id: "RA-05(10)" title: "Correlate Scanning Information" family: "RA" family_name: "Risk Assessment" sort_id: "ra-05.10" priority: "P1" implementation_level: "organization" parent: "RA-05" enhancement: True


Statement

Correlate the output from vulnerability scanning tools to determine the presence of multi-vulnerability and multi-hop attack vectors.

Guidance

An attack vector is a path or means by which an adversary can gain access to a system in order to deliver malicious code or exfiltrate information. Organizations can use attack trees to show how hostile activities by adversaries interact and combine to produce adverse impacts or negative consequences to systems and organizations. Such information, together with correlated data from vulnerability scanning tools, can provide greater clarity regarding multi-vulnerability and multi-hop attack vectors. The correlation of vulnerability scanning information is especially important when organizations are transitioning from older technologies to newer technologies (e.g., transitioning from IPv4 to IPv6 network protocols). During such transitions, some system components may inadvertently be unmanaged and create opportunities for adversary exploitation.

Assessment Objective

the output from vulnerability scanning tools is correlated to determine the presence of multi-vulnerability and multi-hop attack vectors.

Risk assessment policy

procedures addressing vulnerability scanning

risk assessment

vulnerability scanning tools and techniques documentation

vulnerability scanning results

vulnerability management records

audit records

event/vulnerability correlation logs

system security plan

other relevant documents or records

Organizational personnel with vulnerability scanning responsibilities

organizational personnel with vulnerability scan analysis responsibilities

organizational personnel with security responsibilities

Organizational processes for vulnerability scanning

mechanisms/tools supporting and/or implementing vulnerability scanning

mechanisms implementing the correlation of vulnerability scan results