Frameworks / ISO 27701:2019 / 6.9.6 ISO 27701:2019
PIMS-specific guidance related to ISO/IEC 27002, ISO 27701:2019
ISO 27701:2019 6.9.6: Technical vulnerability management Technical vulnerability management and restriction on software installation apply as the base guidance requires, read as protecting the personal data that an unpatched vulnerability would expose.
Maintained by Gerard Blokdyk What else in your programme already covers this This control maps to 83 controls across 23 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
CIS-10.5 Enable Anti-Exploitation Features CIS-12.1 Ensure Network Infrastructure is Up-to-Date CIS-13.5 Manage Access Control for Remote Assets CIS-14.7 Train Workforce on How to Identify and Report if Their Enterprise Assets are Missing Security Updates CIS-16.2 Establish and Maintain a Process to Accept and Address Software Vulnerabilities CIS-16.6 Establish and Maintain a Severity Rating System and Process for Application Vulnerabilities CIS-16.7 Use Standard Hardening Configuration Templates for Application Infrastructure CIS-18.2 Perform Periodic External Penetration Tests CIS-18.4 Validate Security Measures CIS-2.5 Allowlist Authorized Software CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software CIS-7.1 Establish and Maintain a Vulnerability Management Process CIS-7.3 Perform Automated Operating System Patch Management CIS-7.4 Perform Automated Application Patch Management CIS-7.5 Perform Automated Vulnerability Scans of Internal Enterprise Assets CIS-7.6 Perform Automated Vulnerability Scans of Externally-Exposed Enterprise Assets CIS-7.7 Remediate Detected Vulnerabilities 1.2.6 1.2.6 Security features for insecure services in use 11.3.1 11.3.1 Quarterly internal vulnerability scans 11.3.1.1 11.3.1.1 Lower-risk vulnerabilities handled per risk analysis 11.3.1.2 11.3.1.2 Authenticated internal vulnerability scanning 11.3.1.3 11.3.1.3 Internal scans after significant change 11.3.2 11.3.2 Quarterly ASV external vulnerability scans 11.3.2.1 11.3.2.1 External scans after significant change 11.4.2 11.4.2 Internal penetration testing annually and after change 11.4.4 11.4.4 Correct exploitable findings from penetration tests 12.3.4 12.3.4 Annual review of hardware and software technologies 12.6.1 12.6.1 Formal security awareness program 2.2.1 2.2.1 System configuration standards maintained 2.2.6 2.2.6 System security parameters configured against misuse 6.4.1 6.4.1 Public web application review or automated protection 6.3.1 6.3.1 Vulnerability identification and risk ranking 6.3.2 6.3.2 Inventory of bespoke software and components 6.3.3 6.3.3 Timely installation of security patches NIST-CSF-ID.AM-08 Systems, hardware, software, services, and data are managed throughout their life cycles NIST-CSF-ID.RA-01 Vulnerabilities in assets are identified, validated, and recorded NIST-CSF-PR.PS-01 Configuration management practices are established and applied NIST-CSF-PR.PS-02 Software is maintained, replaced, and removed commensurate with risk SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11) SOC2-CC6.1 CC6.1 Logical access security over protected information assets SOC2-CC6.8 CC6.8 Preventing and detecting unauthorised or malicious software SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities ASBv3-AM-5 Use only approved applications in virtual machine ASBv3-PV-6 Rapidly and automatically remediate vulnerabilities PV-5 Perform vulnerability assessments CM-11 User-Installed Software RA-5 Vulnerability Monitoring and Scanning SI-2 Flaw Remediation CM-11 User-Installed Software RA-5 Vulnerability Monitoring and Scanning SI-2 Flaw Remediation C5-AM-02 Acceptable Use and Safe Handling of Assets Policy C5-OPS-22 Testing and Documentation of known Vulnerabilities AUCDR-IS-4 Formal vulnerability management program 8.8 Management of technical vulnerabilities 8.8 Management of technical vulnerabilities 12.6 Technical vulnerability management 12.6 Technical vulnerability management ISO27043-25 Technical vulnerability management ISO21434-25 Technical vulnerability management Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in PIMS-specific guidance related to ISO/IEC 27002, ISO 27701:2019 You are reading one control. How much of ISO 27701:2019 have you already done? ISO 27701:2019 6.9.6 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27701:2019 your existing evidence covers. Hold SOC 2 and 58 of 108 ISO 27701:2019 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 289 were rejected on the SOC 2 pair alone.
Query this from an agent The graph holds this control, the 83 it maps to, and the evidence behind each claim, over MCP and REST.