.6 Service provider segmentation testing every six months 12.3.3 12.3.3 Cryptographic cipher suite and protocol inventory reviewed annually 12.3.4 12.3.4 Annual review of hardware and software technologies 12.6.1 12.6.1 Formal security awareness program 2.2.1 2.2.1 System configuration standards maintained 2.2.5 2.2.5 Insecure services, protocols or daemons secured 5.3.2.1 5.3.2.1 Targeted risk analysis sets malware scan frequency 6.4.1 6.4.1 Public web application review or automated protection 5.3.1 5.3.1 Anti-malware kept current through automatic updates 6.3.1 6.3.1 Vulnerability identification and risk ranking 6.3.2 6.3.2 Inventory of bespoke software and components 6.3.3 6.3.3 Timely installation of security patches CIS-10.5 Enable Anti-Exploitation Features CIS-12.1 Ensure Network Infrastructure is Up-to-Date CIS-13.5 Manage Access Control for Remote Assets CIS-14.7 Train Workforce on How to Identify and Report if Their Enterprise Assets are Missing Security Updates CIS-16.2 Establish and Maintain a Process to Accept and Address Software Vulnerabilities CIS-16.4 Establish and Manage an Inventory of Third-Party Software Components CIS-16.5 Use Up-to-Date and Trusted Third-Party Software Components CIS-16.6 Establish and Maintain a Severity Rating System and Process for Application Vulnerabilities CIS-18.2 Perform Periodic External Penetration Tests CIS-18.3 Remediate Penetration Test Findings CIS-2.2 Ensure Authorized Software is Currently Supported CIS-7.1 Establish and Maintain a Vulnerability Management Process CIS-7.2 Establish and Maintain a Remediation Process CIS-7.3 Perform Automated Operating System Patch Management CIS-7.4 Perform Automated Application Patch Management CIS-7.5 Perform Automated Vulnerability Scans of Internal Enterprise Assets CIS-7.6 Perform Automated Vulnerability Scans of Externally-Exposed Enterprise Assets CIS-7.7 Remediate Detected Vulnerabilities CIS-9.1 Ensure Use of Only Fully Supported Browsers and Email Clients CA-7 Continuous Monitoring CM-12(1) Information Location | Automated Tools to Support Information Location (CM-12(1)) RA-5 Vulnerability Monitoring and Scanning RA-5(2) Update Vulnerabilities to be Scanned RA-5(3) Vulnerability Monitoring and Scanning | Breadth and Depth of Coverage (RA-5(3)) SA-22 Unsupported System Components (SA-22) SI-2 Flaw Remediation SI-2(2) Automated Flaw Remediation Status SI-2(3) Flaw Remediation | Time to Remediate Flaws and Benchmarks for Corrective Actions (SI-2(3)) SI-8(2) Spam Protection | Automatic Updates (SI-8(2)) SR-10 Inspection of Systems or Components (SR-10) RA-7 Risk Response CA-7 Continuous Monitoring CM-12(1) Information Location | Automated Tools to Support Information Location (CM-12(1)) RA-5 Vulnerability Monitoring and Scanning RA-5(2) Update Vulnerabilities to be Scanned RA-5(3) Vulnerability Monitoring and Scanning | Breadth and Depth of Coverage (RA-5(3)) SA-22 Unsupported System Components (SA-22) SI-2 Flaw Remediation SI-2(2) Automated Flaw Remediation Status SI-2(3) Flaw Remediation | Time to Remediate Flaws and Benchmarks for Corrective Actions (SI-2(3)) SI-8(2) Spam Protection | Automatic Updates (SI-8(2)) SR-10 Inspection of Systems or Components (SR-10) SEC01-BP04 Stay up to date with security threats and recommendations SEC04-BP04 Initiate remediation for non-compliant resources SEC06-BP01 Perform vulnerability management SEC06-BP05 Automate compute protection SEC11-BP02 Automate testing throughout the development and release lifecycle SEC11-BP03 Perform regular penetration testing C5-OPS-18 Managing Vulnerabilities, Malfunctions and Errors - Concept C5-OPS-19 Managing Vulnerabilities, Malfunctions and Errors - Penetration Tests C5-OPS-20 Managing Vulnerabilities, Malfunctions and Errors - Measurements, Analyses and Assessments of Procedures C5-OPS-22 Testing and Documentation of known Vulnerabilities C5-PSS-02 Identification of Vulnerabilities of the Cloud Service C5-PSS-03 Online Register of Known Vulnerabilities NIST-CSF-ID.RA-01 Vulnerabilities in assets are identified, validated, and recorded NIST-CSF-ID.RA-04 Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded NIST-CSF-ID.RA-05 Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization NIST-CSF-ID.RA-06 Risk responses are chosen, prioritized, planned, tracked, and communicated NIST-CSF-PR.PS-02 Software is maintained, replaced, and removed commensurate with risk NIST-CSF-RS.MI-02 Incidents are eradicated SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11) SOC2-CC6.8 CC6.8 Preventing and detecting unauthorised or malicious software SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities SOC2-CC7.2 CC7.2 Monitoring system components for anomalies SOC2-CC7.3 CC7.3 Evaluating security events to identify incidents SOC2-CC8.1 CC8.1 Managing changes to procedures, software, data and infrastructure E8-PATCHAPP-ML1 Patch Applications (ML1) E8-PATCHAPP-ML3 Patch Applications (ML3) E8-PATCHOS-ML1 Patch Operating Systems (ML1) E8-PATCHOS-ML3 Patch Operating Systems (ML3) ASBv3-PV-6 Rapidly and automatically remediate vulnerabilities ASBv3-PV-7 Conduct regular red team operations DS-2 Ensure software supply chain security PV-5 Perform vulnerability assessments CE-SU.1 Software Licensed and Supported CE-SU.2 Automatic Updates Enabled Where Possible CE-SU.3 Critical and High Updates within 14 Days CE-SU.4 Remove Out-of-Support Software ANSSI-HYG-34 Define an Update Policy for Information System Components ANSSI-HYG-35 Anticipate the End of Maintenance of Software and Systems ANSSI-HYG-38 Carry Out Regular Security Checks and Audits and Apply the Corrective Actions BAI03.10 BAI03.10 Maintain solutions DSS05.01 DSS05.01 Protect against malicious software DSS05.07 DSS05.07 Manage vulnerabilities and monitor the infrastructure for security-related events Art.21.2.e Security in acquisition, development and maintenance, including vulnerability handling and disclosure Art.21.2.g Basic cyber hygiene practices and cybersecurity training Art.21.4 Take corrective measures without undue delay on finding that the measures are not met CPS234-22 Systematic Control Testing Program CPS234-P17 Active Maintenance of Capability Against Change ASD37-02 Patch applications (Essential) ASD37-19 Patch operating systems (Essential) 6.9.5 Control of operational software 6.9.6 Technical vulnerability management CPS230-P31 Remediation of Material Operational Risk Weaknesses AUCDR-IS-4 Formal vulnerability management program A.12.6.1 Management of technical vulnerabilities 8.8 Management of technical vulnerabilities 3.12.1e Penetration Testing by Independent Agents Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in Technological controls – ISO 27001:2022 You are reading one control. How much of ISO 27001:2022 have you already done? ISO 27001:2022 8.8 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27001:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27001:2022 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 170 were rejected on the NIST SP 800-53 Rev 5 pair alone.
Query this from an agent The graph holds this control, the 172 it maps to, and the evidence behind each claim, over MCP and REST.