{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"technical","domain":"Vulnerability & Patch Management","type":"detective"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-VULN-01","description":"Run authenticated vulnerability scans across all in-scope systems and applications on a defined cadence — at least quarterly and after significant changes — using tools whose vulnerability feeds are kept current. Subscribe to security advisories and directives from authoritative sources, assess their applicability, and disseminate them to system owners with required actions and completion dates. Validate and record every finding in a central register with severity ratings, and track findings to closure within severity-based timeframes. Share scan results and advisory status with designated security and management roles.","details":{"control_category":"technical","control_type":"detective","domain":"Vulnerability & Patch Management","guidance":[],"members":[{"control_id":"RA-5","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"SI-5","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"ID.RA-01","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"},{"control_id":"500.5","coverage":"partial","delta":"also requires annual penetration testing by a qualified independent party","framework":"nydfs-500","relationship":"intersects_with"}],"statement":"Run authenticated vulnerability scans across all in-scope systems and applications on a defined cadence — at least quarterly and after significant changes — using tools whose vulnerability feeds are kept current. Subscribe to security advisories and directives from authoritative sources, assess their applicability, and disseminate them to system owners with required actions and completion dates. Validate and record every finding in a central register with severity ratings, and track findings to closure within severity-based timeframes. Share scan results and advisory status with designated security and management roles.","title":"Scan for vulnerabilities and track advisories on a defined cadence","unified_id":"UC-VULN-01"},"id":"uc:UC-VULN-01","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-VULN-01","sourceIds":["nist-800-53","nist-csf-2","nydfs-500"],"sourceUrl":null,"title":"UC-VULN-01 — Scan for vulnerabilities and track advisories on a defined cadence","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:365f3878096fc1b1f826e84015aab672b22281d274a9d3fbd8ff07efa0b04831","properties":{"rationale":"Authenticated scans detect exposed ports/services and misconfigured internet-facing systems, enabling correction.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-vuln-01-ec9a46fe.json","sourceId":"uc:UC-VULN-01","targetDetailPath":"/data/v1/records/risk-config-internet-exposed-misconfig-61b3613a.json","targetId":"risk:config-internet-exposed-misconfig","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4fd2a8dbab21276b567ca1ee445117f105f29d7df458b8a73cf90c90b40b217c","properties":{"control_id":"500.5","coverage":"partial","delta":"also requires annual penetration testing by a qualified independent party","framework":"nydfs-500","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"23 NYCRR 500, Second Amendment"},"sourceDetailPath":"/data/v1/records/uc-uc-vuln-01-ec9a46fe.json","sourceId":"uc:UC-VULN-01","targetDetailPath":"/data/v1/records/ctrl-nydfs-500-500-5-986f2983.json","targetId":"ctrl:nydfs-500:500.5","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:50d27a47969af98dff31c09db66262b6fbdb5555eff75ecfdd2ebd1398b99311","properties":{"control_id":"SI-5","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-vuln-01-ec9a46fe.json","sourceId":"uc:UC-VULN-01","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-si-5-ab6c2a64.json","targetId":"ctrl:nist-800-53:SI-5","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5212df51e6670c6da8efc7b621801d9435975211885acdb291a90fbb36249be4","properties":{"control_id":"ID.RA-01","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-vuln-01-ec9a46fe.json","sourceId":"uc:UC-VULN-01","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-id-ra-01-190d1f99.json","targetId":"ctrl:nist-csf-2:ID.RA-01","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:57219d4c9090d24c46a3958113a962c179d5e2d2e2cfa13ac16a857ef447fa1e","properties":{"rationale":"Authenticated scans on a defined cadence are the operative control against absent or irregular vulnerability scanning.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-vuln-01-ec9a46fe.json","sourceId":"uc:UC-VULN-01","targetDetailPath":"/data/v1/records/risk-vuln-inadequate-testing-scanning-ee33b888.json","targetId":"risk:vuln-inadequate-testing-scanning","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6bd27af7de8c37306c757455fc856aa1a73c98fc45fc7ff859d7b45306ca6dab","properties":{"rationale":"Scans surface deviations from secure baselines (missing patches, insecure settings), flagging drift for remediation.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-vuln-01-ec9a46fe.json","sourceId":"uc:UC-VULN-01","targetDetailPath":"/data/v1/records/risk-config-poor-baseline-drift-2dd66324.json","targetId":"risk:config-poor-baseline-drift","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9beee782eb85c483af1b7bd330b68dec1a6387a7ffe086e621bbd4ce8e43e9f6","properties":{},"sourceDetailPath":"/data/v1/records/wf-a1-f09c8201.json","sourceId":"wf:A1","targetDetailPath":"/data/v1/records/uc-uc-vuln-01-ec9a46fe.json","targetId":"uc:UC-VULN-01","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:aac289b08fe5983f3c59bfa0cda25a4360ae1fa98294e7da01c6dcdb294c9564","properties":{},"sourceDetailPath":"/data/v1/records/wf-c13-1ffe161d.json","sourceId":"wf:C13","targetDetailPath":"/data/v1/records/uc-uc-vuln-01-ec9a46fe.json","targetId":"uc:UC-VULN-01","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d3ddb46b94f7218b46cefa4bf8a2da9f206a1e22fb702c845137773af6322277","properties":{"control_id":"RA-5","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-vuln-01-ec9a46fe.json","sourceId":"uc:UC-VULN-01","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ra-5-7e761aee.json","targetId":"ctrl:nist-800-53:RA-5","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d977b3520904eaeb456c31700f20fd95ee11885a82f3b2c4404661aba5297720","properties":{"rationale":"Scanning plus advisory subscription identifies known unpatched CVEs and tracks them to closure within severity-based timeframes.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-vuln-01-ec9a46fe.json","sourceId":"uc:UC-VULN-01","targetDetailPath":"/data/v1/records/risk-vuln-unpatched-known-flaws-c4a6b075.json","targetId":"risk:vuln-unpatched-known-flaws","type":"mitigates"}],"schemaVersion":1}
