NIST SP 800-123
Operations

NIST SP 800-123 NISTSP123-5: Server Operations - Patching, Malware, Logging, Backup

Apply Section 6.1-6.2 server operations including: vulnerability and patch management per NIST SP 800-40 (Critical 7 days + High 30 days + Medium 90 days + scheduled monthly + automatic patching where appropriate) + malware prevention (signature-based antivirus + EDR + XDR + EDR-NG + sandboxing + application whitelisting) + comprehensive logging per NIST SP 800-92 (security events + system events + application events + administrator actions + with appropriate retention 1+ year for SECRET + 7+ year for compliance) + log aggregation to SIEM + 24x7 monitoring + backup per NIST SP 800-34 (3-2-1 rule + immutable backups + regular testing + RTO/RPO targets).

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 132 controls across 48 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • ASD37-06 Email content filtering (Excellent)
  • ASD37-12 Antivirus software with heuristics (Very Good)
  • ASD37-16 Antivirus software with signatures (Limited)
  • ASD37-34 Regular backups (Essential)
  • ASD37-35 Business continuity and disaster recovery plans (Very Good)
  • ASD37-36 System recovery capabilities (Very Good)

API 1164 · 4 controls

  • API1164-12 Incident Response
  • API1164-17 Wireless and Field Communications
  • API1164-18 Field Device Security
  • API1164-19 Safety Instrumented Systems Interface

BSI IT-Grundschutz · 4 controls

  • BSI-14 Vulnerability scanning and management
  • BSI-28 Audit event logging and storage
  • BSI-29 Audit record review and analysis
  • BSI-31 Audit log protection and retention

IEC 62443 · 4 controls

  • IEC62443-12 Malware prevention for operational systems
  • IEC62443-16 Incident response plan for operational disruptions
  • IEC62443-17 Recovery plan for critical systems
  • IEC62443-20 Exercises and drills for OT incidents

ISO/IEC 27019:2024 · 4 controls

  • ISO27019-12 Malware prevention for operational systems
  • ISO27019-16 Incident response plan for operational disruptions
  • ISO27019-18 Reporting obligations to authorities
  • ISO27019-20 Exercises and drills for OT incidents

ISO/IEC 27043:2015 · 4 controls

  • ISO27043-22 Protection from malware
  • ISO27043-23 Backup and recovery procedures
  • ISO27043-24 Logging and monitoring
  • ISO27043-25 Technical vulnerability management

ISO/SAE 21434 · 4 controls

  • ISO21434-22 Protection from malware
  • ISO21434-23 Backup and recovery procedures
  • ISO21434-24 Logging and monitoring
  • ISO21434-25 Technical vulnerability management

South Korea ISMS-P · 4 controls

  • ISMSP-PI-06 Personal Information Destruction
  • ISMSP-SYS-03 Security Monitoring and Log Management
  • ISMSP-SYS-04 Vulnerability Management
  • ISMSP-SYS-06 Business Continuity and Disaster Recovery

ISO/IEC 27011:2024 · 3 controls

  • 27011-8.4 Logging and monitoring
  • 27011-8.5 Vulnerability and malware management
  • 27011-8.6 Data protection and backup

ISO/IEC 27031:2011 · 3 controls

  • 27031-8.1 Exercising and Testing
  • 27031-8.2 Maintaining IRBC
  • 27031-9.3 Management Review

ISO/IEC 30111:2019 · 3 controls

  • 30111-1 Scope
  • 30111-3 Terms and definitions
  • 30111-8.1 Post-release monitoring
  • NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process
  • NIST-CSF-RC.RP-06 The end of incident recovery is declared based on criteria, and incident-related documentation is completed
  • NIST-CSF-RS.MA-05 The criteria for initiating incident recovery are applied

OWASP ASVS · 3 controls

OWASP MASVS · 3 controls

  • OWASPMASVS-6 MASVS-CODE: Code Quality, Build Settings, and Updates
  • OWASPMASVS-7 MASVS-RESILIENCE: Resilience Against Reverse Engineering
  • OWASPMASVS-8 MASVS-PRIVACY: Privacy and Data Protection
  • IM8-RES.2 Disaster Recovery
  • IM8-RES.4 Resilience Testing
  • IM8-SEC.4 Vulnerability Management
  • AWWA-4.1 Malware Protection
  • AWWA-4.4 Audit Logging and Monitoring
  • CAT-D3-2 Detective controls
  • CAT-D3-3 Corrective controls
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • FTC-Safeguards-ServiceProvider-Evaluation Service Provider Oversight + Program Evaluation + Personnel Training (16 CFR 314.4(d-g))

ISO 22316 · 2 controls

  • ISO22316-08 Recovery time and point objectives
  • ISO22316-12 Recovery strategy for critical activities

ISO/IEC 29147:2018 · 2 controls

  • 29147-5.6 Advisory Content and Quality
  • 29147-7.8 Remediation information

ISO/TS 22317:2021 · 2 controls

  • ISO22317-08 Recovery time and point objectives
  • ISO22317-12 Recovery strategy for critical activities

ISO/TS 22318:2021 · 2 controls

  • ISO22318-08 Recovery time and point objectives
  • ISO22318-12 Recovery strategy for critical activities
  • NFPA1600-5.3 Resource Needs Assessment
  • NFPA1600-6.4 Continuity and Recovery
  • NISTSP34-2 Business Impact Analysis (BIA): Critical Resources, Recovery Priorities
  • NISTSP34-4 Information System Contingency Plan (ISCP) Development
  • DSOMM-1 Culture, Organization, Education, and Governance
  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management
  • 4.4.8 Business Continuity and Recovery
  • CPG-5.A Vulnerability Disclosure Program
  • DIQ-1 Data Integration and Interoperability
  • CJIS-10 System and Information Integrity
  • FFIEC-12 Disaster recovery procedures

FedRAMP Rev 5 · 1 control

  • FEDRAMP-CP-9 System Backup
  • 62351-14 Cyber security event logging

ISO 22320:2018 · 1 control

  • ISO-22320-5.2 Incident management process

ISO 27799:2025 · 1 control

  • ISO27799-05 Audit trail for ePHI access
  • ISO-25012-4.11 Traceability

ISO/IEC 27010:2015 · 1 control

  • 27010-12.2 Protection from malware

ISO/IEC 29134:2023 · 1 control

  • 29134-9.2 Report findings and recommendations
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)
  • NZISM-5 Network Security, System Hardening, and Application Security

OWASP Top 10:2025 · 1 control

  • OWASPTOP10-9 A09:2025 Security Logging and Monitoring Failures
  • UNGPBHR-2 Pillar II: Corporate Responsibility to Respect Human Rights

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 132 it maps to, and the evidence behind each claim, over MCP and REST.