id: "RA-05(02)" title: "Update Vulnerabilities to Be Scanned" family: "RA" family_name: "Risk Assessment" sort_id: "ra-05.02" priority: "P1" implementation_level: "organization" parent: "RA-05" enhancement: True
Statement
Update the system vulnerabilities to be scanned {{ insert: param, ra-05.02_odp.01 }}.
Guidance
Due to the complexity of modern software, systems, and other factors, new vulnerabilities are discovered on a regular basis. It is important that newly discovered vulnerabilities are added to the list of vulnerabilities to be scanned to ensure that the organization can take steps to mitigate those vulnerabilities in a timely manner.
Assessment Objective
the system vulnerabilities to be scanned are updated {{ insert: param, ra-05.02_odp.01 }}.
Procedures addressing vulnerability scanning
assessment report
vulnerability scanning tools and associated configuration documentation
vulnerability scanning results
patch and vulnerability management records
system security plan
other relevant documents or records
Organizational personnel with vulnerability scanning responsibilities
organizational personnel with vulnerability scan analysis responsibilities
organizational personnel with security responsibilities
system/network administrators
Organizational processes for vulnerability scanning
mechanisms/tools supporting and/or implementing vulnerability scanning