NIST Cybersecurity Framework 2.0
ID - Identify

NIST Cybersecurity Framework 2.0 NIST-CSF-ID.RA-01: Vulnerabilities in assets are identified, validated, and recorded

Vulnerabilities in assets are identified, validated, and recorded. Control from NIST Cybersecurity Framework 2.0 framework, domain: ID - Identify.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 135 controls across 51 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 11 controls

  • 11.3.1 11.3.1 Quarterly internal vulnerability scans
  • 11.3.1.1 11.3.1.1 Lower-risk vulnerabilities handled per risk analysis
  • 11.3.1.2 11.3.1.2 Authenticated internal vulnerability scanning
  • 11.3.1.3 11.3.1.3 Internal scans after significant change
  • 11.3.2 11.3.2 Quarterly ASV external vulnerability scans
  • 11.3.2.1 11.3.2.1 External scans after significant change
  • 12.6.1 12.6.1 Formal security awareness program
  • 5.3.2.1 5.3.2.1 Targeted risk analysis sets malware scan frequency
  • 6.4.1 6.4.1 Public web application review or automated protection
  • 6.3.1 6.3.1 Vulnerability identification and risk ranking
  • 6.3.3 6.3.3 Timely installation of security patches

CIS Controls v8 · 9 controls

  • CIS-16.2 Establish and Maintain a Process to Accept and Address Software Vulnerabilities
  • CIS-16.5 Use Up-to-Date and Trusted Third-Party Software Components
  • CIS-16.6 Establish and Maintain a Severity Rating System and Process for Application Vulnerabilities
  • CIS-18.1 Establish and Maintain a Penetration Testing Program
  • CIS-2.2 Ensure Authorized Software is Currently Supported
  • CIS-7.1 Establish and Maintain a Vulnerability Management Process
  • CIS-7.4 Perform Automated Application Patch Management
  • CIS-7.5 Perform Automated Vulnerability Scans of Internal Enterprise Assets
  • CIS-7.6 Perform Automated Vulnerability Scans of Externally-Exposed Enterprise Assets

NIST SP 800-218 · 7 controls

BIMCO Cyber Security · 6 controls

FedRAMP High · 6 controls

  • CA-5 Plan of Action and Milestones
  • RA-5 Vulnerability Monitoring and Scanning
  • RA-5(2) Update Vulnerabilities to be Scanned
  • RA-5(3) Vulnerability Monitoring and Scanning | Breadth and Depth of Coverage (RA-5(3))
  • SI-2 Flaw Remediation
  • SI-2(2) Automated Flaw Remediation Status

FedRAMP Moderate · 6 controls

  • CA-5 Plan of Action and Milestones
  • RA-5 Vulnerability Monitoring and Scanning
  • RA-5(2) Update Vulnerabilities to be Scanned
  • RA-5(3) Vulnerability Monitoring and Scanning | Breadth and Depth of Coverage (RA-5(3))
  • SI-2 Flaw Remediation
  • SI-2(2) Automated Flaw Remediation Status

C5 (Germany) · 4 controls

  • C5-OPS-18 Managing Vulnerabilities, Malfunctions and Errors - Concept
  • C5-OPS-22 Testing and Documentation of known Vulnerabilities
  • C5-PSS-02 Identification of Vulnerabilities of the Cloud Service
  • C5-PSS-03 Online Register of Known Vulnerabilities

NIST SP 800-53 Rev 5 · 4 controls

  • NIST800-RA-5 RA-5 Vulnerability Monitoring and Scanning
  • NIST800-SI-2 SI-2 Flaw Remediation
  • SP800-53-RA Risk Assessment Family
  • SP800-53-SI System and Information Integrity Family

SOC 2 · 4 controls

  • SOC2-CC3.2 CC3.2 Identifying and analysing risks to objectives (COSO principle 7)
  • SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11)
  • SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities
  • SOC2-CC9.1 CC9.1 Mitigating risks of business disruption
  • ISM-1163 Continuous monitoring plan
  • ISM-1701 Daily scanning of internet-facing OS
  • ISM-1808 Up-to-date vulnerability database for scanning
  • ASBv3-DS-4 Integrate static application security testing into DevOps pipeline
  • DS-2 Ensure software supply chain security
  • PV-5 Perform vulnerability assessments

CMMC 2.0 · 3 controls

  • CIRMP-s6 Identification of material risks
  • CIRMP-s7 General requirement - minimise, eliminate and mitigate all hazards
  • CIRMP-s8 Cyber and information security hazard management

DORA · 3 controls

  • DE.CM-8 DE.CM-8: Vulnerability scans are performed
  • ID.RA-1 ID.RA-1: Asset vulnerabilities are identified and documented
  • PR.IP-12 PR.IP-12: A vulnerability management plan is developed and implemented
  • DE.CM-8 DE.CM-8: Vulnerability scans are performed
  • ID.RA-1 ID.RA-1: Asset vulnerabilities are identified and documented
  • PR.IP-12 PR.IP-12: A vulnerability management plan is developed and implemented

ACSC Essential Eight · 2 controls

  • E8-PATCHAPP-ML1 Patch Applications (ML1)
  • E8-PATCHOS-ML1 Patch Operating Systems (ML1)
  • ANSSI-HYG-34 Define an Update Policy for Information System Components
  • ANSSI-HYG-38 Carry Out Regular Security Checks and Audits and Apply the Corrective Actions
  • ASD37-02 Patch applications (Essential)
  • ASD37-19 Patch operating systems (Essential)
  • SEC06-BP01 Perform vulnerability management
  • SEC11-BP02 Automate testing throughout the development and release lifecycle
  • AWWA-1.2 Risk Assessment
  • AWWA-4.2 Patch Management
  • AESCSF-RM-2 Identify and assess cyber risks
  • AESCSF-TVM-1 Vulnerability management
  • BE-CF-13 Risk assessment procedures
  • BE-CF-14 Vulnerability scanning and management
  • BMA-21 Security Testing Programme
  • BMA-6 Risk Assessment Process

C2M2 · 2 controls

  • RISK-2 Identify and Analyze Cyber Risk
  • THREAT-2 Reduce Cybersecurity Vulnerabilities
  • CSL-Art22 Security of Network Products and Services - Art. 22
  • CSL-Art38 CII Annual Security Inspection - Art. 38
  • DSL-Art22 National Data Security Risk Assessment, Monitoring and Early Warning (Art. 22)
  • DSL-Art30 Important Data Risk Assessment and Reporting (Art. 30)
  • EBA-GL-3.3.2 Identification of functions, processes and assets
  • EBA-GL-3.3.3 Classification and risk assessment

NIST SP 800-171 Rev 3 · 2 controls

NIST SP 800-172 · 2 controls

  • 3.12.1e Penetration Testing by Independent Agents
  • 3.14.7e Verify Correctness of Security Functions
  • AUCDR-IS-4 Formal vulnerability management program
  • ITSG33-RA Risk Assessment (RA)
  • PIPL-Art55 Personal Information Protection Impact Assessment
  • ENISA-DPE-2.2 Connection with the Data Protection Impact Assessment
  • FAA-CSA-Governance FAA Cybersecurity Strategy, Governance and Order 1370.123A

HIPAA Security Rule · 1 control

ISO 27001:2022 · 1 control

  • 8.8 Management of technical vulnerabilities

ISO 27002:2022 · 1 control

  • 8.8 Management of technical vulnerabilities

ISO 27701:2019 · 1 control

  • 6.9.6 Technical vulnerability management

NIS2 Directive · 1 control

  • Art.21.2.e Security in acquisition, development and maintenance, including vulnerability handling and disclosure
  • ID.RA-01 ID.RA-01 All types of known vulnerabilities understood for risk decisions

UK Cyber Essentials · 1 control

  • CE-SU.3 Critical and High Updates within 14 Days
  • 6(e) Sec. 6(e) (now 5(b)) Manage AI software vulnerabilities and compromises in vulnerability management

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in ID - Identify

You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done?

NIST Cybersecurity Framework 2.0 NIST-CSF-ID.RA-01 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 135 it maps to, and the evidence behind each claim, over MCP and REST.