Frameworks / NIST SP 800-123 / NISTSP123-5 NIST SP 800-123
Operations
NIST SP 800-123 NISTSP123-5: Server Operations - Patching, Malware, Logging, Backup Apply Section 6.1-6.2 server operations including: vulnerability and patch management per NIST SP 800-40 (Critical 7 days + High 30 days + Medium 90 days + scheduled monthly + automatic patching where appropriate) + malware prevention (signature-based antivirus + EDR + XDR + EDR-NG + sandboxing + application whitelisting) + comprehensive logging per NIST SP 800-92 (security events + system events + application events + administrator actions + with appropriate retention 1+ year for SECRET + 7+ year for compliance) + log aggregation to SIEM + 24x7 monitoring + backup per NIST SP 800-34 (3-2-1 rule + immutable backups + regular testing + RTO/RPO targets).
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 132 controls across 48 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
ASD37-06 Email content filtering (Excellent) ASD37-12 Antivirus software with heuristics (Very Good) ASD37-16 Antivirus software with signatures (Limited) ASD37-34 Regular backups (Essential) ASD37-35 Business continuity and disaster recovery plans (Very Good) ASD37-36 System recovery capabilities (Very Good) API1164-12 Incident Response API1164-17 Wireless and Field Communications API1164-18 Field Device Security API1164-19 Safety Instrumented Systems Interface BSI-14 Vulnerability scanning and management BSI-28 Audit event logging and storage BSI-29 Audit record review and analysis BSI-31 Audit log protection and retention IEC62443-12 Malware prevention for operational systems IEC62443-16 Incident response plan for operational disruptions IEC62443-17 Recovery plan for critical systems IEC62443-20 Exercises and drills for OT incidents ISO27019-12 Malware prevention for operational systems ISO27019-16 Incident response plan for operational disruptions ISO27019-18 Reporting obligations to authorities ISO27019-20 Exercises and drills for OT incidents ISO27043-22 Protection from malware ISO27043-23 Backup and recovery procedures ISO27043-24 Logging and monitoring ISO27043-25 Technical vulnerability management ISO21434-22 Protection from malware ISO21434-23 Backup and recovery procedures ISO21434-24 Logging and monitoring ISO21434-25 Technical vulnerability management ISMSP-PI-06 Personal Information Destruction ISMSP-SYS-03 Security Monitoring and Log Management ISMSP-SYS-04 Vulnerability Management ISMSP-SYS-06 Business Continuity and Disaster Recovery 27011-8.4 Logging and monitoring 27011-8.5 Vulnerability and malware management 27011-8.6 Data protection and backup 27031-8.1 Exercising and Testing 27031-8.2 Maintaining IRBC 27031-9.3 Management Review 30111-1 Scope 30111-3 Terms and definitions 30111-8.1 Post-release monitoring NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process NIST-CSF-RC.RP-06 The end of incident recovery is declared based on criteria, and incident-related documentation is completed NIST-CSF-RS.MA-05 The criteria for initiating incident recovery are applied OWASPMASVS-6 MASVS-CODE: Code Quality, Build Settings, and Updates OWASPMASVS-7 MASVS-RESILIENCE: Resilience Against Reverse Engineering OWASPMASVS-8 MASVS-PRIVACY: Privacy and Data Protection IM8-RES.2 Disaster Recovery IM8-RES.4 Resilience Testing IM8-SEC.4 Vulnerability Management AWWA-4.1 Malware Protection AWWA-4.4 Audit Logging and Monitoring CAT-D3-2 Detective controls CAT-D3-3 Corrective controls FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) FTC-Safeguards-ServiceProvider-Evaluation Service Provider Oversight + Program Evaluation + Personnel Training (16 CFR 314.4(d-g)) ISO22316-08 Recovery time and point objectives ISO22316-12 Recovery strategy for critical activities 29147-5.6 Advisory Content and Quality 29147-7.8 Remediation information ISO22317-08 Recovery time and point objectives ISO22317-12 Recovery strategy for critical activities ISO22318-08 Recovery time and point objectives ISO22318-12 Recovery strategy for critical activities NFPA1600-5.3 Resource Needs Assessment NFPA1600-6.4 Continuity and Recovery NISTSP34-2 Business Impact Analysis (BIA): Critical Resources, Recovery Priorities NISTSP34-4 Information System Contingency Plan (ISCP) Development DSOMM-1 Culture, Organization, Education, and Governance DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management 4.4.8 Business Continuity and Recovery CPG-5.A Vulnerability Disclosure Program DIQ-1 Data Integration and Interoperability CJIS-10 System and Information Integrity FFIEC-12 Disaster recovery procedures FEDRAMP-CP-9 System Backup 62351-14 Cyber security event logging ISO-22320-5.2 Incident management process ISO27799-05 Audit trail for ePHI access ISO-25012-4.11 Traceability 27010-12.2 Protection from malware 29134-9.2 Report findings and recommendations NISTPF-8 Protect-P Information Protection Processes (PR.PO-P) NZISM-5 Network Security, System Hardening, and Application Security OWASPTOP10-9 A09:2025 Security Logging and Monitoring Failures UNGPBHR-2 Pillar II: Corporate Responsibility to Respect Human Rights CYB-5 Cyber Incident Response Plan Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Query this from an agent The graph holds this control, the 132 it maps to, and the evidence behind each claim, over MCP and REST.