Control statement
- a.Monitor and scan for vulnerabilities in the system and hosted applications [Organization-defined: organization-defined frequency and/or randomly in accordance with organization-defined process] and when new vulnerabilities potentially affecting the system are identified and reported;
- b.Employ vulnerability monitoring tools and techniques that facilitate interoperability among tools and automate parts of the vulnerability management process by using standards for:
- 1.Enumerating platforms, software flaws, and improper configurations;
- 2.Formatting checklists and test procedures; and
- 3.Measuring vulnerability impact;
- c.Analyze vulnerability scan reports and results from vulnerability monitoring;
- d.Remediate legitimate vulnerabilities [Organization-defined: response times] in accordance with an organizational assessment of risk;
- e.Share information obtained from the vulnerability monitoring process and control assessments with [Organization-defined: personnel or roles] to help eliminate similar vulnerabilities in other systems; and
- f.Employ vulnerability monitoring tools that include the capability to readily update the vulnerabilities to be scanned.
Discussion
Security categorization of information and systems guides the frequency and comprehensiveness of vulnerability monitoring (including scans). Organizations determine the required vulnerability monitoring for system components, ensuring that the potential sources of vulnerabilities—such as infrastructure components (e.g., switches, routers, guards, sensors), networked printers, scanners, and copiers—are not overlooked. The capability to readily update vulnerability monitoring tools as new vulnerabilities are discovered and announced and as new scanning methods are developed helps to ensure that new vulnerabilities are not missed by employed vulnerability monitoring tools. The vulnerability monitoring tool update process helps to ensure that potential vulnerabilities in the system are identified and addressed as quickly as possible. Vulnerability monitoring and analyses for custom software may require additional approaches, such as static analysis, dynamic analysis, binary analysis, or a hybrid of the three approaches. Organizations can use these analysis approaches in source code reviews and in a variety of tools, including web-based application scanners, static analysis tools, and binary analyzers. Vulnerability monitoring includes scanning for patch levels; scanning for functions, ports, protocols, and services that should not be accessible to users or devices; and scanning for flow control mechanisms that are improperly configured or operating incorrectly. Vulnerability monitoring may also include continuous vulnerability monitoring tools that use instrumentation to continuously analyze components. Instrumentation-based tools may improve accuracy and may be run throughout an organization without scanning. Vulnerability monitoring tools that facilitate interoperability include tools that are Security Content Automated Protocol (SCAP)-validated. Thus, organizations consider using scanning tools that express vulnerabilities in the Common Vulnerabilities and Exposures (CVE) naming convention and that employ the Open Vulnerability Assessment Language (OVAL) to determine the presence of vulnerabilities. Sources for vulnerability information include the Common Weakness Enumeration (CWE) listing and the National Vulnerability Database (NVD). Control assessments, such as red team exercises, provide additional sources of potential vulnerabilities for which to scan. Organizations also consider using scanning tools that express vulnerability impact by the Common Vulnerability Scoring System (CVSS). Vulnerability monitoring includes a channel and process for receiving reports of security vulnerabilities from the public at-large. Vulnerability disclosure programs can be as simple as publishing a monitored email address or web form that can receive reports, including notification authorizing good-faith research and disclosure of security vulnerabilities. Organizations generally expect that such research is happening with or without their authorization and can use public vulnerability disclosure channels to increase the likelihood that discovered vulnerabilities are reported directly to the organization for remediation. Organizations may also employ the use of financial incentives (also known as "bug bounties" ) to further encourage external security researchers to report discovered vulnerabilities. Bug bounty programs can be tailored to the organization’s needs. Bounties can be operated indefinitely or over a defined period of time and can be offered to the general public or to a curated group. Organizations may run public and private bounties simultaneously and could choose to offer partially credentialed access to certain participants in order to evaluate security vulnerabilities from privileged vantage points.
Organization-defined parameters
These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.
From control text to operational evidence
Use Vulnerability Monitoring and Scanning as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to risk framing, threat and vulnerability analysis, impact, criticality, and response decisions.
Implementation workflow
- Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
- Resolve each organization-defined parameter before declaring the control implemented.
- Document how the implementation satisfies every clause of the official control statement.
- Collect evidence as a normal byproduct of operation rather than only before an assessment.
- Review exceptions, changes, and monitoring results on a risk-based cadence.
Evidence examples
- risk assessments and threat models
- vulnerability findings and prioritization records
- supply-chain risk assessments
- risk response and acceptance decisions
Common failure patterns
- risk registers detached from technical evidence
- vulnerability severity treated as business impact
- assessments not updated after material change
- accepted risks have no owner or expiration
Questions practitioners should ask
- What risk decision is this control intended to support in this system?
- Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
- Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
- What event or threshold requires the implementation to be reviewed or changed?
Assessment objectives and methods
Show the assessment objective
- RA-05a.
- RA-05a.[01]systems and hosted applications are monitored for vulnerabilities [Organization-defined: frequency and/or randomly in accordance with organization-defined process] and when new vulnerabilities potentially affecting the system are identified and reported;
- RA-05a.[02]systems and hosted applications are scanned for vulnerabilities [Organization-defined: frequency and/or randomly in accordance with organization-defined process] and when new vulnerabilities potentially affecting the system are identified and reported;
- RA-05b.vulnerability monitoring tools and techniques are employed to facilitate interoperability among tools;
- RA-05b.01vulnerability monitoring tools and techniques are employed to automate parts of the vulnerability management process by using standards for enumerating platforms, software flaws, and improper configurations;
- RA-05b.02vulnerability monitoring tools and techniques are employed to facilitate interoperability among tools and to automate parts of the vulnerability management process by using standards for formatting checklists and test procedures;
- RA-05b.03vulnerability monitoring tools and techniques are employed to facilitate interoperability among tools and to automate parts of the vulnerability management process by using standards for measuring vulnerability impact;
- RA-05c.vulnerability scan reports and results from vulnerability monitoring are analyzed;
- RA-05d.legitimate vulnerabilities are remediated [Organization-defined: response times] in accordance with an organizational assessment of risk;
- RA-05e.information obtained from the vulnerability monitoring process and control assessments is shared with [Organization-defined: personnel or roles] to help eliminate similar vulnerabilities in other systems;
- RA-05f.vulnerability monitoring tools that include the capability to readily update the vulnerabilities to be scanned are employed.
Examine
- Risk assessment policy
- procedures addressing vulnerability scanning
- risk assessment
- assessment report
- vulnerability scanning tools and associated configuration documentation
- vulnerability scanning results
- patch and vulnerability management records
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with risk assessment, control assessment, and vulnerability scanning responsibilities
- organizational personnel with vulnerability scan analysis responsibilities
- organizational personnel with vulnerability remediation responsibilities
- organizational personnel with security responsibilities
- system/network administrators
Test
- Organizational processes for vulnerability scanning, analysis, remediation, and information sharing
- mechanisms supporting and/or implementing vulnerability scanning, analysis, remediation, and information sharing
Related controls
These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.
Related defensive techniques
D3FEND maps this base control or one of its enhancements to the following defensive techniques. The ontology relation label is preserved and does not by itself prove implementation or effectiveness.
MITRE D3FEND™ and the D3FEND logo are trademarks of The MITRE Corporation. Bare Metal Cyber is not affiliated with or endorsed by MITRE.
Control enhancements
Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.
RA-5(1) — Update Tool Capability
This enhancement is marked withdrawn in the official OSCAL catalog. Related-control metadata below may identify where its intent was incorporated.
RA-5(2) — Update Vulnerabilities to Be Scanned
Update the system vulnerabilities to be scanned [Organization-defined: ra-05.02_odp.01].
Official discussion
Due to the complexity of modern software, systems, and other factors, new vulnerabilities are discovered on a regular basis. It is important that newly discovered vulnerabilities are added to the list of vulnerabilities to be scanned to ensure that the organization can take steps to mitigate those vulnerabilities in a timely manner.
Organization-defined parameters (2)
Assessment objectives and methods
the system vulnerabilities to be scanned are updated [Organization-defined: ra-05.02_odp.01].
Examine
- Procedures addressing vulnerability scanning
- assessment report
- vulnerability scanning tools and associated configuration documentation
- vulnerability scanning results
- patch and vulnerability management records
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with vulnerability scanning responsibilities
- organizational personnel with vulnerability scan analysis responsibilities
- organizational personnel with security responsibilities
- system/network administrators
Test
- Organizational processes for vulnerability scanning
- mechanisms/tools supporting and/or implementing vulnerability scanning
Related controls
RA-5(3) — Breadth and Depth of Coverage
Define the breadth and depth of vulnerability scanning coverage.
Official discussion
The breadth of vulnerability scanning coverage can be expressed as a percentage of components within the system, by the particular types of systems, by the criticality of systems, or by the number of vulnerabilities to be checked. Conversely, the depth of vulnerability scanning coverage can be expressed as the level of the system design that the organization intends to monitor (e.g., component, module, subsystem, element). Organizations can determine the sufficiency of vulnerability scanning coverage with regard to its risk tolerance and other factors. Scanning tools and how the tools are configured may affect the depth and coverage. Multiple scanning tools may be needed to achieve the desired depth and coverage. [SP 800-53A](#a21aef46-7330-48a0-b2e1-c5bb8b2dd11d) provides additional information on the breadth and depth of coverage.
Assessment objectives and methods
the breadth and depth of vulnerability scanning coverage are defined.
Examine
- Procedures addressing vulnerability scanning
- assessment report
- vulnerability scanning tools and associated configuration documentation
- vulnerability scanning results
- patch and vulnerability management records
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with vulnerability scanning responsibilities
- organizational personnel with vulnerability scan analysis responsibilities
- organizational personnel with security responsibilities
Test
- Organizational processes for vulnerability scanning
- mechanisms/tools supporting and/or implementing vulnerability scanning
RA-5(4) — Discoverable Information
Determine information about the system that is discoverable and take [Organization-defined: corrective actions].
Official discussion
Discoverable information includes information that adversaries could obtain without compromising or breaching the system, such as by collecting information that the system is exposing or by conducting extensive web searches. Corrective actions include notifying appropriate organizational personnel, removing designated information, or changing the system to make the designated information less relevant or attractive to adversaries. This enhancement excludes intentionally discoverable information that may be part of a decoy capability (e.g., honeypots, honeynets, or deception nets) deployed by the organization.
Organization-defined parameters (1)
Assessment objectives and methods
- RA-05(04)[01]information about the system is discoverable;
- RA-05(04)[02][Organization-defined: corrective actions] are taken when information about the system is confirmed as discoverable.
Examine
- Procedures addressing vulnerability scanning
- assessment report
- penetration test results
- vulnerability scanning results
- risk assessment report
- records of corrective actions taken
- incident response records
- audit records
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with vulnerability scanning and/or penetration testing responsibilities
- organizational personnel with vulnerability scan analysis responsibilities
- organizational personnel responsible for risk response
- organizational personnel responsible for incident management and response
- organizational personnel with security responsibilities
Test
- Organizational processes for vulnerability scanning
- organizational processes for risk response
- organizational processes for incident management and response
- mechanisms/tools supporting and/or implementing vulnerability scanning
- mechanisms supporting and/or implementing risk response
- mechanisms supporting and/or implementing incident management and response
Related controls
RA-5(5) — Privileged Access
Implement privileged access authorization to [Organization-defined: system components] for [Organization-defined: vulnerability scanning activities].
Official discussion
In certain situations, the nature of the vulnerability scanning may be more intrusive, or the system component that is the subject of the scanning may contain classified or controlled unclassified information, such as personally identifiable information. Privileged access authorization to selected system components facilitates more thorough vulnerability scanning and protects the sensitive nature of such scanning.
Organization-defined parameters (2)
Assessment objectives and methods
privileged access authorization is implemented to [Organization-defined: system components] for [Organization-defined: vulnerability scanning activities].
Examine
- Risk assessment policy
- procedures addressing vulnerability scanning
- system design documentation
- system configuration settings and associated documentation
- list of system components for vulnerability scanning
- personnel access authorization list
- authorization credentials
- access authorization records
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with vulnerability scanning responsibilities
- system/network administrators
- organizational personnel responsible for access control to the system
- organizational personnel responsible for configuration management of the system
- system developers
- organizational personnel with security responsibilities
Test
- Organizational processes for vulnerability scanning
- organizational processes for access control
- mechanisms supporting and/or implementing access control
- mechanisms/tools supporting and/or implementing vulnerability scanning
RA-5(6) — Automated Trend Analyses
Compare the results of multiple vulnerability scans using [Organization-defined: automated mechanisms].
Official discussion
Using automated mechanisms to analyze multiple vulnerability scans over time can help determine trends in system vulnerabilities and identify patterns of attack.
Organization-defined parameters (1)
Assessment objectives and methods
the results of multiple vulnerability scans are compared using [Organization-defined: automated mechanisms].
Examine
- Risk assessment policy
- procedures addressing vulnerability scanning
- system design documentation
- vulnerability scanning tools and techniques documentation
- vulnerability scanning results
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with vulnerability scanning responsibilities
- organizational personnel with vulnerability scan analysis responsibilities
- organizational personnel with security responsibilities
Test
- Organizational processes for vulnerability scanning
- automated mechanisms/tools supporting and/or implementing vulnerability scanning
- automated mechanisms supporting and/or implementing trend analysis of vulnerability scan results
RA-5(7) — Automated Detection and Notification of Unauthorized Components
This enhancement is marked withdrawn in the official OSCAL catalog. Related-control metadata below may identify where its intent was incorporated.
RA-5(8) — Review Historic Audit Logs
Review historic audit logs to determine if a vulnerability identified in a [Organization-defined: system] has been previously exploited within an [Organization-defined: time period].
Official discussion
Reviewing historic audit logs to determine if a recently detected vulnerability in a system has been previously exploited by an adversary can provide important information for forensic analyses. Such analyses can help identify, for example, the extent of a previous intrusion, the trade craft employed during the attack, organizational information exfiltrated or modified, mission or business capabilities affected, and the duration of the attack.
Organization-defined parameters (2)
Assessment objectives and methods
historic audit logs are reviewed to determine if a vulnerability identified in a [Organization-defined: system] has been previously exploited within [Organization-defined: time period].
Examine
- Risk assessment policy
- procedures addressing vulnerability scanning
- audit logs
- records of audit log reviews
- vulnerability scanning results
- patch and vulnerability management records
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with vulnerability scanning responsibilities
- organizational personnel with vulnerability scan analysis responsibilities
- organizational personnel with audit record review responsibilities
- system/network administrators
- organizational personnel with security responsibilities
Test
- Organizational processes for vulnerability scanning
- organizational process for audit record review and response
- mechanisms/tools supporting and/or implementing vulnerability scanning
- mechanisms supporting and/or implementing audit record review
Related controls
RA-5(9) — Penetration Testing and Analyses
This enhancement is marked withdrawn in the official OSCAL catalog. Related-control metadata below may identify where its intent was incorporated.
RA-5(10) — Correlate Scanning Information
Correlate the output from vulnerability scanning tools to determine the presence of multi-vulnerability and multi-hop attack vectors.
Official discussion
An attack vector is a path or means by which an adversary can gain access to a system in order to deliver malicious code or exfiltrate information. Organizations can use attack trees to show how hostile activities by adversaries interact and combine to produce adverse impacts or negative consequences to systems and organizations. Such information, together with correlated data from vulnerability scanning tools, can provide greater clarity regarding multi-vulnerability and multi-hop attack vectors. The correlation of vulnerability scanning information is especially important when organizations are transitioning from older technologies to newer technologies (e.g., transitioning from IPv4 to IPv6 network protocols). During such transitions, some system components may inadvertently be unmanaged and create opportunities for adversary exploitation.
Assessment objectives and methods
the output from vulnerability scanning tools is correlated to determine the presence of multi-vulnerability and multi-hop attack vectors.
Examine
- Risk assessment policy
- procedures addressing vulnerability scanning
- risk assessment
- vulnerability scanning tools and techniques documentation
- vulnerability scanning results
- vulnerability management records
- audit records
- event/vulnerability correlation logs
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with vulnerability scanning responsibilities
- organizational personnel with vulnerability scan analysis responsibilities
- organizational personnel with security responsibilities
Test
- Organizational processes for vulnerability scanning
- mechanisms/tools supporting and/or implementing vulnerability scanning
- mechanisms implementing the correlation of vulnerability scan results
RA-5(11) — Public Disclosure Program
Establish a public reporting channel for receiving reports of vulnerabilities in organizational systems and system components.
Official discussion
The reporting channel is publicly discoverable and contains clear language authorizing good-faith research and the disclosure of vulnerabilities to the organization. The organization does not condition its authorization on an expectation of indefinite non-disclosure to the public by the reporting entity but may request a specific time period to properly remediate the vulnerability.
Assessment objectives and methods
a public reporting channel is established for receiving reports of vulnerabilities in organizational systems and system components.
Examine
- Risk assessment policy
- procedures addressing vulnerability scanning
- risk assessment
- vulnerability scanning tools and techniques documentation
- vulnerability scanning results
- vulnerability management records
- audit records
- public reporting channel
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with vulnerability scanning responsibilities
- organizational personnel with vulnerability scan analysis responsibilities
- organizational personnel with security responsibilities
Test
- Organizational processes for vulnerability scanning
- mechanisms/tools supporting and/or implementing vulnerability scanning
- mechanisms implementing the public reporting of vulnerabilities
Authoritative sources
Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST. Official control requirements and interpretations remain with NIST and the responsible authorizing organization.