{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Vulnerability & Patch Management","type":"detective"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-ASSET-09","description":"Receive cyber threat intelligence from information-sharing forums and other sources, and identify and record internal and external threats to the organization. Operate a documented channel to receive, analyze, and respond to vulnerability disclosures from internal and external reporters. Track intelligence and disclosures to closure and feed the results into risk assessment and remediation.","details":{"control_category":"administrative","control_type":"detective","domain":"Vulnerability & Patch Management","guidance":[],"members":[{"control_id":"ID.RA-02","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"},{"control_id":"ID.RA-03","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"},{"control_id":"ID.RA-08","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"}],"statement":"Receive cyber threat intelligence from information-sharing forums and other sources, and identify and record internal and external threats to the organization. Operate a documented channel to receive, analyze, and respond to vulnerability disclosures from internal and external reporters. Track intelligence and disclosures to closure and feed the results into risk assessment and remediation.","title":"Receive, analyze, and act on threat and vulnerability intelligence","unified_id":"UC-ASSET-09"},"id":"uc:UC-ASSET-09","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-ASSET-09","sourceIds":["nist-csf-2"],"sourceUrl":null,"title":"UC-ASSET-09 — Receive, analyze, and act on threat and vulnerability intelligence","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3125978e4c4b0254f5023cb92a8b6fea0088eb0478698a6922a5fefd1a5f8a6d","properties":{"rationale":"Threat-intel feeds give early IOC/TTP warning of novel exploits, enabling detection before any signature or patch exists.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-09-911f6a6c.json","sourceId":"uc:UC-ASSET-09","targetDetailPath":"/data/v1/records/risk-vuln-zero-day-a821d603.json","targetId":"risk:vuln-zero-day","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6bfc674faffa0a96cb5119482dee591d0243706b16e033ffdc8301a82b1dffe8","properties":{"rationale":"A coordinated external vulnerability-disclosure channel surfaces exploitable defects that inadequate internal testing missed.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-09-911f6a6c.json","sourceId":"uc:UC-ASSET-09","targetDetailPath":"/data/v1/records/risk-vuln-inadequate-testing-scanning-ee33b888.json","targetId":"risk:vuln-inadequate-testing-scanning","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ab9edc61ab3338cd0b044ce5af4abc6b1acad35b761225fa037da13820b1a99b","properties":{"rationale":"Malware IOCs received via threat intelligence enable detection and blocking of active campaigns.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-09-911f6a6c.json","sourceId":"uc:UC-ASSET-09","targetDetailPath":"/data/v1/records/risk-sdlc-malware-injection-compromise-ec5a8dc4.json","targetId":"risk:sdlc-malware-injection-compromise","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:accb279338b1b6069d45ede587ecdb2ef71585f2f99a56648108fb934cd8ba2a","properties":{},"sourceDetailPath":"/data/v1/records/wf-c13-1ffe161d.json","sourceId":"wf:C13","targetDetailPath":"/data/v1/records/uc-uc-asset-09-911f6a6c.json","targetId":"uc:UC-ASSET-09","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:af4bcf008f3da9c0bd64deb9f178e9ad624c93e745f08197029e8f8ed8cb4c5d","properties":{},"sourceDetailPath":"/data/v1/records/wf-c7-acbef2ee.json","sourceId":"wf:C7","targetDetailPath":"/data/v1/records/uc-uc-asset-09-911f6a6c.json","targetId":"uc:UC-ASSET-09","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:bdeaae7b99fe45243a69fa35d702049c350cad59c9796af0a18b078eff5e1957","properties":{"rationale":"Vulnerability-disclosure/advisory intake surfaces known flaws and feeds remediation, but scanning and patching are the operative defenses against unpatched-CVE exploitation.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-09-911f6a6c.json","sourceId":"uc:UC-ASSET-09","targetDetailPath":"/data/v1/records/risk-vuln-unpatched-known-flaws-c4a6b075.json","targetId":"risk:vuln-unpatched-known-flaws","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c61152abfb9b43a56ce57f765445475272c5a422f0f4e1367f3678cc89212c7f","properties":{"control_id":"ID.RA-02","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-09-911f6a6c.json","sourceId":"uc:UC-ASSET-09","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-id-ra-02-12ef12d3.json","targetId":"ctrl:nist-csf-2:ID.RA-02","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e88bb95cccc59e0134052cce367e578a7ba5d9c4cb5d15c6ca591219d4048bcd","properties":{"control_id":"ID.RA-03","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-09-911f6a6c.json","sourceId":"uc:UC-ASSET-09","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-id-ra-03-1743f396.json","targetId":"ctrl:nist-csf-2:ID.RA-03","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fda32fdda58aae0fe70ea8797a37e2d5398a190824f0abcb1aeb0ca5b1c8b78c","properties":{"control_id":"ID.RA-08","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-09-911f6a6c.json","sourceId":"uc:UC-ASSET-09","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-id-ra-08-9bcf1311.json","targetId":"ctrl:nist-csf-2:ID.RA-08","type":"maps_to"}],"schemaVersion":1}
