unified
UC-VULN-01 — Scan for vulnerabilities and track advisories on a defined cadence
Run authenticated vulnerability scans across all in-scope systems and applications on a defined cadence — at least quarterly and after significant changes — using tools whose vulnerability feeds are kept current. Subscribe to security advisories and directives from authoritative sources, assess their applicability, and disseminate them to system owners with required actions and completion dates. Validate and record every finding in a central register with severity ratings, and track findings to closure within severity-based timeframes. Share scan results and advisory status with designated security and management roles.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Vulnerability & Patch Management
- type
- detective
- category
- technical
Details
- unified_id
- UC-VULN-01
- title
- Scan for vulnerabilities and track advisories on a defined cadence
- statement
- Run authenticated vulnerability scans across all in-scope systems and applications on a defined cadence — at least quarterly and after significant changes — using tools whose vulnerability feeds are kept current. Subscribe to security advisories and directives from authoritative sources, assess their applicability, and disseminate them to system owners with required actions and completion dates. Validate and record every finding in a central register with severity ratings, and track findings to closure within severity-based timeframes. Share scan results and advisory status with designated security and management roles.
- domain
- Vulnerability & Patch Management
- control_type
- detective
- control_category
- technical
- members
- framework
- nist-800-53
- control_id
- RA-5
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- SI-5
- coverage
- full
- relationship
- superset_of
- framework
- nist-csf-2
- control_id
- ID.RA-01
- coverage
- full
- relationship
- superset_of
- framework
- nydfs-500
- control_id
- 500.5
- coverage
- partial
- delta
- also requires annual penetration testing by a qualified independent party
- relationship
- intersects_with
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-VULN-01 — Scan for vulnerabilities and track advisories on a defined cadence mitigates Internet-exposed or misconfigured systems
- strength
- related
- rationale
- Authenticated scans detect exposed ports/services and misconfigured internet-facing systems, enabling correction.
- UC-VULN-01 — Scan for vulnerabilities and track advisories on a defined cadence maps_to 500.5 — Vulnerability management (penetration testing and scanning)
- framework
- nydfs-500
- control_id
- 500.5
- coverage
- partial
- delta
- also requires annual penetration testing by a qualified independent party
- relationship
- intersects_with
- source_version
- 23 NYCRR 500, Second Amendment
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-VULN-01 — Scan for vulnerabilities and track advisories on a defined cadence maps_to SI-5 — Security Alerts, Advisories, and Directives
- framework
- nist-800-53
- control_id
- SI-5
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-VULN-01 — Scan for vulnerabilities and track advisories on a defined cadence maps_to ID.RA-01 — Risk Assessment: Vulnerabilities in assets are identified, validated, and recorded
- framework
- nist-csf-2
- control_id
- ID.RA-01
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-VULN-01 — Scan for vulnerabilities and track advisories on a defined cadence mitigates Inadequate vulnerability scanning and pre-release testing
- strength
- primary
- rationale
- Authenticated scans on a defined cadence are the operative control against absent or irregular vulnerability scanning.
- UC-VULN-01 — Scan for vulnerabilities and track advisories on a defined cadence mitigates Poor configuration management and insecure baseline drift
- strength
- related
- rationale
- Scans surface deviations from secure baselines (missing patches, insecure settings), flagging drift for remediation.
- Cybersecurity Assurance Review tests UC-VULN-01 — Scan for vulnerabilities and track advisories on a defined cadence
- Vulnerability & Patch Management Cycle operates UC-VULN-01 — Scan for vulnerabilities and track advisories on a defined cadence
- UC-VULN-01 — Scan for vulnerabilities and track advisories on a defined cadence maps_to RA-5 — Vulnerability Monitoring and Scanning
- framework
- nist-800-53
- control_id
- RA-5
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-VULN-01 — Scan for vulnerabilities and track advisories on a defined cadence mitigates Exploitation of known, unpatched vulnerabilities
- strength
- primary
- rationale
- Scanning plus advisory subscription identifies known unpatched CVEs and tracks them to closure within severity-based timeframes.