Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

NIST SP 800-53 Learning Center

RA-5 — Vulnerability Monitoring and Scanning

Read the official control and assessment content, then use the separately labeled Bare Metal Cyber perspective to connect the requirement to implementation, evidence, and sustained operation.

11Enhancements
5Parameters
3Baseline memberships
3Assessment methods

RA — Risk Assessment · NIST SP 800-53 Release 5.2.0

LowModerateHigh
Official NIST control content

Control statement

  1. a.Monitor and scan for vulnerabilities in the system and hosted applications [Organization-defined: organization-defined frequency and/or randomly in accordance with organization-defined process] and when new vulnerabilities potentially affecting the system are identified and reported;
  2. b.Employ vulnerability monitoring tools and techniques that facilitate interoperability among tools and automate parts of the vulnerability management process by using standards for:
    1. 1.Enumerating platforms, software flaws, and improper configurations;
    2. 2.Formatting checklists and test procedures; and
    3. 3.Measuring vulnerability impact;
  3. c.Analyze vulnerability scan reports and results from vulnerability monitoring;
  4. d.Remediate legitimate vulnerabilities [Organization-defined: response times] in accordance with an organizational assessment of risk;
  5. e.Share information obtained from the vulnerability monitoring process and control assessments with [Organization-defined: personnel or roles] to help eliminate similar vulnerabilities in other systems; and
  6. f.Employ vulnerability monitoring tools that include the capability to readily update the vulnerabilities to be scanned.
Official NIST discussion

Discussion

Security categorization of information and systems guides the frequency and comprehensiveness of vulnerability monitoring (including scans). Organizations determine the required vulnerability monitoring for system components, ensuring that the potential sources of vulnerabilities—such as infrastructure components (e.g., switches, routers, guards, sensors), networked printers, scanners, and copiers—are not overlooked. The capability to readily update vulnerability monitoring tools as new vulnerabilities are discovered and announced and as new scanning methods are developed helps to ensure that new vulnerabilities are not missed by employed vulnerability monitoring tools. The vulnerability monitoring tool update process helps to ensure that potential vulnerabilities in the system are identified and addressed as quickly as possible. Vulnerability monitoring and analyses for custom software may require additional approaches, such as static analysis, dynamic analysis, binary analysis, or a hybrid of the three approaches. Organizations can use these analysis approaches in source code reviews and in a variety of tools, including web-based application scanners, static analysis tools, and binary analyzers. Vulnerability monitoring includes scanning for patch levels; scanning for functions, ports, protocols, and services that should not be accessible to users or devices; and scanning for flow control mechanisms that are improperly configured or operating incorrectly. Vulnerability monitoring may also include continuous vulnerability monitoring tools that use instrumentation to continuously analyze components. Instrumentation-based tools may improve accuracy and may be run throughout an organization without scanning. Vulnerability monitoring tools that facilitate interoperability include tools that are Security Content Automated Protocol (SCAP)-validated. Thus, organizations consider using scanning tools that express vulnerabilities in the Common Vulnerabilities and Exposures (CVE) naming convention and that employ the Open Vulnerability Assessment Language (OVAL) to determine the presence of vulnerabilities. Sources for vulnerability information include the Common Weakness Enumeration (CWE) listing and the National Vulnerability Database (NVD). Control assessments, such as red team exercises, provide additional sources of potential vulnerabilities for which to scan. Organizations also consider using scanning tools that express vulnerability impact by the Common Vulnerability Scoring System (CVSS). Vulnerability monitoring includes a channel and process for receiving reports of security vulnerabilities from the public at-large. Vulnerability disclosure programs can be as simple as publishing a monitored email address or web form that can receive reports, including notification authorizing good-faith research and disclosure of security vulnerabilities. Organizations generally expect that such research is happening with or without their authorization and can use public vulnerability disclosure channels to increase the likelihood that discovered vulnerabilities are reported directly to the organization for remediation. Organizations may also employ the use of financial incentives (also known as "bug bounties" ) to further encourage external security researchers to report discovered vulnerabilities. Bug bounty programs can be tailored to the organization’s needs. Bounties can be operated indefinitely or over a defined period of time and can be offered to the general public or to a curated group. Organizations may run public and private bounties simultaneously and could choose to offer partially credentialed access to certain participants in order to evaluate security vulnerabilities from privileged vantage points.

Official OSCAL parameters

Organization-defined parameters

These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.

organization-defined frequency and/or randomly in accordance with organization-defined process
frequency and/or randomly in accordance with organization-defined processfrequency for monitoring systems and hosted applications for vulnerabilities is defined;
frequency and/or randomly in accordance with organization-defined processfrequency for scanning systems and hosted applications for vulnerabilities is defined;
response timesresponse times to remediate legitimate vulnerabilities in accordance with an organizational assessment of risk are defined;
personnel or rolespersonnel or roles with whom information obtained from the vulnerability scanning process and control assessments is to be shared;
Original Bare Metal Cyber perspective

From control text to operational evidence

Use Vulnerability Monitoring and Scanning as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to risk framing, threat and vulnerability analysis, impact, criticality, and response decisions.

Implementation workflow

  • Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
  • Resolve each organization-defined parameter before declaring the control implemented.
  • Document how the implementation satisfies every clause of the official control statement.
  • Collect evidence as a normal byproduct of operation rather than only before an assessment.
  • Review exceptions, changes, and monitoring results on a risk-based cadence.

Evidence examples

  • risk assessments and threat models
  • vulnerability findings and prioritization records
  • supply-chain risk assessments
  • risk response and acceptance decisions

Common failure patterns

  • risk registers detached from technical evidence
  • vulnerability severity treated as business impact
  • assessments not updated after material change
  • accepted risks have no owner or expiration

Questions practitioners should ask

  • What risk decision is this control intended to support in this system?
  • Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
  • Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
  • What event or threshold requires the implementation to be reviewed or changed?
Official NIST SP 800-53A content

Assessment objectives and methods

Show the assessment objective
  1. RA-05a.
    1. RA-05a.[01]systems and hosted applications are monitored for vulnerabilities [Organization-defined: frequency and/or randomly in accordance with organization-defined process] and when new vulnerabilities potentially affecting the system are identified and reported;
    2. RA-05a.[02]systems and hosted applications are scanned for vulnerabilities [Organization-defined: frequency and/or randomly in accordance with organization-defined process] and when new vulnerabilities potentially affecting the system are identified and reported;
  2. RA-05b.vulnerability monitoring tools and techniques are employed to facilitate interoperability among tools;
    1. RA-05b.01vulnerability monitoring tools and techniques are employed to automate parts of the vulnerability management process by using standards for enumerating platforms, software flaws, and improper configurations;
    2. RA-05b.02vulnerability monitoring tools and techniques are employed to facilitate interoperability among tools and to automate parts of the vulnerability management process by using standards for formatting checklists and test procedures;
    3. RA-05b.03vulnerability monitoring tools and techniques are employed to facilitate interoperability among tools and to automate parts of the vulnerability management process by using standards for measuring vulnerability impact;
  3. RA-05c.vulnerability scan reports and results from vulnerability monitoring are analyzed;
  4. RA-05d.legitimate vulnerabilities are remediated [Organization-defined: response times] in accordance with an organizational assessment of risk;
  5. RA-05e.information obtained from the vulnerability monitoring process and control assessments is shared with [Organization-defined: personnel or roles] to help eliminate similar vulnerabilities in other systems;
  6. RA-05f.vulnerability monitoring tools that include the capability to readily update the vulnerabilities to be scanned are employed.

Examine

  • Risk assessment policy
  • procedures addressing vulnerability scanning
  • risk assessment
  • assessment report
  • vulnerability scanning tools and associated configuration documentation
  • vulnerability scanning results
  • patch and vulnerability management records
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with risk assessment, control assessment, and vulnerability scanning responsibilities
  • organizational personnel with vulnerability scan analysis responsibilities
  • organizational personnel with vulnerability remediation responsibilities
  • organizational personnel with security responsibilities
  • system/network administrators

Test

  • Organizational processes for vulnerability scanning, analysis, remediation, and information sharing
  • mechanisms supporting and/or implementing vulnerability scanning, analysis, remediation, and information sharing
Official relationships

Related controls

These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.

MITRE D3FEND semantic mapping

Related defensive techniques

D3FEND maps this base control or one of its enhancements to the following defensive techniques. The ontology relation label is preserved and does not by itself prove implementation or effectiveness.

MITRE D3FEND™ and the D3FEND logo are trademarks of The MITRE Corporation. Bare Metal Cyber is not affiliated with or endorsed by MITRE.

Official NIST enhancements

Control enhancements

Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.

Official NIST control enhancement

RA-5(1) — Update Tool Capability

Withdrawn

This enhancement is marked withdrawn in the official OSCAL catalog. Related-control metadata below may identify where its intent was incorporated.

Official NIST control enhancement

RA-5(2) — Update Vulnerabilities to Be Scanned

LowModerateHigh

Update the system vulnerabilities to be scanned [Organization-defined: ra-05.02_odp.01].

Official discussion

Due to the complexity of modern software, systems, and other factors, new vulnerabilities are discovered on a regular basis. It is important that newly discovered vulnerabilities are added to the list of vulnerabilities to be scanned to ensure that the organization can take steps to mitigate those vulnerabilities in a timely manner.

Organization-defined parameters (2)
ra-05.02_odp.01
frequencythe frequency for updating the system vulnerabilities to be scanned is defined (if selected);
Assessment objectives and methods

the system vulnerabilities to be scanned are updated [Organization-defined: ra-05.02_odp.01].

Examine

  • Procedures addressing vulnerability scanning
  • assessment report
  • vulnerability scanning tools and associated configuration documentation
  • vulnerability scanning results
  • patch and vulnerability management records
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with vulnerability scanning responsibilities
  • organizational personnel with vulnerability scan analysis responsibilities
  • organizational personnel with security responsibilities
  • system/network administrators

Test

  • Organizational processes for vulnerability scanning
  • mechanisms/tools supporting and/or implementing vulnerability scanning
Related controls
Official NIST control enhancement

RA-5(3) — Breadth and Depth of Coverage

Define the breadth and depth of vulnerability scanning coverage.

Official discussion

The breadth of vulnerability scanning coverage can be expressed as a percentage of components within the system, by the particular types of systems, by the criticality of systems, or by the number of vulnerabilities to be checked. Conversely, the depth of vulnerability scanning coverage can be expressed as the level of the system design that the organization intends to monitor (e.g., component, module, subsystem, element). Organizations can determine the sufficiency of vulnerability scanning coverage with regard to its risk tolerance and other factors. Scanning tools and how the tools are configured may affect the depth and coverage. Multiple scanning tools may be needed to achieve the desired depth and coverage. [SP 800-53A](#a21aef46-7330-48a0-b2e1-c5bb8b2dd11d) provides additional information on the breadth and depth of coverage.

Assessment objectives and methods

the breadth and depth of vulnerability scanning coverage are defined.

Examine

  • Procedures addressing vulnerability scanning
  • assessment report
  • vulnerability scanning tools and associated configuration documentation
  • vulnerability scanning results
  • patch and vulnerability management records
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with vulnerability scanning responsibilities
  • organizational personnel with vulnerability scan analysis responsibilities
  • organizational personnel with security responsibilities

Test

  • Organizational processes for vulnerability scanning
  • mechanisms/tools supporting and/or implementing vulnerability scanning
Official NIST control enhancement

RA-5(4) — Discoverable Information

High

Determine information about the system that is discoverable and take [Organization-defined: corrective actions].

Official discussion

Discoverable information includes information that adversaries could obtain without compromising or breaching the system, such as by collecting information that the system is exposing or by conducting extensive web searches. Corrective actions include notifying appropriate organizational personnel, removing designated information, or changing the system to make the designated information less relevant or attractive to adversaries. This enhancement excludes intentionally discoverable information that may be part of a decoy capability (e.g., honeypots, honeynets, or deception nets) deployed by the organization.

Organization-defined parameters (1)
corrective actionscorrective actions to be taken if information about the system is discoverable are defined;
Assessment objectives and methods
  1. RA-05(04)[01]information about the system is discoverable;
  2. RA-05(04)[02][Organization-defined: corrective actions] are taken when information about the system is confirmed as discoverable.

Examine

  • Procedures addressing vulnerability scanning
  • assessment report
  • penetration test results
  • vulnerability scanning results
  • risk assessment report
  • records of corrective actions taken
  • incident response records
  • audit records
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with vulnerability scanning and/or penetration testing responsibilities
  • organizational personnel with vulnerability scan analysis responsibilities
  • organizational personnel responsible for risk response
  • organizational personnel responsible for incident management and response
  • organizational personnel with security responsibilities

Test

  • Organizational processes for vulnerability scanning
  • organizational processes for risk response
  • organizational processes for incident management and response
  • mechanisms/tools supporting and/or implementing vulnerability scanning
  • mechanisms supporting and/or implementing risk response
  • mechanisms supporting and/or implementing incident management and response
Related controls
Official NIST control enhancement

RA-5(5) — Privileged Access

ModerateHigh

Implement privileged access authorization to [Organization-defined: system components] for [Organization-defined: vulnerability scanning activities].

Official discussion

In certain situations, the nature of the vulnerability scanning may be more intrusive, or the system component that is the subject of the scanning may contain classified or controlled unclassified information, such as personally identifiable information. Privileged access authorization to selected system components facilitates more thorough vulnerability scanning and protects the sensitive nature of such scanning.

Organization-defined parameters (2)
system componentssystem components to which privileged access is authorized for selected vulnerability scanning activities are defined;
vulnerability scanning activitiesvulnerability scanning activities selected for privileged access authorization to system components are defined;
Assessment objectives and methods

privileged access authorization is implemented to [Organization-defined: system components] for [Organization-defined: vulnerability scanning activities].

Examine

  • Risk assessment policy
  • procedures addressing vulnerability scanning
  • system design documentation
  • system configuration settings and associated documentation
  • list of system components for vulnerability scanning
  • personnel access authorization list
  • authorization credentials
  • access authorization records
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with vulnerability scanning responsibilities
  • system/network administrators
  • organizational personnel responsible for access control to the system
  • organizational personnel responsible for configuration management of the system
  • system developers
  • organizational personnel with security responsibilities

Test

  • Organizational processes for vulnerability scanning
  • organizational processes for access control
  • mechanisms supporting and/or implementing access control
  • mechanisms/tools supporting and/or implementing vulnerability scanning
Official NIST control enhancement

RA-5(6) — Automated Trend Analyses

Compare the results of multiple vulnerability scans using [Organization-defined: automated mechanisms].

Official discussion

Using automated mechanisms to analyze multiple vulnerability scans over time can help determine trends in system vulnerabilities and identify patterns of attack.

Organization-defined parameters (1)
automated mechanismsautomated mechanisms to compare the results of multiple vulnerability scans are defined;
Assessment objectives and methods

the results of multiple vulnerability scans are compared using [Organization-defined: automated mechanisms].

Examine

  • Risk assessment policy
  • procedures addressing vulnerability scanning
  • system design documentation
  • vulnerability scanning tools and techniques documentation
  • vulnerability scanning results
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with vulnerability scanning responsibilities
  • organizational personnel with vulnerability scan analysis responsibilities
  • organizational personnel with security responsibilities

Test

  • Organizational processes for vulnerability scanning
  • automated mechanisms/tools supporting and/or implementing vulnerability scanning
  • automated mechanisms supporting and/or implementing trend analysis of vulnerability scan results
Official NIST control enhancement

RA-5(7) — Automated Detection and Notification of Unauthorized Components

Withdrawn

This enhancement is marked withdrawn in the official OSCAL catalog. Related-control metadata below may identify where its intent was incorporated.

Official NIST control enhancement

RA-5(8) — Review Historic Audit Logs

Review historic audit logs to determine if a vulnerability identified in a [Organization-defined: system] has been previously exploited within an [Organization-defined: time period].

Official discussion

Reviewing historic audit logs to determine if a recently detected vulnerability in a system has been previously exploited by an adversary can provide important information for forensic analyses. Such analyses can help identify, for example, the extent of a previous intrusion, the trade craft employed during the attack, organizational information exfiltrated or modified, mission or business capabilities affected, and the duration of the attack.

Organization-defined parameters (2)
systema system whose historic audit logs are to be reviewed is defined;
time perioda time period for a potential previous exploit of a system is defined;
Assessment objectives and methods

historic audit logs are reviewed to determine if a vulnerability identified in a [Organization-defined: system] has been previously exploited within [Organization-defined: time period].

Examine

  • Risk assessment policy
  • procedures addressing vulnerability scanning
  • audit logs
  • records of audit log reviews
  • vulnerability scanning results
  • patch and vulnerability management records
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with vulnerability scanning responsibilities
  • organizational personnel with vulnerability scan analysis responsibilities
  • organizational personnel with audit record review responsibilities
  • system/network administrators
  • organizational personnel with security responsibilities

Test

  • Organizational processes for vulnerability scanning
  • organizational process for audit record review and response
  • mechanisms/tools supporting and/or implementing vulnerability scanning
  • mechanisms supporting and/or implementing audit record review
Related controls
Official NIST control enhancement

RA-5(9) — Penetration Testing and Analyses

Withdrawn

This enhancement is marked withdrawn in the official OSCAL catalog. Related-control metadata below may identify where its intent was incorporated.

Official NIST control enhancement

RA-5(10) — Correlate Scanning Information

Correlate the output from vulnerability scanning tools to determine the presence of multi-vulnerability and multi-hop attack vectors.

Official discussion

An attack vector is a path or means by which an adversary can gain access to a system in order to deliver malicious code or exfiltrate information. Organizations can use attack trees to show how hostile activities by adversaries interact and combine to produce adverse impacts or negative consequences to systems and organizations. Such information, together with correlated data from vulnerability scanning tools, can provide greater clarity regarding multi-vulnerability and multi-hop attack vectors. The correlation of vulnerability scanning information is especially important when organizations are transitioning from older technologies to newer technologies (e.g., transitioning from IPv4 to IPv6 network protocols). During such transitions, some system components may inadvertently be unmanaged and create opportunities for adversary exploitation.

Assessment objectives and methods

the output from vulnerability scanning tools is correlated to determine the presence of multi-vulnerability and multi-hop attack vectors.

Examine

  • Risk assessment policy
  • procedures addressing vulnerability scanning
  • risk assessment
  • vulnerability scanning tools and techniques documentation
  • vulnerability scanning results
  • vulnerability management records
  • audit records
  • event/vulnerability correlation logs
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with vulnerability scanning responsibilities
  • organizational personnel with vulnerability scan analysis responsibilities
  • organizational personnel with security responsibilities

Test

  • Organizational processes for vulnerability scanning
  • mechanisms/tools supporting and/or implementing vulnerability scanning
  • mechanisms implementing the correlation of vulnerability scan results
Official NIST control enhancement

RA-5(11) — Public Disclosure Program

LowModerateHigh

Establish a public reporting channel for receiving reports of vulnerabilities in organizational systems and system components.

Official discussion

The reporting channel is publicly discoverable and contains clear language authorizing good-faith research and the disclosure of vulnerabilities to the organization. The organization does not condition its authorization on an expectation of indefinite non-disclosure to the public by the reporting entity but may request a specific time period to properly remediate the vulnerability.

Assessment objectives and methods

a public reporting channel is established for receiving reports of vulnerabilities in organizational systems and system components.

Examine

  • Risk assessment policy
  • procedures addressing vulnerability scanning
  • risk assessment
  • vulnerability scanning tools and techniques documentation
  • vulnerability scanning results
  • vulnerability management records
  • audit records
  • public reporting channel
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with vulnerability scanning responsibilities
  • organizational personnel with vulnerability scan analysis responsibilities
  • organizational personnel with security responsibilities

Test

  • Organizational processes for vulnerability scanning
  • mechanisms/tools supporting and/or implementing vulnerability scanning
  • mechanisms implementing the public reporting of vulnerabilities
Source record

Authoritative sources