Vulnerabilities in assets are identified, validated, and recorded
Parent: ID.RA
Description
No description available.
Mapped SPARTA techniques
4 techniques
Supported by two independent derivations that agree, neither of them SafeMode's invention. Through NIST 800-53: SafeMode's curated mapping records EX-0005.01 against RA-5 Vulnerability Monitoring and Scanning, and CSF 2.0's own crosswalk names that control as an informative reference for ID.RA-01. Through SPARTA: SPARTA's catalog maps EX-0005.01 to countermeasure CM0018 Dynamic Testing, and that countermeasure's own CSF references include ID.RA-01. Recorded as `addresses` rather than `mitigates` because a CSF subcategory states an outcome to be achieved while the underlying control states the mechanism that achieves it, which is the mechanism-versus-mandate ceiling in decisions entry 15.
Supported by two independent derivations that agree, neither of them SafeMode's invention. Through NIST 800-53: SafeMode's curated mapping records EX-0009.03 against CA-7 Continuous Monitoring, and CSF 2.0's own crosswalk names that control as an informative reference for ID.RA-01. Through SPARTA: SPARTA's catalog maps EX-0009.03 to countermeasure CM0008 Security Testing Results; CM0011 Vulnerability Scanning; CM0012 Software Bill of Materials, and that countermeasure's own CSF references include ID.RA-01. Recorded as `addresses` rather than `mitigates` because a CSF subcategory states an outcome to be achieved while the underlying control states the mechanism that achieves it, which is the mechanism-versus-mandate ceiling in decisions entry 15.
Supported by two independent derivations that agree, neither of them SafeMode's invention. Through NIST 800-53: SafeMode's curated mapping records REC-0001 against RA-3 Risk Assessment, and CSF 2.0's own crosswalk names that control as an informative reference for ID.RA-01. Through SPARTA: SPARTA's catalog maps REC-0001 to countermeasure CM0005 Ground-based Countermeasures, and that countermeasure's own CSF references include ID.RA-01. Recorded as `addresses` rather than `mitigates` because a CSF subcategory states an outcome to be achieved while the underlying control states the mechanism that achieves it, which is the mechanism-versus-mandate ceiling in decisions entry 15.
Supported by two independent derivations that agree, neither of them SafeMode's invention. Through NIST 800-53: SafeMode's curated mapping records REC-0008.03 against RA-3 Risk Assessment, and CSF 2.0's own crosswalk names that control as an informative reference for ID.RA-01. Through SPARTA: SPARTA's catalog maps REC-0008.03 to countermeasure CM0005 Ground-based Countermeasures; CM0008 Security Testing Results, and that countermeasure's own CSF references include ID.RA-01. Recorded as `addresses` rather than `mitigates` because a CSF subcategory states an outcome to be achieved while the underlying control states the mechanism that achieves it, which is the mechanism-versus-mandate ceiling in decisions entry 15.
Cross-framework references
Relationships published by the source frameworks themselves, reproduced here with attribution. They are not SafeMode Space mappings and carry no confidence rating of ours.
Cite as SafeMode Space, csf-2-0 ID.RA-01.