id: "RA-05(10)" title: "Correlate Scanning Information" family: "RA" family_name: "Risk Assessment" sort_id: "ra-05.10" priority: "P1" implementation_level: "organization" parent: "RA-05" enhancement: True
Statement
Correlate the output from vulnerability scanning tools to determine the presence of multi-vulnerability and multi-hop attack vectors.
Guidance
An attack vector is a path or means by which an adversary can gain access to a system in order to deliver malicious code or exfiltrate information. Organizations can use attack trees to show how hostile activities by adversaries interact and combine to produce adverse impacts or negative consequences to systems and organizations. Such information, together with correlated data from vulnerability scanning tools, can provide greater clarity regarding multi-vulnerability and multi-hop attack vectors. The correlation of vulnerability scanning information is especially important when organizations are transitioning from older technologies to newer technologies (e.g., transitioning from IPv4 to IPv6 network protocols). During such transitions, some system components may inadvertently be unmanaged and create opportunities for adversary exploitation.
Assessment Objective
the output from vulnerability scanning tools is correlated to determine the presence of multi-vulnerability and multi-hop attack vectors.
Risk assessment policy
procedures addressing vulnerability scanning
risk assessment
vulnerability scanning tools and techniques documentation
vulnerability scanning results
vulnerability management records
audit records
event/vulnerability correlation logs
system security plan
other relevant documents or records
Organizational personnel with vulnerability scanning responsibilities
organizational personnel with vulnerability scan analysis responsibilities
organizational personnel with security responsibilities
Organizational processes for vulnerability scanning
mechanisms/tools supporting and/or implementing vulnerability scanning
mechanisms implementing the correlation of vulnerability scan results