NIST SP 800-53 Rev. 5
RA-5
Risk Assessment

Vulnerability Monitoring and Scanning

Description

a. Monitor and scan for vulnerabilities in the system and hosted applications [organization-defined parameter] and when new vulnerabilities potentially affecting the system are identified and reported; b. Employ vulnerability monitoring tools and techniques that facilitate interoperability among tools and automate parts of the vulnerability management process by using standards for: c. Analyze vulnerability scan reports and results from vulnerability monitoring; d. Remediate legitimate vulnerabilities [organization-defined parameter] in accordance with an organizational assessment of risk; e. Share information obtained from the vulnerability monitoring process and control assessments with [organization-defined parameter] to help eliminate similar vulnerabilities in other systems; and f. Employ vulnerability monitoring tools that include the capability to readily update the vulnerabilities to be scanned.

Mapped SPARTA techniques

90 techniques

Cross-framework references

Relationships published by the source frameworks themselves, reproduced here with attribution. They are not SafeMode Space mappings and carry no confidence rating of ours.

Cite as SafeMode Space, nist-80053-rev5 RA-5.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.