ISO 27002:2022
Technological controls – ISO 27002:2022

ISO 27002:2022 8.8: Management of technical vulnerabilities

The organization is to gather information about technical vulnerabilities in the information systems it uses, assess how exposed it is, and take suitable action. Purpose: prevent technical vulnerabilities from being exploited. Identifying vulnerabilities: an accurate asset inventory (5.9 to 5.14) is a precondition, recording software vendor, name, versions, where it is deployed and who is responsible. Consider defining roles for vulnerability monitoring, risk assessment, updating, asset tracking and coordination; identifying and maintaining the information sources used to learn of vulnerabilities in the inventoried technologies; requiring system and component suppliers to report, handle and disclose vulnerabilities, including through contracts (5.20); scanning with tools suited to the technologies in use, also to confirm patches worked; penetration testing or vulnerability assessment that is planned, documented and repeatable and done by competent, authorized testers, with care since they can compromise systems; and tracking vulnerabilities in third-party libraries and source code as part of secure coding (8.28). Build capabilities to detect vulnerabilities in the organization's own products and services, including external components, and to receive reports from inside and outside; publish a public contact point under a vulnerability disclosure policy, with reporting procedures, online forms and use of threat intelligence or sharing forums; consider bug bounty programmes; and share information with competent industry bodies. Evaluating: analyse and verify reports to decide the response, then determine risks and actions such as updating systems or applying other controls. Acting: run a software update management process so approved current patches are installed on all authorized software; keep original software when changes are needed and apply them to a designated copy, fully tested and documented for future upgrades, with independent validation if required. Act promptly and within a defined reaction timeline; route actions through change management (8.32) or incident response (5.26) according to urgency; use updates only from legitimate sources; test and evaluate updates first, weighing the risk of the vulnerability against the risk of installing the update; deal with high-risk systems first; develop remediation, test that it works and provide ways to verify its authenticity; and where no update exists or it cannot be installed, apply vendor workarounds, disable affected services, add or adjust access controls at network borders (8.20 to 8.22), shield systems with traffic filtering (virtual patching), increase monitoring for attacks and raise awareness. Decide whether to use vendors' automatic updates. Keep an audit log of every step, monitor and evaluate the process regularly, and align it with incident management. For cloud services, the provider manages vulnerabilities in its own resources under the service agreement with reporting of its actions (5.23), while the customer handles its own assets. Other information: vulnerability management is a sub-function of change management; updates can fail or be hard to reverse, so where testing is not feasible a delay informed by others' experience may be considered; scanners can misreport where layered countermeasures mask each other; suppliers of products should publish advisories and remediation; ISO/IEC 19086, 27017, 29147 and 30111 give more.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 226 controls across 43 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ACSC Essential Eight · 33 controls

  • E8-PATCHAPP-ML1 Patch Applications (ML1)
  • E8-PATCHAPP-ML3 Patch Applications (ML3)
  • E8-PATCHOS-ML1 Patch Operating Systems (ML1)
  • E8-PATCHOS-ML3 Patch Operating Systems (ML3)
  • E8-PATCHAPP-ISM-0304 Patch applications (ISM-0304): Applications other than office productivity suites, web browsers and their extensions, email clients, PDF software, Adobe Flash Player, and security products that are no longer supported by vendors are removed
  • E8-PATCHAPP-ISM-1690 Patch applications (ISM-1690): Patches, updates or other vendor mitigations for vulnerabilities in online services are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist
  • E8-PATCHAPP-ISM-1691 Patch applications (ISM-1691): Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF software, and security products are applied within two weeks of release
  • E8-PATCHAPP-ISM-1692 Patch applications (ISM-1692): Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF software, and security products are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist
  • E8-PATCHAPP-ISM-1693 Patch applications (ISM-1693): Patches, updates or other vendor mitigations for vulnerabilities in applications other than office productivity suites, web browsers and their extensions, email clients, PDF software, and security products are applied within one month of release
  • E8-PATCHAPP-ISM-1698 Patch applications (ISM-1698): A vulnerability scanner is used at least daily to identify missing patches or updates for vulnerabilities in online services
  • E8-PATCHAPP-ISM-1699 Patch applications (ISM-1699): A vulnerability scanner is used at least weekly to identify missing patches or updates for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF software, and security products
  • E8-PATCHAPP-ISM-1700 Patch applications (ISM-1700): A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in applications other than office productivity suites, web browsers and their extensions, email clients, PDF software, and security products
  • E8-PATCHAPP-ISM-1704 Patch applications (ISM-1704): Office productivity suites, web browsers and their extensions, email clients, PDF software, Adobe Flash Player, and security products that are no longer supported by vendors are removed
  • E8-PATCHAPP-ISM-1808 Patch applications (ISM-1808): A vulnerability scanner with an up-to-date vulnerability database is used for vulnerability scanning activities
  • E8-PATCHAPP-ISM-1876 Patch applications (ISM-1876): Patches, updates or other vendor mitigations for vulnerabilities in online services are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist
  • E8-PATCHAPP-ISM-1901 Patch applications (ISM-1901): Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF software, and security products are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist
  • E8-PATCHAPP-ISM-1905 Patch applications (ISM-1905): Online services that are no longer supported by vendors are removed
  • E8-PATCHOS-ISM-1407 Patch operating systems (ISM-1407): The latest release, or the previous release, of operating systems are used
  • E8-PATCHOS-ISM-1501 Patch operating systems (ISM-1501): Operating systems that are no longer supported by vendors are replaced
  • E8-PATCHOS-ISM-1694 Patch operating systems (ISM-1694): Patches, updates or other vendor mitigations for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist
  • E8-PATCHOS-ISM-1695 Patch operating systems (ISM-1695): Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices are applied within one month of release
  • E8-PATCHOS-ISM-1696 Patch operating systems (ISM-1696): Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist
  • E8-PATCHOS-ISM-1697 Patch operating systems (ISM-1697): Patches, updates or other vendor mitigations for vulnerabilities in drivers are applied within one month of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist
  • E8-PATCHOS-ISM-1701 Patch operating systems (ISM-1701): A vulnerability scanner is used at least daily to identify missing patches or updates for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices
  • E8-PATCHOS-ISM-1702 Patch operating systems (ISM-1702): A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices
  • E8-PATCHOS-ISM-1703 Patch operating systems (ISM-1703): A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in drivers
  • E8-PATCHOS-ISM-1808 Patch operating systems (ISM-1808): A vulnerability scanner with an up-to-date vulnerability database is used for vulnerability scanning activities
  • E8-PATCHOS-ISM-1877 Patch operating systems (ISM-1877): Patches, updates or other vendor mitigations for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist
  • E8-PATCHOS-ISM-1879 Patch operating systems (ISM-1879): Patches, updates or other vendor mitigations for vulnerabilities in drivers are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist
  • E8-PATCHOS-ISM-1900 Patch operating systems (ISM-1900): A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in firmware
  • E8-PATCHOS-ISM-1902 Patch operating systems (ISM-1902): Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices are applied within one month of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist
  • E8-PATCHOS-ISM-1903 Patch operating systems (ISM-1903): Patches, updates or other vendor mitigations for vulnerabilities in firmware are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist
  • E8-PATCHOS-ISM-1904 Patch operating systems (ISM-1904): Patches, updates or other vendor mitigations for vulnerabilities in firmware are applied within one month of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist

PCI DSS 4.0 · 20 controls

  • 1.2.6 1.2.6 Security features for insecure services in use
  • 11.3.1 11.3.1 Quarterly internal vulnerability scans
  • 11.3.1.1 11.3.1.1 Lower-risk vulnerabilities handled per risk analysis
  • 11.3.1.2 11.3.1.2 Authenticated internal vulnerability scanning
  • 11.3.1.3 11.3.1.3 Internal scans after significant change
  • 11.3.2 11.3.2 Quarterly ASV external vulnerability scans
  • 11.3.2.1 11.3.2.1 External scans after significant change
  • 11.4.1 11.4.1 Penetration testing methodology defined and implemented
  • 11.4.3 11.4.3 External penetration testing annually and after change
  • 11.4.4 11.4.4 Correct exploitable findings from penetration tests
  • 12.3.4 12.3.4 Annual review of hardware and software technologies
  • 12.6.1 12.6.1 Formal security awareness program
  • 2.2.1 2.2.1 System configuration standards maintained
  • 2.2.5 2.2.5 Insecure services, protocols or daemons secured
  • 5.3.2.1 5.3.2.1 Targeted risk analysis sets malware scan frequency
  • 6.4.1 6.4.1 Public web application review or automated protection
  • 5.2.3 5.2.3 Periodic evaluation of components not at risk from malware
  • 6.3.1 6.3.1 Vulnerability identification and risk ranking
  • 6.3.2 6.3.2 Inventory of bespoke software and components
  • 6.3.3 6.3.3 Timely installation of security patches
  • ISM-1143 Patch management processes and procedures
  • ISM-1163 Continuous monitoring plan
  • ISM-1606 Patching isolation mechanisms and host operating systems
  • ISM-1690 Non-critical patches for online services within two weeks
  • ISM-1697 Non-critical driver patches within one month
  • ISM-1699 Weekly scanning of office, browser, email, PDF and security products
  • ISM-1751 Non-critical OS patches for other IT equipment within one month
  • ISM-1752 Fortnightly scanning of other IT equipment OS
  • ISM-1808 Up-to-date vulnerability database for scanning
  • ISM-1809 Compensating controls for unsupported systems
  • ISM-1876 Critical patches for online services within 48 hours
  • ISM-1877 Critical OS patches for internet-facing systems within 48 hours
  • ISM-1878 Critical OS patches for other IT equipment within 48 hours
  • ISM-1879 Critical driver patches within 48 hours
  • ISM-1901 Non-critical patches for user-facing applications within two weeks
  • ISM-1902 Non-critical OS patches for internal systems within one month
  • ISM-1903 Critical firmware patches within 48 hours
  • ISM-1904 Non-critical firmware patches within one month
  • ISM-1921 Assessing compromise likelihood for exploited vulnerabilities

CIS Controls v8 · 17 controls

  • CIS-12.1 Ensure Network Infrastructure is Up-to-Date
  • CIS-13.5 Manage Access Control for Remote Assets
  • CIS-14.7 Train Workforce on How to Identify and Report if Their Enterprise Assets are Missing Security Updates
  • CIS-16.2 Establish and Maintain a Process to Accept and Address Software Vulnerabilities
  • CIS-16.5 Use Up-to-Date and Trusted Third-Party Software Components
  • CIS-16.6 Establish and Maintain a Severity Rating System and Process for Application Vulnerabilities
  • CIS-18.1 Establish and Maintain a Penetration Testing Program
  • CIS-18.2 Perform Periodic External Penetration Tests
  • CIS-18.3 Remediate Penetration Test Findings
  • CIS-2.2 Ensure Authorized Software is Currently Supported
  • CIS-7.1 Establish and Maintain a Vulnerability Management Process
  • CIS-7.2 Establish and Maintain a Remediation Process
  • CIS-7.3 Perform Automated Operating System Patch Management
  • CIS-7.4 Perform Automated Application Patch Management
  • CIS-7.5 Perform Automated Vulnerability Scans of Internal Enterprise Assets
  • CIS-7.6 Perform Automated Vulnerability Scans of Externally-Exposed Enterprise Assets
  • CIS-7.7 Remediate Detected Vulnerabilities

FedRAMP High · 12 controls

  • RA-5 Vulnerability Monitoring and Scanning
  • RA-5(11) Vulnerability Monitoring and Scanning | Public Disclosure Program (RA-5(11))
  • RA-5(2) Update Vulnerabilities to be Scanned
  • RA-5(3) Vulnerability Monitoring and Scanning | Breadth and Depth of Coverage (RA-5(3))
  • RA-5(5) Privileged Access
  • SA-22 Unsupported System Components (SA-22)
  • SC-7(12) Boundary Protection | Host-based Protection (SC-7(12))
  • SI-2 Flaw Remediation
  • SI-2(2) Automated Flaw Remediation Status
  • SI-2(3) Flaw Remediation | Time to Remediate Flaws and Benchmarks for Corrective Actions (SI-2(3))
  • SI-7(1) Integrity Checks
  • SI-8(2) Spam Protection | Automatic Updates (SI-8(2))

FedRAMP Moderate · 12 controls

  • RA-5 Vulnerability Monitoring and Scanning
  • RA-5(11) Vulnerability Monitoring and Scanning | Public Disclosure Program (RA-5(11))
  • RA-5(2) Update Vulnerabilities to be Scanned
  • RA-5(3) Vulnerability Monitoring and Scanning | Breadth and Depth of Coverage (RA-5(3))
  • RA-5(5) Privileged Access
  • SA-22 Unsupported System Components (SA-22)
  • SC-7(12) Boundary Protection | Host-based Protection (SC-7(12))
  • SI-2 Flaw Remediation
  • SI-2(2) Automated Flaw Remediation Status
  • SI-2(3) Flaw Remediation | Time to Remediate Flaws and Benchmarks for Corrective Actions (SI-2(3))
  • SI-7(1) Integrity Checks
  • SI-8(2) Spam Protection | Automatic Updates (SI-8(2))

NIST SP 800-53 Rev 5 · 9 controls

NIST SP 800-218 · 8 controls

  • SEC01-BP04 Stay up to date with security threats and recommendations
  • SEC06-BP01 Perform vulnerability management
  • SEC06-BP05 Automate compute protection
  • SEC11-BP02 Automate testing throughout the development and release lifecycle
  • SEC11-BP03 Perform regular penetration testing
  • SEC11-BP05 Centralize services for packages and dependencies

CMMC 2.0 · 5 controls

HIPAA Security Rule · 5 controls

NIST SP 800-66 Rev 2 · 5 controls

SOC 2 · 5 controls

  • SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11)
  • SOC2-CC6.8 CC6.8 Preventing and detecting unauthorised or malicious software
  • SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities
  • SOC2-CC8.1 CC8.1 Managing changes to procedures, software, data and infrastructure
  • SOC2-CC9.1 CC9.1 Mitigating risks of business disruption
  • ASBv3-PV-6 Rapidly and automatically remediate vulnerabilities
  • ASBv3-PV-7 Conduct regular red team operations
  • DS-2 Ensure software supply chain security
  • PV-5 Perform vulnerability assessments

C5 (Germany) · 4 controls

  • C5-OPS-18 Managing Vulnerabilities, Malfunctions and Errors - Concept
  • C5-OPS-19 Managing Vulnerabilities, Malfunctions and Errors - Penetration Tests
  • C5-OPS-22 Testing and Documentation of known Vulnerabilities
  • C5-PSS-03 Online Register of Known Vulnerabilities

ETSI EN 303 645 · 4 controls

  • NIST-CSF-ID.RA-01 Vulnerabilities in assets are identified, validated, and recorded
  • NIST-CSF-ID.RA-04 Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded
  • NIST-CSF-ID.RA-05 Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization
  • NIST-CSF-PR.PS-02 Software is maintained, replaced, and removed commensurate with risk

UK Cyber Essentials · 4 controls

  • CE-SU.1 Software Licensed and Supported
  • CE-SU.2 Automatic Updates Enabled Where Possible
  • CE-SU.3 Critical and High Updates within 14 Days
  • CE-SU.4 Remove Out-of-Support Software
  • ANSSI-HYG-34 Define an Update Policy for Information System Components
  • ANSSI-HYG-35 Anticipate the End of Maintenance of Software and Systems
  • ANSSI-HYG-38 Carry Out Regular Security Checks and Audits and Apply the Corrective Actions

DORA · 3 controls

MTCS (Singapore) · 3 controls

  • 15.2 Vulnerability scanning
  • 15.3 Penetration testing
  • 20.6 Patch management procedures

NIS2 Directive · 3 controls

  • Art.21.2.e Security in acquisition, development and maintenance, including vulnerability handling and disclosure
  • Art.21.2.g Basic cyber hygiene practices and cybersecurity training
  • Art.21.4 Take corrective measures without undue delay on finding that the measures are not met

NIST SP 800-161 Rev 1 · 3 controls

NIST SP 800-171 Rev 3 · 3 controls

  • 03.11.02 Vulnerability Monitoring and Scanning
  • 03.14.01 Flaw Remediation
  • 03.14.03 Security Alerts, Advisories, and Directives

APRA CPS 234 · 2 controls

  • CPS234-22 Systematic Control Testing Program
  • CPS234-P17 Active Maintenance of Capability Against Change
  • ASD37-02 Patch applications (Essential)
  • ASD37-19 Patch operating systems (Essential)

IEC 62443 · 2 controls

  • 62443-2-1-PM Patch Management and System Update for IACS
  • 62443-4-2-EDR-3-10 Embedded Device Support for Updates

NY DFS 23 NYCRR 500 · 2 controls

  • 12.4.5.C.01 12.4.5.C.01 Compensating controls where patches are unavailable
  • 6.2.4.C.01 6.2.4.C.01 Vulnerability analysis strategy for systems
  • CPS230-P25 Information and Technology Capability and Asset Health
  • AUCDR-IS-4 Formal vulnerability management program

ISO 27001:2022 · 1 control

  • 8.8 Management of technical vulnerabilities

ISO 27701:2019 · 1 control

  • 6.9.6 Technical vulnerability management

NIST SP 800-172 · 1 control

  • 3.12.1e Penetration Testing by Independent Agents
  • NRC7354-6 Vulnerability Management, Configuration Management, Baseline Control, and Patching
  • P1-4.2.4 P1-4.2.4 Vulnerabilities ranked by criticality

PTES · 1 control

  • PTES-3.3 Scope vulnerability analysis to the agreed depth and breadth
  • TSA-SD-08 Patch and vulnerability management
  • MTSA-Patch-Management Patch and Vulnerability Management

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Technological controls – ISO 27002:2022

You are reading one control. How much of ISO 27002:2022 have you already done?

ISO 27002:2022 8.8 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 226 it maps to, and the evidence behind each claim, over MCP and REST.