NIST SP 800-53 Rev. 5
SA-15(7)
System and Services Acquisition
enhancement

Automated Vulnerability Analysis

Parent: SA-15

Description

Require the developer of the system, system component, or system service [organization-defined parameter] to: a. Perform an automated vulnerability analysis using [organization-defined parameter]; b. Determine the exploitation potential for discovered vulnerabilities; c. Determine potential risk mitigations for delivered vulnerabilities; and d. Deliver the outputs of the tools and results of the analysis to [organization-defined parameter].

Mapped SPARTA techniques

88 techniques

Cite as SafeMode Space, nist-80053-rev5 SA-15(7).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.