NIST SP 800-137
Vulnerability and Configuration

NIST SP 800-137 NISTSP137-5: Vulnerability + Patch + Configuration Status Monitoring

Monitor vulnerability per Section 4.1 continuously: scanning + assessment + risk prioritisation + remediation tracking aligned with NIST SP 800-40 + NIST SP 800-126 SCAP + authenticated vulnerability scanners. Monitor patch management status per Section 4.2 including Critical 7 days + High 30 days + Medium 90 days + emergency patching processes + automated patching pipelines. Monitor configuration status per Section 4.3 including baseline compliance per CIS Benchmarks + DISA STIGs + custom baselines + drift detection + configuration management database (CMDB) currency.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 108 controls across 45 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO/IEC 27043:2015 · 5 controls

  • ISO27043-17 Encryption of data at rest
  • ISO27043-18 Encryption of data in transit
  • ISO27043-19 Certificate management
  • ISO27043-20 Key lifecycle management
  • ISO27043-25 Technical vulnerability management

ISO/SAE 21434 · 5 controls

  • ISO21434-16 Cryptographic policy and key management
  • ISO21434-17 Encryption of data at rest
  • ISO21434-18 Encryption of data in transit
  • ISO21434-19 Certificate management
  • ISO21434-25 Technical vulnerability management

FedRAMP Rev 5 · 3 controls

  • FEDRAMP-SC-13 Cryptographic Protection
  • FEDRAMP-SC-28 Protection of Information at Rest
  • FEDRAMP-SC-8 Transmission Confidentiality and Integrity

ISO/IEC 23837:2023 · 3 controls

  • 23837-1.2 Normative references
  • 23837-1.5.2 Cryptographic module requirements
  • 23837-1.5.3 Network device testing requirements

ISO/IEC 30111:2019 · 3 controls

  • 30111-1 Scope
  • 30111-3 Terms and definitions
  • 30111-8.1 Post-release monitoring

OWASP ASVS · 3 controls

OWASP MASVS · 3 controls

  • AWWA-3.2 Remote Access Security
  • AWWA-3.4 Encryption and Data Protection

BSI IT-Grundschutz · 2 controls

  • BSI-08 Cryptographic protection of data
  • BSI-14 Vulnerability scanning and management
  • CJIS-8 Media Protection
  • CJIS-9 System and Communications Protection
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • FTC-Safeguards-ServiceProvider-Evaluation Service Provider Oversight + Program Evaluation + Personnel Training (16 CFR 314.4(d-g))

ISO 27799:2025 · 2 controls

  • ISO27799-02 ePHI encryption at rest and in transit
  • ISO27799-16 Transmission security and encryption

ISO/IEC 27011:2024 · 2 controls

  • 27011-8.3 Cryptography and key management
  • 27011-8.5 Vulnerability and malware management

ISO/IEC 29147:2018 · 2 controls

  • 29147-5.6 Advisory Content and Quality
  • 29147-7.8 Remediation information
  • NZISM-3 Personnel Security, Physical Security, and Cryptography
  • NZISM-5 Network Security, System Hardening, and Application Security

OWASP Top 10:2025 · 2 controls

  • OWASPTOP10-2 A02:2025 Cryptographic Failures and Secret Management
  • OWASPTOP10-4 A04:2025 Insecure Design and Business Logic (incl. A11 API Abuse)
  • IM8-CLD.2 Cloud Security Controls
  • IM8-SEC.4 Vulnerability Management

South Korea ISMS-P · 2 controls

  • ISMSP-SYS-02 Encryption Implementation
  • ISMSP-SYS-04 Vulnerability Management

APPI · 1 control

  • APPI-A34 Request for Correction, Addition or Deletion
  • ASD37-17 TLS encryption between email servers (Limited)

Bahrain PDPL · 1 control

  • CAT-D3-3 Corrective controls
  • FFIEC-09 Encryption and key management

FIDO2 / WebAuthn · 1 control

  • UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5)
  • 62351-9 Cyber security key management

ISO/IEC 27010:2015 · 1 control

  • 27010-10.1 Cryptographic Protection

ISO/IEC 27400:2022 · 1 control

  • 27400-6.2 Device Identity and Authentication
  • 29115-7.4 Level of Assurance 4 (LoA4)

ISO/IEC 29134:2023 · 1 control

  • 29134-9.2 Report findings and recommendations
  • STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)
  • NISTSP34-3 Preventive Controls and Recovery Strategies: Backup, Alternate Sites, Equipment
  • NJDPA-7 Data Protection Assessments and Processor Contracts
  • NGOB-3 API Security Standards, mTLS, and Encryption
  • OWASPAPI-6 Security Misconfiguration and Secure API Design
  • DSOMM-1 Culture, Organization, Education, and Governance
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information

Turkey KVKK · 1 control

  • TURKEYKVKK-2 Information Notice and Data Subject Rights
  • UNGPBHR-2 Pillar II: Corporate Responsibility to Respect Human Rights

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 108 it maps to, and the evidence behind each claim, over MCP and REST.