Skip to main content

πŸ’Ό SA-15(7) Development Process, Standards, and Tools | Automated Vulnerability Analysis

Description​

Require the developer of the system, system component, or system service [Assignment: organization-defined frequency] to: (a) Perform an automated vulnerability analysis using [Assignment: organization-defined tools]; (b) Determine the exploitation potential for discovered vulnerabilities; (c) Determine potential risk mitigations for delivered vulnerabilities; and (d) Deliver the outputs of the tools and results of the analysis to [Assignment: organization-defined personnel or roles].

Similar​

  • Internal
    • ID: dec-c-d63f353a

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό NIST CSF v2.0 β†’ πŸ’Ό ID.RA-01: Vulnerabilities in assets are identified, validated, and recorded22

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags