Frameworks / NIST SP 800-137 / NISTSP137-5 NIST SP 800-137
Vulnerability and Configuration
NIST SP 800-137 NISTSP137-5: Vulnerability + Patch + Configuration Status Monitoring Monitor vulnerability per Section 4.1 continuously: scanning + assessment + risk prioritisation + remediation tracking aligned with NIST SP 800-40 + NIST SP 800-126 SCAP + authenticated vulnerability scanners. Monitor patch management status per Section 4.2 including Critical 7 days + High 30 days + Medium 90 days + emergency patching processes + automated patching pipelines. Monitor configuration status per Section 4.3 including baseline compliance per CIS Benchmarks + DISA STIGs + custom baselines + drift detection + configuration management database (CMDB) currency.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 108 controls across 45 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
ISO27043-17 Encryption of data at rest ISO27043-18 Encryption of data in transit ISO27043-19 Certificate management ISO27043-20 Key lifecycle management ISO27043-25 Technical vulnerability management ISO21434-16 Cryptographic policy and key management ISO21434-17 Encryption of data at rest ISO21434-18 Encryption of data in transit ISO21434-19 Certificate management ISO21434-25 Technical vulnerability management FEDRAMP-SC-13 Cryptographic Protection FEDRAMP-SC-28 Protection of Information at Rest FEDRAMP-SC-8 Transmission Confidentiality and Integrity 23837-1.2 Normative references 23837-1.5.2 Cryptographic module requirements 23837-1.5.3 Network device testing requirements 30111-1 Scope 30111-3 Terms and definitions 30111-8.1 Post-release monitoring AWWA-3.2 Remote Access Security AWWA-3.4 Encryption and Data Protection BSI-08 Cryptographic protection of data BSI-14 Vulnerability scanning and management CJIS-8 Media Protection CJIS-9 System and Communications Protection FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) FTC-Safeguards-ServiceProvider-Evaluation Service Provider Oversight + Program Evaluation + Personnel Training (16 CFR 314.4(d-g)) ISO27799-02 ePHI encryption at rest and in transit ISO27799-16 Transmission security and encryption 27011-8.3 Cryptography and key management 27011-8.5 Vulnerability and malware management 29147-5.6 Advisory Content and Quality 29147-7.8 Remediation information NZISM-3 Personnel Security, Physical Security, and Cryptography NZISM-5 Network Security, System Hardening, and Application Security OWASPTOP10-2 A02:2025 Cryptographic Failures and Secret Management OWASPTOP10-4 A04:2025 Insecure Design and Business Logic (incl. A11 API Abuse) IM8-CLD.2 Cloud Security Controls IM8-SEC.4 Vulnerability Management ISMSP-SYS-02 Encryption Implementation ISMSP-SYS-04 Vulnerability Management APPI-A34 Request for Correction, Addition or Deletion ASD37-17 TLS encryption between email servers (Limited) CAT-D3-3 Corrective controls FFIEC-09 Encryption and key management UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5) 62351-9 Cyber security key management 27010-10.1 Cryptographic Protection 27400-6.2 Device Identity and Authentication 29115-7.4 Level of Assurance 4 (LoA4) 29134-9.2 Report findings and recommendations STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding NISTPF-8 Protect-P Information Protection Processes (PR.PO-P) NISTSP34-3 Preventive Controls and Recovery Strategies: Backup, Alternate Sites, Equipment NJDPA-7 Data Protection Assessments and Processor Contracts NGOB-3 API Security Standards, mTLS, and Encryption OWASPAPI-6 Security Misconfiguration and Secure API Design DSOMM-1 Culture, Organization, Education, and Governance AUPRV-4 APP 10-11 Quality, Security of Personal Information TURKEYKVKK-2 Information Notice and Data Subject Rights UNGPBHR-2 Pillar II: Corporate Responsibility to Respect Human Rights Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Query this from an agent The graph holds this control, the 108 it maps to, and the evidence behind each claim, over MCP and REST.