Frameworks / NIST SP 800-66 Rev 2 / 164.308(a)(1)(ii)(B) NIST SP 800-66 Rev 2
Administrative
NIST SP 800-66 Rev 2 164.308(a)(1)(ii)(B): Risk Management (Required) Implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level. NIST recommends prioritized treatment plans, residual risk acceptance by leadership, and continuous monitoring tied to NIST SP 800-137.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 134 controls across 31 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
1.2.6 1.2.6 Security features for insecure services in use 11.3.1 11.3.1 Quarterly internal vulnerability scans 11.3.1.1 11.3.1.1 Lower-risk vulnerabilities handled per risk analysis 11.3.1.3 11.3.1.3 Internal scans after significant change 11.3.2.1 11.3.2.1 External scans after significant change 11.4.4 11.4.4 Correct exploitable findings from penetration tests 12.3.2 12.3.2 Targeted risk analysis for each customized-approach requirement 12.3.3 12.3.3 Cryptographic cipher suite and protocol inventory reviewed annually 12.6.1 12.6.1 Formal security awareness program 2.2.4 2.2.4 Only necessary functionality enabled 6.2.1 6.2.1 Secure development of bespoke and custom software 6.4.1 6.4.1 Public web application review or automated protection 6.3.1 6.3.1 Vulnerability identification and risk ranking 6.3.2 6.3.2 Inventory of bespoke software and components 5.4 Planning 5.4.1 Actions to address risks and opportunities 5.6.2 Information security risk assessment 5.6.3 Information security risk treatment 5.7.1 Monitoring, measurement, analysis and evaluation 6.10.1 Network security management 6.11 Systems acquisition, development and maintenance 6.11.1 Security requirements of information systems 6.9 Operations security 7.4 Privacy by design and privacy by default 8.2 Conditions for collection and processing 8.4 Privacy by design and privacy by default CIS-16.4 Establish and Manage an Inventory of Third-Party Software Components CIS-16.5 Use Up-to-Date and Trusted Third-Party Software Components CIS-18.1 Establish and Maintain a Penetration Testing Program CIS-2.2 Ensure Authorized Software is Currently Supported CIS-7.1 Establish and Maintain a Vulnerability Management Process CIS-7.2 Establish and Maintain a Remediation Process CIS-7.5 Perform Automated Vulnerability Scans of Internal Enterprise Assets CIS-7.6 Perform Automated Vulnerability Scans of Externally-Exposed Enterprise Assets CIS-7.7 Remediate Detected Vulnerabilities 5.25 Assessment and decision on information security events 5.34 Privacy and protection of personal identifiable information (PII) 5.7 Threat intelligence 8.16 Monitoring activities 8.27 Secure system architecture and engineering principles 8.8 Management of technical vulnerabilities 8.9 Configuration management NIST-CSF-GV.OV-02 The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks NIST-CSF-GV.OV-03 Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed NIST-CSF-GV.RM-01 Risk management objectives are established and agreed to by organizational stakeholders NIST-CSF-GV.RM-02 Risk appetite and risk tolerance statements are established, communicated, and maintained NIST-CSF-GV.RM-06 A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated NIST-CSF-ID.RA-04 Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded NIST-CSF-ID.RA-06 Risk responses are chosen, prioritized, planned, tracked, and communicated 6.1 Actions to address risks and opportunities 6.1.1 Determining risks and opportunities 6.1.2 Addressing risks and opportunities 8.1 Operational planning and control 8.2 Business impact analysis and risk assessment 8.2.3 Risk assessment 5.24 Information security incident management planning and preparation 5.34 Privacy and protection of PII 5.7 Threat intelligence 8.16 Monitoring activities 8.26 Application security requirements 8.8 Management of technical vulnerabilities SOC2-CC3.2 CC3.2 Identifying and analysing risks to objectives (COSO principle 7) SOC2-CC4.2 CC4.2 Evaluating and communicating control deficiencies (COSO principle 17) SOC2-CC5.1 CC5.1 Selecting control activities that mitigate risk (COSO principle 10) SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities SOC2-CC9.1 CC9.1 Mitigating risks of business disruption CPS234-15 Information Security Capability CPS234-21 Implementation of Information Security Controls CPS234-28 Escalation of Unremediated Testing Deficiencies CPS234-P17 Active Maintenance of Capability Against Change CFTC-SS-1 Program of Risk Analysis and Oversight CFTC-SS-17 Enterprise Technology Risk Assessment CFTC-SS-2 Enterprise Risk Management and Governance Category CFTC-SS-21 Remediation of Vulnerabilities and Deficiencies CA-5 Plan of Action and Milestones CA-7 Continuous Monitoring RA-3 Risk Assessment SI-2 Flaw Remediation CA-5 Plan of Action and Milestones CA-7 Continuous Monitoring RA-3 Risk Assessment SI-2 Flaw Remediation CPS230-11 Identification, Assessment and Management of Operational Risk CPS230-24 Design and Embedding of Internal Controls CPS230-P31 Remediation of Material Operational Risk Weaknesses SEC01-BP07 Identify threats and prioritize mitigations using a threat model SEC04-BP04 Initiate remediation for non-compliant resources SEC06-BP01 Perform vulnerability management C5-OIS-06 Risk Management Policy C5-OIS-07 Application of the Risk Management Policy C5-OPS-18 Managing Vulnerabilities, Malfunctions and Errors - Concept E8-PATCHAPP-ML1 Patch Applications (ML1) E8-PATCHOS-ML1 Patch Operating Systems (ML1) ANSSI-HYG-38 Carry Out Regular Security Checks and Audits and Apply the Corrective Actions ANSSI-HYG-41 Conduct a Formal Risk Analysis AUCDR-IS-4 Formal vulnerability management program AUCDR-IS-STEP3 Step 3 - Have and maintain an information security capability CPS220-P35 Required Content of Risk Management Policies and Procedures ASBv3-PV-6 Rapidly and automatically remediate vulnerabilities 3.11.4e Security Solution Rationale Document CE-FW.1 Boundary Firewalls Deployed Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in Administrative Query this from an agent The graph holds this control, the 134 it maps to, and the evidence behind each claim, over MCP and REST.