Vulnerability and Predisposing Condition Identification
NIST SP 800-30 NISTSP30-4: Vulnerability and Predisposing Condition Identification
Identify vulnerabilities and predisposing conditions per NIST SP 800-30 Rev 1 Section 3.2 Step 3 + Appendix F (Vulnerabilities and Predisposing Conditions). Vulnerabilities include weaknesses in information systems, security procedures, internal controls, or implementation that could be exploited by a threat source. Predisposing conditions are organisational characteristics (mission, location, dependencies, technology choices, partnerships) that increase or decrease the likelihood that vulnerabilities will be exploited or that adverse impacts will result. Sources include (a) vulnerability scanning (continuous scan results, infrastructure-as-code policy scans, container image scans), (b) penetration testing reports, (c) red-team and tabletop exercise findings, (d) prior audit and assessment reports, (e) plan-of-action-and-milestones (POAM) register, (f) industry advisories (CVE, CWE, KEV catalogue). Document the vulnerability and predisposing condition catalogue per assessment with citation of source.
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 89 controls across 49 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33