NIST Cybersecurity Framework 2.0
ID - Identify

NIST Cybersecurity Framework 2.0 NIST-CSF-ID.RA-08: Processes for receiving, analyzing, and responding to vulnerability disclosures are established

Processes for receiving, analyzing, and responding to vulnerability disclosures are established

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 59 controls across 33 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 6 controls

ISO 22301:2019 · 4 controls

  • 8.5 Exercise programme
  • 9.1 Monitoring, measurement, analysis and evaluation
  • 9.2 Internal audit
  • 9.3 Management review

ISO 27701:2019 · 4 controls

  • 5.6.3 Information security risk treatment
  • 5.7.1 Monitoring, measurement, analysis and evaluation
  • 5.7.3 Management review
  • 6.15.2 Information security reviews
  • ISM-1526 Continuous security monitoring by system owners
  • ISM-1587 Annual reporting of system security status
  • ISM-1636 Security assessment by organisational or IRAP assessors

FedRAMP High · 3 controls

  • CA-2 Control Assessments
  • CA-7 Continuous Monitoring
  • CA-7(4) Continuous Monitoring | Risk Monitoring (CA-7(4))

FedRAMP Moderate · 3 controls

  • CA-2 Control Assessments
  • CA-7 Continuous Monitoring
  • CA-7(4) Continuous Monitoring | Risk Monitoring (CA-7(4))
  • CPS220-11 Annual Audit Review of the Framework
  • CPS220-P47 Minimum Assessment Required by the Framework Review
  • CFTC-SS-15 Controls Testing
  • CFTC-SS-33 Regular Periodic Objective Testing and Review of Automated Systems

ISO 27001:2022 · 2 controls

  • 5.35 Independent review of information security
  • 5.36 Compliance with policies, rules and standards for information security

ISO 27002:2022 · 2 controls

  • 5.35 Independent review of information security
  • 5.36 Compliance with policies, rules and standards for information security

NIST SP 800-172 · 2 controls

  • 3.11.5e Assess Effectiveness of Security Solutions
  • 3.14.7e Verify Correctness of Security Functions

PCI DSS 4.0 · 2 controls

  • 10.7.2 10.7.2 Detect and alert on critical security control failures
  • 11.3.1.3 11.3.1.3 Internal scans after significant change

SOC 2 · 2 controls

  • SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16)
  • SOC2-CC4.2 CC4.2 Evaluating and communicating control deficiencies (COSO principle 17)
  • CPS230-P30 Monitoring, Review and Testing of Control Effectiveness

APRA CPS 234 · 1 control

  • CPS234-22 Systematic Control Testing Program
  • ADMF-6.4 Test data protection control effectiveness
  • AUCDR-IS-STEP4 Step 4 - Implement a formal controls assessment program
  • PV-2 Audit and enforce secure configurations

C5 (Germany) · 1 control

  • C5-OPS-20 Managing Vulnerabilities, Malfunctions and Errors - Measurements, Analyses and Assessments of Procedures

CIS Controls v8 · 1 control

CMMC 2.0 · 1 control

GDPR · 1 control

HIPAA Security Rule · 1 control

ISO/IEC 42001:2023 · 1 control

NIS2 Directive · 1 control

  • Art.21.2.f Policies and procedures to assess the effectiveness of the cybersecurity risk-management measures
  • RS.AN-5 RS.AN-5: Processes are established to receive, analyze and respond to vulnerabilities disclosed to the organization from internal and external sources (e.g. internal testing, security bulletins, or security researchers)
  • ID.RA-08 ID.RA-08 Processes for receiving and acting on vulnerability disclosures

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in ID - Identify

You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done?

NIST Cybersecurity Framework 2.0 NIST-CSF-ID.RA-08 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 59 it maps to, and the evidence behind each claim, over MCP and REST.