Vulnerability Monitoring and Scanning

✓ LOW ✓ MODERATE ✓ HIGH
8 Enhancements 1 Overlay 17 Related Controls
Graph
Export ▾

Requirements NIST SOURCE

    1. 1.Enumerating platforms, software flaws, and improper configurations;
    2. 2.Formatting checklists and test procedures; and
    3. 3.Measuring vulnerability impact;
Discussion (NIST Supplemental Guidance)

Security categorization of information and systems guides the frequency and comprehensiveness of vulnerability monitoring (including scans). Organizations determine the required vulnerability monitoring for system components, ensuring that the potential sources of vulnerabilities—such as infrastructure components (e.g., switches, routers, guards, sensors), networked printers, scanners, and copiers—are not overlooked. The capability to readily update vulnerability monitoring tools as new vulnerabilities are discovered and announced and as new scanning methods are developed helps to ensure that new vulnerabilities are not missed by employed vulnerability monitoring tools. The vulnerability monitoring tool update process helps to ensure that potential vulnerabilities in the system are identified and addressed as quickly as possible. Vulnerability monitoring and analyses for custom software may require additional approaches, such as static analysis, dynamic analysis, binary analysis, or a hybrid of the three approaches. Organizations can use these analysis approaches in source code reviews and in a variety of tools, including web-based application scanners, static analysis tools, and binary analyzers. Vulnerability monitoring includes scanning for patch levels; scanning for functions, ports, protocols, and services that should not be accessible to users or devices; and scanning for flow control mechanisms that are improperly configured or operating incorrectly. Vulnerability monitoring may also include continuous vulnerability monitoring tools that use instrumentation to continuously analyze components. Instrumentation-based tools may improve accuracy and may be run throughout an organization without scanning. Vulnerability monitoring tools that facilitate interoperability include tools that are Security Content Automated Protocol (SCAP)-validated. Thus, organizations consider using scanning tools that express vulnerabilities in the Common Vulnerabilities and Exposures (CVE) naming convention and that employ the Open Vulnerability Assessment Language (OVAL) to determine the presence of vulnerabilities. Sources for vulnerability information include the Common Weakness Enumeration (CWE) listing and the National Vulnerability Database (NVD). Control assessments, such as red team exercises, provide additional sources of potential vulnerabilities for which to scan. Organizations also consider using scanning tools that express vulnerability impact by the Common Vulnerability Scoring System (CVSS). Vulnerability monitoring includes a channel and process for receiving reports of security vulnerabilities from the public at-large. Vulnerability disclosure programs can be as simple as publishing a monitored email address or web form that can receive reports, including notification authorizing good-faith research and disclosure of security vulnerabilities. Organizations generally expect that such research is happening with or without their authorization and can use public vulnerability disclosure channels to increase the likelihood that discovered vulnerabilities are reported directly to the organization for remediation. Organizations may also employ the use of financial incentives (also known as "bug bounties" ) to further encourage external security researchers to report discovered vulnerabilities. Bug bounty programs can be tailored to the organization’s needs. Bounties can be operated indefinitely or over a defined period of time and can be offered to the general public or to a curated group. Organizations may run public and private bounties simultaneously and could choose to offer partially credentialed access to certain participants in order to evaluate security vulnerabilities from privileged vantage points.

Enhancements NIST SOURCE

RA-5(1) Update Tool Capability WITHDRAWN

Withdrawn. Incorporated into RA-5.

RA-5(2) Update Vulnerabilities to Be Scanned ✓ LOW ✓ MODERATE ✓ HIGH

Update the system vulnerabilities to be scanned [one of: ; prior to a new scan; when new vulnerabilities are identified and reported].

Discussion

Due to the complexity of modern software, systems, and other factors, new vulnerabilities are discovered on a regular basis. It is important that newly discovered vulnerabilities are added to the list of vulnerabilities to be scanned to ensure that the organization can take steps to mitigate those vulnerabilities in a timely manner.

Open full page for RA-5(2) →
RA-5(3) Breadth and Depth of Coverage LOW MODERATE HIGH

Define the breadth and depth of vulnerability scanning coverage.

Discussion

The breadth of vulnerability scanning coverage can be expressed as a percentage of components within the system, by the particular types of systems, by the criticality of systems, or by the number of vulnerabilities to be checked. Conversely, the depth of vulnerability scanning coverage can be expressed as the level of the system design that the organization intends to monitor (e.g., component, module, subsystem, element). Organizations can determine the sufficiency of vulnerability scanning coverage with regard to its risk tolerance and other factors. Scanning tools and how the tools are configured may affect the depth and coverage. Multiple scanning tools may be needed to achieve the desired depth and coverage. SP 800-53A provides additional information on the breadth and depth of coverage.

Open full page for RA-5(3) →
RA-5(4) Discoverable Information LOW MODERATE ✓ HIGH

Determine information about the system that is discoverable and take [corrective actions].

Discussion

Discoverable information includes information that adversaries could obtain without compromising or breaching the system, such as by collecting information that the system is exposing or by conducting extensive web searches. Corrective actions include notifying appropriate organizational personnel, removing designated information, or changing the system to make the designated information less relevant or attractive to adversaries. This enhancement excludes intentionally discoverable information that may be part of a decoy capability (e.g., honeypots, honeynets, or deception nets) deployed by the organization.

Open full page for RA-5(4) →
RA-5(5) Privileged Access LOW ✓ MODERATE ✓ HIGH

Implement privileged access authorization to [system components] for [vulnerability scanning activities].

Discussion

In certain situations, the nature of the vulnerability scanning may be more intrusive, or the system component that is the subject of the scanning may contain classified or controlled unclassified information, such as personally identifiable information. Privileged access authorization to selected system components facilitates more thorough vulnerability scanning and protects the sensitive nature of such scanning.

Open full page for RA-5(5) →
RA-5(6) Automated Trend Analyses LOW MODERATE HIGH

Compare the results of multiple vulnerability scans using [automated mechanisms].

Discussion

Using automated mechanisms to analyze multiple vulnerability scans over time can help determine trends in system vulnerabilities and identify patterns of attack.

Open full page for RA-5(6) →
RA-5(7) Automated Detection and Notification of Unauthorized Components WITHDRAWN

Withdrawn. Incorporated into CM-8.

RA-5(8) Review Historic Audit Logs LOW MODERATE HIGH

Review historic audit logs to determine if a vulnerability identified in a [system] has been previously exploited within an [time period].

Discussion

Reviewing historic audit logs to determine if a recently detected vulnerability in a system has been previously exploited by an adversary can provide important information for forensic analyses. Such analyses can help identify, for example, the extent of a previous intrusion, the trade craft employed during the attack, organizational information exfiltrated or modified, mission or business capabilities affected, and the duration of the attack.

Open full page for RA-5(8) →
RA-5(9) Penetration Testing and Analyses WITHDRAWN

Withdrawn. Incorporated into CA-8.

RA-5(10) Correlate Scanning Information LOW MODERATE HIGH

Correlate the output from vulnerability scanning tools to determine the presence of multi-vulnerability and multi-hop attack vectors.

Discussion

An attack vector is a path or means by which an adversary can gain access to a system in order to deliver malicious code or exfiltrate information. Organizations can use attack trees to show how hostile activities by adversaries interact and combine to produce adverse impacts or negative consequences to systems and organizations. Such information, together with correlated data from vulnerability scanning tools, can provide greater clarity regarding multi-vulnerability and multi-hop attack vectors. The correlation of vulnerability scanning information is especially important when organizations are transitioning from older technologies to newer technologies (e.g., transitioning from IPv4 to IPv6 network protocols). During such transitions, some system components may inadvertently be unmanaged and create opportunities for adversary exploitation.

Open full page for RA-5(10) →
RA-5(11) Public Disclosure Program ✓ LOW ✓ MODERATE ✓ HIGH

Establish a public reporting channel for receiving reports of vulnerabilities in organizational systems and system components.

Discussion

The reporting channel is publicly discoverable and contains clear language authorizing good-faith research and the disclosure of vulnerabilities to the organization. The organization does not condition its authorization on an expectation of indefinite non-disclosure to the public by the reporting entity but may request a specific time period to properly remediate the vulnerability.

Open full page for RA-5(11) →

Implementation Guidance

Engineering Interpretation

Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.

No engineering interpretation has been authored for RA-5 yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.

Assessment

NIST SP 800-53A REV 5.2.0

Assessment Objectives

  1. frequency for monitoring systems and hosted applications for vulnerabilities is defined;
  2. frequency for scanning systems and hosted applications for vulnerabilities is defined;
  3. response times to remediate legitimate vulnerabilities in accordance with an organizational assessment of risk are defined;
  4. personnel or roles with whom information obtained from the vulnerability scanning process and control assessments is to be shared;
  5. systems and hosted applications are monitored for vulnerabilities <RA-05_ODP[01] frequency and/or randomly in accordance with organization-defined process> and when new vulnerabilities potentially affecting the system are identified and reported;
  6. systems and hosted applications are scanned for vulnerabilities <RA-05_ODP[02] frequency and/or randomly in accordance with organization-defined process> and when new vulnerabilities potentially affecting the system are identified and reported;
  7. vulnerability monitoring tools and techniques are employed to facilitate interoperability among tools;
  8. vulnerability monitoring tools and techniques are employed to automate parts of the vulnerability management process by using standards for enumerating platforms, software flaws, and improper configurations;
  9. vulnerability monitoring tools and techniques are employed to facilitate interoperability among tools and to automate parts of the vulnerability management process by using standards for formatting checklists and test procedures;
  10. vulnerability monitoring tools and techniques are employed to facilitate interoperability among tools and to automate parts of the vulnerability management process by using standards for measuring vulnerability impact;
  11. vulnerability scan reports and results from vulnerability monitoring are analyzed;
  12. legitimate vulnerabilities are remediated <RA-05_ODP[03] response times> in accordance with an organizational assessment of risk;
  13. information obtained from the vulnerability monitoring process and control assessments is shared with <RA-05_ODP[04] personnel or roles> to help eliminate similar vulnerabilities in other systems;
  14. vulnerability monitoring tools that include the capability to readily update the vulnerabilities to be scanned are employed.

Examine

[SELECT FROM: Risk assessment policy; procedures addressing vulnerability scanning; risk assessment; assessment report; vulnerability scanning tools and associated configuration documentation; vulnerability scanning results; patch and vulnerability management records; system security plan; other relevant documents or records].

Interview

[SELECT FROM: Organizational personnel with risk assessment, control assessment, and vulnerability scanning responsibilities; organizational personnel with vulnerability scan analysis responsibilities; organizational personnel with vulnerability remediation responsibilities; organizational personnel with security responsibilities; system/network administrators].

Test

[SELECT FROM: Organizational processes for vulnerability scanning, analysis, remediation, and information sharing; mechanisms supporting and/or implementing vulnerability scanning, analysis, remediation, and information sharing].

Overlays

OT/ICS Overlay SP 800-82r3

NIST SP 800-82r3 Appendix F, Table 22. Blank baseline means the control/control enhancement is not selected in that initial OT baseline.

LOW

  • Base control: Included (matches standard baseline)
  • Included: (2) (11)

MODERATE

  • Base control: Included (matches standard baseline)
  • Included: (2) (5) (11)

HIGH

  • Base control: Included (matches standard baseline)
  • Included: (2) (4) (5) (11)

STIGs & CCIs

No STIG checks or CCI mappings are currently loaded for RA-5. This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.

Learn more about STIG/CCI integration →

Evidence

Potential Evidence — Derived

Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.

Policy

  • Risk assessment policy
  • system security plan

Configuration

  • vulnerability scanning tools and associated configuration documentation

Testing

  • Organizational processes for vulnerability scanning, analysis, remediation, and information sharing
  • mechanisms supporting and/or implementing vulnerability scanning, analysis, remediation, and information sharing

Other Records

  • procedures addressing vulnerability scanning
  • risk assessment
  • assessment report
  • vulnerability scanning results
  • patch and vulnerability management records
  • other relevant documents or records