ISO 27701:2019
PIMS-specific guidance related to ISO/IEC 27002, ISO 27701:2019

ISO 27701:2019 6.9.6: Technical vulnerability management

Technical vulnerability management and restriction on software installation apply as the base guidance requires, read as protecting the personal data that an unpatched vulnerability would expose.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 83 controls across 23 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

CIS Controls v8 · 17 controls

  • CIS-10.5 Enable Anti-Exploitation Features
  • CIS-12.1 Ensure Network Infrastructure is Up-to-Date
  • CIS-13.5 Manage Access Control for Remote Assets
  • CIS-14.7 Train Workforce on How to Identify and Report if Their Enterprise Assets are Missing Security Updates
  • CIS-16.2 Establish and Maintain a Process to Accept and Address Software Vulnerabilities
  • CIS-16.6 Establish and Maintain a Severity Rating System and Process for Application Vulnerabilities
  • CIS-16.7 Use Standard Hardening Configuration Templates for Application Infrastructure
  • CIS-18.2 Perform Periodic External Penetration Tests
  • CIS-18.4 Validate Security Measures
  • CIS-2.5 Allowlist Authorized Software
  • CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • CIS-7.1 Establish and Maintain a Vulnerability Management Process
  • CIS-7.3 Perform Automated Operating System Patch Management
  • CIS-7.4 Perform Automated Application Patch Management
  • CIS-7.5 Perform Automated Vulnerability Scans of Internal Enterprise Assets
  • CIS-7.6 Perform Automated Vulnerability Scans of Externally-Exposed Enterprise Assets
  • CIS-7.7 Remediate Detected Vulnerabilities

PCI DSS 4.0 · 17 controls

  • 1.2.6 1.2.6 Security features for insecure services in use
  • 11.3.1 11.3.1 Quarterly internal vulnerability scans
  • 11.3.1.1 11.3.1.1 Lower-risk vulnerabilities handled per risk analysis
  • 11.3.1.2 11.3.1.2 Authenticated internal vulnerability scanning
  • 11.3.1.3 11.3.1.3 Internal scans after significant change
  • 11.3.2 11.3.2 Quarterly ASV external vulnerability scans
  • 11.3.2.1 11.3.2.1 External scans after significant change
  • 11.4.2 11.4.2 Internal penetration testing annually and after change
  • 11.4.4 11.4.4 Correct exploitable findings from penetration tests
  • 12.3.4 12.3.4 Annual review of hardware and software technologies
  • 12.6.1 12.6.1 Formal security awareness program
  • 2.2.1 2.2.1 System configuration standards maintained
  • 2.2.6 2.2.6 System security parameters configured against misuse
  • 6.4.1 6.4.1 Public web application review or automated protection
  • 6.3.1 6.3.1 Vulnerability identification and risk ranking
  • 6.3.2 6.3.2 Inventory of bespoke software and components
  • 6.3.3 6.3.3 Timely installation of security patches

CMMC 2.0 · 5 controls

NIST SP 800-53 Rev 5 · 5 controls

  • NIST-CSF-ID.AM-08 Systems, hardware, software, services, and data are managed throughout their life cycles
  • NIST-CSF-ID.RA-01 Vulnerabilities in assets are identified, validated, and recorded
  • NIST-CSF-PR.PS-01 Configuration management practices are established and applied
  • NIST-CSF-PR.PS-02 Software is maintained, replaced, and removed commensurate with risk

SOC 2 · 4 controls

  • SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11)
  • SOC2-CC6.1 CC6.1 Logical access security over protected information assets
  • SOC2-CC6.8 CC6.8 Preventing and detecting unauthorised or malicious software
  • SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities
  • ASBv3-AM-5 Use only approved applications in virtual machine
  • ASBv3-PV-6 Rapidly and automatically remediate vulnerabilities
  • PV-5 Perform vulnerability assessments

FedRAMP High · 3 controls

  • CM-11 User-Installed Software
  • RA-5 Vulnerability Monitoring and Scanning
  • SI-2 Flaw Remediation

FedRAMP Moderate · 3 controls

  • CM-11 User-Installed Software
  • RA-5 Vulnerability Monitoring and Scanning
  • SI-2 Flaw Remediation

C5 (Germany) · 2 controls

  • C5-AM-02 Acceptable Use and Safe Handling of Assets Policy
  • C5-OPS-22 Testing and Documentation of known Vulnerabilities

HIPAA Security Rule · 2 controls

NIST SP 800-161 Rev 1 · 2 controls

NIST SP 800-171 Rev 3 · 2 controls

NIST SP 800-66 Rev 2 · 2 controls

  • AUCDR-IS-4 Formal vulnerability management program

ISO 27001:2022 · 1 control

  • 8.8 Management of technical vulnerabilities

ISO 27002:2022 · 1 control

  • 8.8 Management of technical vulnerabilities

ISO 27017:2015 · 1 control

  • 12.6 Technical vulnerability management

ISO 27018:2019 · 1 control

  • 12.6 Technical vulnerability management

ISO/IEC 27043:2015 · 1 control

  • ISO27043-25 Technical vulnerability management

ISO/SAE 21434 · 1 control

  • ISO21434-25 Technical vulnerability management

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in PIMS-specific guidance related to ISO/IEC 27002, ISO 27701:2019

You are reading one control. How much of ISO 27701:2019 have you already done?

ISO 27701:2019 6.9.6 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27701:2019 your existing evidence covers. Hold SOC 2 and 58 of 108 ISO 27701:2019 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 289 were rejected on the SOC 2 pair alone.

Query this from an agent

The graph holds this control, the 83 it maps to, and the evidence behind each claim, over MCP and REST.