NIST SP 800-218 218-RV.1.1: Identify and Confirm Vulnerabilities on an Ongoing Basis
Continuously identify vulnerabilities in released software using internal testing, external reports, and intelligence from component upstreams. Confirm reproducibility and severity before treating findings.
What else in your programme already covers this
This control maps to 57 controls across 22 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
6.4.1 For public-facing web applications, new threats and vulnerabilities are addressed on an ongoing basis and these applications are protected against known attacks as follows: • Reviewing public-facing web applications via manual or automated application
6.3.1 Security vulnerabilities are identified and managed as follows: • New security vulnerabilities are identified using industry-recognized sources for security vulnerability information, including alerts from international and national computer emergency response teams (CERTs). • Vulnerabilities
You are reading one control. How much of NIST SP 800-218 have you already done?
NIST SP 800-218 218-RV.1.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST SP 800-218 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 30 of 42 NIST SP 800-218 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the NIST SP 800-53 Rev 5 pair alone.