unified

UC-VULN-01 — Scan for vulnerabilities and track advisories on a defined cadence

Run authenticated vulnerability scans across all in-scope systems and applications on a defined cadence — at least quarterly and after significant changes — using tools whose vulnerability feeds are kept current. Subscribe to security advisories and directives from authoritative sources, assess their applicability, and disseminate them to system owners with required actions and completion dates. Validate and record every finding in a central register with severity ratings, and track findings to closure within severity-based timeframes. Share scan results and advisory status with designated security and management roles.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
Vulnerability & Patch Management
type
detective
category
technical

Details

unified_id
UC-VULN-01
title
Scan for vulnerabilities and track advisories on a defined cadence
statement
Run authenticated vulnerability scans across all in-scope systems and applications on a defined cadence — at least quarterly and after significant changes — using tools whose vulnerability feeds are kept current. Subscribe to security advisories and directives from authoritative sources, assess their applicability, and disseminate them to system owners with required actions and completion dates. Validate and record every finding in a central register with severity ratings, and track findings to closure within severity-based timeframes. Share scan results and advisory status with designated security and management roles.
domain
Vulnerability & Patch Management
control_type
detective
control_category
technical
members
  • framework
    nist-800-53
    control_id
    RA-5
    coverage
    full
    relationship
    superset_of
  • framework
    nist-800-53
    control_id
    SI-5
    coverage
    full
    relationship
    superset_of
  • framework
    nist-csf-2
    control_id
    ID.RA-01
    coverage
    full
    relationship
    superset_of
  • framework
    nydfs-500
    control_id
    500.5
    coverage
    partial
    delta
    also requires annual penetration testing by a qualified independent party
    relationship
    intersects_with
guidance

    Source

    No record-specific source URL is provided.

    Connections