RA-5 — Vulnerability Monitoring and Scanning
Security categorization of information and systems guides the frequency and comprehensiveness of vulnerability monitoring (including scans). Organizations determine the required vulnerability monitoring for system components, ensuring that the potential sources of vulnerabilities—such as infrastructure components (e.g., switches, routers, guards, sensors), networked printers, scanners, and copiers—are not overlooked. The capability to readily update vulnerability monitoring tools as new vulnerabilities are discovered and announced and as new scanning methods are developed helps to ensure that new vulnerabilities are not missed by employed vulnerability monitoring tools. The vulnerability monitoring tool update process helps to ensure that potential vulnerabilities in the system are identified and addressed as quickly as possible. Vulnerability monitoring and analyses for custom softw
Read the official statement, discussion, parameters, enhancements, and assessment methods →
NIST CSF 2.0 informative references
These CSF Subcategories list this base control or one of its enhancements in the imported NIST informative reference.
NIST SP 800-171 and SP 800-172
SP 800-171 requirements sourcing this control
SP 800-172 enhanced requirements sourcing this control
MITRE D3FEND techniques
MITRE ATT&CK relationships
Curated mitigation mappings
Show 2 additional relationships
Inferred behavior relationships
Experimental: These relationships are inferred through D3FEND and must be validated against architecture, telemetry, and threat context.
Show 429 additional relationships
Use the map without overclaiming.
A CSF informative reference is not an equivalence statement. A source-control relationship is not proof of implementation. A D3FEND semantic relationship is not a product claim. An inferred ATT&CK link is a hypothesis for engineering analysis.
Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST or MITRE. Informative references and cross-framework relationships support navigation and analysis; they do not establish compliance, applicability, equivalence, control inheritance, or guaranteed mitigation effectiveness.