Frameworks / NIST Cybersecurity Framework 2.0 / NIST-CSF-ID.RA-01 NIST Cybersecurity Framework 2.0
ID - Identify
NIST Cybersecurity Framework 2.0 NIST-CSF-ID.RA-01: Vulnerabilities in assets are identified, validated, and recorded Vulnerabilities in assets are identified, validated, and recorded. Control from NIST Cybersecurity Framework 2.0 framework, domain: ID - Identify.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 135 controls across 51 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
11.3.1 11.3.1 Quarterly internal vulnerability scans 11.3.1.1 11.3.1.1 Lower-risk vulnerabilities handled per risk analysis 11.3.1.2 11.3.1.2 Authenticated internal vulnerability scanning 11.3.1.3 11.3.1.3 Internal scans after significant change 11.3.2 11.3.2 Quarterly ASV external vulnerability scans 11.3.2.1 11.3.2.1 External scans after significant change 12.6.1 12.6.1 Formal security awareness program 5.3.2.1 5.3.2.1 Targeted risk analysis sets malware scan frequency 6.4.1 6.4.1 Public web application review or automated protection 6.3.1 6.3.1 Vulnerability identification and risk ranking 6.3.3 6.3.3 Timely installation of security patches CIS-16.2 Establish and Maintain a Process to Accept and Address Software Vulnerabilities CIS-16.5 Use Up-to-Date and Trusted Third-Party Software Components CIS-16.6 Establish and Maintain a Severity Rating System and Process for Application Vulnerabilities CIS-18.1 Establish and Maintain a Penetration Testing Program CIS-2.2 Ensure Authorized Software is Currently Supported CIS-7.1 Establish and Maintain a Vulnerability Management Process CIS-7.4 Perform Automated Application Patch Management CIS-7.5 Perform Automated Vulnerability Scans of Internal Enterprise Assets CIS-7.6 Perform Automated Vulnerability Scans of Externally-Exposed Enterprise Assets CA-5 Plan of Action and Milestones RA-5 Vulnerability Monitoring and Scanning RA-5(2) Update Vulnerabilities to be Scanned RA-5(3) Vulnerability Monitoring and Scanning | Breadth and Depth of Coverage (RA-5(3)) SI-2 Flaw Remediation SI-2(2) Automated Flaw Remediation Status CA-5 Plan of Action and Milestones RA-5 Vulnerability Monitoring and Scanning RA-5(2) Update Vulnerabilities to be Scanned RA-5(3) Vulnerability Monitoring and Scanning | Breadth and Depth of Coverage (RA-5(3)) SI-2 Flaw Remediation SI-2(2) Automated Flaw Remediation Status C5-OPS-18 Managing Vulnerabilities, Malfunctions and Errors - Concept C5-OPS-22 Testing and Documentation of known Vulnerabilities C5-PSS-02 Identification of Vulnerabilities of the Cloud Service C5-PSS-03 Online Register of Known Vulnerabilities NIST800-RA-5 RA-5 Vulnerability Monitoring and Scanning NIST800-SI-2 SI-2 Flaw Remediation SP800-53-RA Risk Assessment Family SP800-53-SI System and Information Integrity Family SOC2-CC3.2 CC3.2 Identifying and analysing risks to objectives (COSO principle 7) SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11) SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities SOC2-CC9.1 CC9.1 Mitigating risks of business disruption ISM-1163 Continuous monitoring plan ISM-1701 Daily scanning of internet-facing OS ISM-1808 Up-to-date vulnerability database for scanning ASBv3-DS-4 Integrate static application security testing into DevOps pipeline DS-2 Ensure software supply chain security PV-5 Perform vulnerability assessments CIRMP-s6 Identification of material risks CIRMP-s7 General requirement - minimise, eliminate and mitigate all hazards CIRMP-s8 Cyber and information security hazard management DE.CM-8 DE.CM-8: Vulnerability scans are performed ID.RA-1 ID.RA-1: Asset vulnerabilities are identified and documented PR.IP-12 PR.IP-12: A vulnerability management plan is developed and implemented DE.CM-8 DE.CM-8: Vulnerability scans are performed ID.RA-1 ID.RA-1: Asset vulnerabilities are identified and documented PR.IP-12 PR.IP-12: A vulnerability management plan is developed and implemented E8-PATCHAPP-ML1 Patch Applications (ML1) E8-PATCHOS-ML1 Patch Operating Systems (ML1) ANSSI-HYG-34 Define an Update Policy for Information System Components ANSSI-HYG-38 Carry Out Regular Security Checks and Audits and Apply the Corrective Actions ASD37-02 Patch applications (Essential) ASD37-19 Patch operating systems (Essential) SEC06-BP01 Perform vulnerability management SEC11-BP02 Automate testing throughout the development and release lifecycle AWWA-1.2 Risk Assessment AWWA-4.2 Patch Management AESCSF-RM-2 Identify and assess cyber risks AESCSF-TVM-1 Vulnerability management BE-CF-13 Risk assessment procedures BE-CF-14 Vulnerability scanning and management BMA-21 Security Testing Programme BMA-6 Risk Assessment Process RISK-2 Identify and Analyze Cyber Risk THREAT-2 Reduce Cybersecurity Vulnerabilities CSL-Art22 Security of Network Products and Services - Art. 22 CSL-Art38 CII Annual Security Inspection - Art. 38 DSL-Art22 National Data Security Risk Assessment, Monitoring and Early Warning (Art. 22) DSL-Art30 Important Data Risk Assessment and Reporting (Art. 30) EBA-GL-3.3.2 Identification of functions, processes and assets EBA-GL-3.3.3 Classification and risk assessment 3.12.1e Penetration Testing by Independent Agents 3.14.7e Verify Correctness of Security Functions AUCDR-IS-4 Formal vulnerability management program ITSG33-RA Risk Assessment (RA) PIPL-Art55 Personal Information Protection Impact Assessment ENISA-DPE-2.2 Connection with the Data Protection Impact Assessment FAA-CSA-Governance FAA Cybersecurity Strategy, Governance and Order 1370.123A 8.8 Management of technical vulnerabilities 8.8 Management of technical vulnerabilities 6.9.6 Technical vulnerability management Art.21.2.e Security in acquisition, development and maintenance, including vulnerability handling and disclosure ID.RA-01 ID.RA-01 All types of known vulnerabilities understood for risk decisions CE-SU.3 Critical and High Updates within 14 Days 6(e) Sec. 6(e) (now 5(b)) Manage AI software vulnerabilities and compromises in vulnerability management Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in ID - Identify You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done? NIST Cybersecurity Framework 2.0 NIST-CSF-ID.RA-01 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.
Query this from an agent The graph holds this control, the 135 it maps to, and the evidence behind each claim, over MCP and REST.