NIST SP 800-30
Vulnerability and Predisposing Condition Identification

NIST SP 800-30 NISTSP30-4: Vulnerability and Predisposing Condition Identification

Identify vulnerabilities and predisposing conditions per NIST SP 800-30 Rev 1 Section 3.2 Step 3 + Appendix F (Vulnerabilities and Predisposing Conditions). Vulnerabilities include weaknesses in information systems, security procedures, internal controls, or implementation that could be exploited by a threat source. Predisposing conditions are organisational characteristics (mission, location, dependencies, technology choices, partnerships) that increase or decrease the likelihood that vulnerabilities will be exploited or that adverse impacts will result. Sources include (a) vulnerability scanning (continuous scan results, infrastructure-as-code policy scans, container image scans), (b) penetration testing reports, (c) red-team and tabletop exercise findings, (d) prior audit and assessment reports, (e) plan-of-action-and-milestones (POAM) register, (f) industry advisories (CVE, CWE, KEV catalogue). Document the vulnerability and predisposing condition catalogue per assessment with citation of source.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.