ISO 27001:2022
Technological controls – ISO 27001:2022

ISO 27001:2022 8.8: Management of technical vulnerabilities

The organization is to gather information about technical vulnerabilities in the information systems it uses, assess how exposed it is, and take suitable action. Purpose (stated in ISO/IEC 27002:2022): prevents exploitation of technical vulnerabilities. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.8.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 172 controls across 33 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 23 controls

  • 1.2.6 1.2.6 Security features for insecure services in use
  • 11.3.1 11.3.1 Quarterly internal vulnerability scans
  • 11.3.1.1 11.3.1.1 Lower-risk vulnerabilities handled per risk analysis
  • 11.3.1.2 11.3.1.2 Authenticated internal vulnerability scanning
  • 11.3.1.3 11.3.1.3 Internal scans after significant change
  • 11.3.2 11.3.2 Quarterly ASV external vulnerability scans
  • 11.3.2.1 11.3.2.1 External scans after significant change
  • 11.4.1 11.4.1 Penetration testing methodology defined and implemented
  • 11.4.2 11.4.2 Internal penetration testing annually and after change
  • 11.4.3 11.4.3 External penetration testing annually and after change
  • 11.4.4 11.4.4 Correct exploitable findings from penetration tests
  • 11.4.6 11.4.6 Service provider segmentation testing every six months
  • 12.3.3 12.3.3 Cryptographic cipher suite and protocol inventory reviewed annually
  • 12.3.4 12.3.4 Annual review of hardware and software technologies
  • 12.6.1 12.6.1 Formal security awareness program
  • 2.2.1 2.2.1 System configuration standards maintained
  • 2.2.5 2.2.5 Insecure services, protocols or daemons secured
  • 5.3.2.1 5.3.2.1 Targeted risk analysis sets malware scan frequency
  • 6.4.1 6.4.1 Public web application review or automated protection
  • 5.3.1 5.3.1 Anti-malware kept current through automatic updates
  • 6.3.1 6.3.1 Vulnerability identification and risk ranking
  • 6.3.2 6.3.2 Inventory of bespoke software and components
  • 6.3.3 6.3.3 Timely installation of security patches

CIS Controls v8 · 19 controls

  • CIS-10.5 Enable Anti-Exploitation Features
  • CIS-12.1 Ensure Network Infrastructure is Up-to-Date
  • CIS-13.5 Manage Access Control for Remote Assets
  • CIS-14.7 Train Workforce on How to Identify and Report if Their Enterprise Assets are Missing Security Updates
  • CIS-16.2 Establish and Maintain a Process to Accept and Address Software Vulnerabilities
  • CIS-16.4 Establish and Manage an Inventory of Third-Party Software Components
  • CIS-16.5 Use Up-to-Date and Trusted Third-Party Software Components
  • CIS-16.6 Establish and Maintain a Severity Rating System and Process for Application Vulnerabilities
  • CIS-18.2 Perform Periodic External Penetration Tests
  • CIS-18.3 Remediate Penetration Test Findings
  • CIS-2.2 Ensure Authorized Software is Currently Supported
  • CIS-7.1 Establish and Maintain a Vulnerability Management Process
  • CIS-7.2 Establish and Maintain a Remediation Process
  • CIS-7.3 Perform Automated Operating System Patch Management
  • CIS-7.4 Perform Automated Application Patch Management
  • CIS-7.5 Perform Automated Vulnerability Scans of Internal Enterprise Assets
  • CIS-7.6 Perform Automated Vulnerability Scans of Externally-Exposed Enterprise Assets
  • CIS-7.7 Remediate Detected Vulnerabilities
  • CIS-9.1 Ensure Use of Only Fully Supported Browsers and Email Clients

FedRAMP Moderate · 12 controls

  • CA-7 Continuous Monitoring
  • CM-12(1) Information Location | Automated Tools to Support Information Location (CM-12(1))
  • RA-5 Vulnerability Monitoring and Scanning
  • RA-5(2) Update Vulnerabilities to be Scanned
  • RA-5(3) Vulnerability Monitoring and Scanning | Breadth and Depth of Coverage (RA-5(3))
  • SA-22 Unsupported System Components (SA-22)
  • SI-2 Flaw Remediation
  • SI-2(2) Automated Flaw Remediation Status
  • SI-2(3) Flaw Remediation | Time to Remediate Flaws and Benchmarks for Corrective Actions (SI-2(3))
  • SI-8(2) Spam Protection | Automatic Updates (SI-8(2))
  • SR-10 Inspection of Systems or Components (SR-10)
  • RA-7 Risk Response

FedRAMP High · 11 controls

  • CA-7 Continuous Monitoring
  • CM-12(1) Information Location | Automated Tools to Support Information Location (CM-12(1))
  • RA-5 Vulnerability Monitoring and Scanning
  • RA-5(2) Update Vulnerabilities to be Scanned
  • RA-5(3) Vulnerability Monitoring and Scanning | Breadth and Depth of Coverage (RA-5(3))
  • SA-22 Unsupported System Components (SA-22)
  • SI-2 Flaw Remediation
  • SI-2(2) Automated Flaw Remediation Status
  • SI-2(3) Flaw Remediation | Time to Remediate Flaws and Benchmarks for Corrective Actions (SI-2(3))
  • SI-8(2) Spam Protection | Automatic Updates (SI-8(2))
  • SR-10 Inspection of Systems or Components (SR-10)

NIST SP 800-53 Rev 5 · 10 controls

NIST SP 800-218 · 7 controls

  • SEC01-BP04 Stay up to date with security threats and recommendations
  • SEC04-BP04 Initiate remediation for non-compliant resources
  • SEC06-BP01 Perform vulnerability management
  • SEC06-BP05 Automate compute protection
  • SEC11-BP02 Automate testing throughout the development and release lifecycle
  • SEC11-BP03 Perform regular penetration testing

C5 (Germany) · 6 controls

  • C5-OPS-18 Managing Vulnerabilities, Malfunctions and Errors - Concept
  • C5-OPS-19 Managing Vulnerabilities, Malfunctions and Errors - Penetration Tests
  • C5-OPS-20 Managing Vulnerabilities, Malfunctions and Errors - Measurements, Analyses and Assessments of Procedures
  • C5-OPS-22 Testing and Documentation of known Vulnerabilities
  • C5-PSS-02 Identification of Vulnerabilities of the Cloud Service
  • C5-PSS-03 Online Register of Known Vulnerabilities
  • NIST-CSF-ID.RA-01 Vulnerabilities in assets are identified, validated, and recorded
  • NIST-CSF-ID.RA-04 Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded
  • NIST-CSF-ID.RA-05 Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization
  • NIST-CSF-ID.RA-06 Risk responses are chosen, prioritized, planned, tracked, and communicated
  • NIST-CSF-PR.PS-02 Software is maintained, replaced, and removed commensurate with risk
  • NIST-CSF-RS.MI-02 Incidents are eradicated

SOC 2 · 6 controls

  • SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11)
  • SOC2-CC6.8 CC6.8 Preventing and detecting unauthorised or malicious software
  • SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities
  • SOC2-CC7.2 CC7.2 Monitoring system components for anomalies
  • SOC2-CC7.3 CC7.3 Evaluating security events to identify incidents
  • SOC2-CC8.1 CC8.1 Managing changes to procedures, software, data and infrastructure

CMMC 2.0 · 5 controls

NIST SP 800-171 Rev 3 · 5 controls

ACSC Essential Eight · 4 controls

  • E8-PATCHAPP-ML1 Patch Applications (ML1)
  • E8-PATCHAPP-ML3 Patch Applications (ML3)
  • E8-PATCHOS-ML1 Patch Operating Systems (ML1)
  • E8-PATCHOS-ML3 Patch Operating Systems (ML3)
  • ASBv3-PV-6 Rapidly and automatically remediate vulnerabilities
  • ASBv3-PV-7 Conduct regular red team operations
  • DS-2 Ensure software supply chain security
  • PV-5 Perform vulnerability assessments

UK Cyber Essentials · 4 controls

  • CE-SU.1 Software Licensed and Supported
  • CE-SU.2 Automatic Updates Enabled Where Possible
  • CE-SU.3 Critical and High Updates within 14 Days
  • CE-SU.4 Remove Out-of-Support Software
  • ANSSI-HYG-34 Define an Update Policy for Information System Components
  • ANSSI-HYG-35 Anticipate the End of Maintenance of Software and Systems
  • ANSSI-HYG-38 Carry Out Regular Security Checks and Audits and Apply the Corrective Actions

COBIT 2019 · 3 controls

  • BAI03.10 BAI03.10 Maintain solutions
  • DSS05.01 DSS05.01 Protect against malicious software
  • DSS05.07 DSS05.07 Manage vulnerabilities and monitor the infrastructure for security-related events

DORA · 3 controls

HIPAA Security Rule · 3 controls

NIS2 Directive · 3 controls

  • Art.21.2.e Security in acquisition, development and maintenance, including vulnerability handling and disclosure
  • Art.21.2.g Basic cyber hygiene practices and cybersecurity training
  • Art.21.4 Take corrective measures without undue delay on finding that the measures are not met

NIST SP 800-161 Rev 1 · 3 controls

NIST SP 800-66 Rev 2 · 3 controls

APRA CPS 234 · 2 controls

  • CPS234-22 Systematic Control Testing Program
  • CPS234-P17 Active Maintenance of Capability Against Change
  • ASD37-02 Patch applications (Essential)
  • ASD37-19 Patch operating systems (Essential)

EU AI Act · 2 controls

ISO 27701:2019 · 2 controls

  • 6.9.5 Control of operational software
  • 6.9.6 Technical vulnerability management
  • CPS230-P31 Remediation of Material Operational Risk Weaknesses
  • AUCDR-IS-4 Formal vulnerability management program

ISO 27001:2013 · 1 control

  • A.12.6.1 Management of technical vulnerabilities

ISO 27002:2022 · 1 control

  • 8.8 Management of technical vulnerabilities

NIST SP 800-172 · 1 control

  • 3.12.1e Penetration Testing by Independent Agents

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Technological controls – ISO 27001:2022

You are reading one control. How much of ISO 27001:2022 have you already done?

ISO 27001:2022 8.8 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27001:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27001:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 170 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 172 it maps to, and the evidence behind each claim, over MCP and REST.