STIGhub
STIGs
RMF Controls
Compare
← All Controls
RA-5
Risk Assessment
Rev 5
Vulnerability Monitoring and Scanning
CCI Identifiers (14)
CCI-001054
Monitor and scan for vulnerabilities in the system and hosted applications on an organization-defined frequency and/or randomly in accordance with organization-defined process.
CCI-001055
Defines a frequency for scanning for vulnerabilities in the system and hosted applications, and/or randomly in accordance with organization-defined process.
CCI-001056
Monitor and scan for vulnerabilities in the system and hosted applications when new vulnerabilities potentially affecting the system/applications are identified and reported.
CCI-001057
Employ vulnerability monitoring tools and techniques that facilitate interoperability among tools and automate parts of the vulnerability management process by using standards for: enumerating platforms, software flaws, and improper configurations.
CCI-001058
Analyze vulnerability scan reports and results from vulnerability monitoring.
CCI-001059
Remediate legitimate vulnerabilities in organization-defined response times in accordance with an organizational assessment risk.
CCI-001060
Defines response times for remediating legitimate vulnerabilities in accordance with an organization assessment of risk.
CCI-001061
Share information obtained from the vulnerability monitoring process and control assessments with organization-defined personnel or roles to help eliminate similar vulnerabilities in other systems.
CCI-001641
Defines the process for conducting random vulnerability scans on the system and hosted applications.
CCI-001643
Monitor and scan for vulnerabilities in the system and hosted applications in accordance with the organization-defined process for random scans.
CCI-002376
Defines the personnel or roles with whom the information obtained from the vulnerability monitoring process and control assessments will be shared.
CCI-004634
Employ vulnerability monitoring tools and techniques that facilitate interoperability among tools and automate parts of the vulnerability management process by using standards for: formatting checklists and test procedures.
CCI-004635
Employ vulnerability monitoring tools and techniques that facilitate interoperability among tools and automate parts of the vulnerability management process by using standards for: measuring vulnerability impact.
CCI-004636
Employ vulnerability monitoring tools that include the capability to readily update the vulnerabilities to be scanned.
Linked STIG Checks (0)
No STIG checks reference this control.