NIST SP 800-128 SecCM-MONITOR-3: Vulnerability Identification and Remediation
Identify vulnerabilities arising from configuration weaknesses, missing patches, or end-of-life software through scanning and threat intelligence, and remediate within risk-based timeframes documented in policy.
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated