Exploit
What is Exploit?
A piece of software, data, or sequence of commands that takes advantage of a vulnerability in a computer system, application, or network to cause unintended behaviour such as unauthorised access or code execution.
Terms that appear alongside exploit
Each of these is named in at least one of the same controls as exploit. The number is how many controls name both.
- integrity 3 shared controls
- mitre 2 shared controls
- vulnerability 2 shared controls
- audit 2 shared controls
- profiling 2 shared controls
- risk analysis 2 shared controls
Frameworks that govern exploit
What the standards actually require on exploit
Requirements naming exploit across 6 standards, quoted from the control text.
The likelihood of system compromise is frequently assessed when working exploits exist for unmitigated vulnerabilities.
ISM-1921 · The likelihood of system compromise is frequently assessed when working exploits exist for →Assess likelihood for each threat and vulnerability pairing using a defined scale, considering threat source capability, intent, and historical occurrence.
RA-LIKELIHOOD · Risk Analysis: Determine the Likelihood of a Threat Exploiting a Vulnerability →Error Handling. Generate error messages that provide information necessary for corrective actions without revealing information that could be exploited; and Reveal error messages only to [organization-defined]
NIST800-SI-11 · Error Handling. Generate error messages that provide information necessary for corrective actions without revealing information that could be exploited; and Reveal error messages only to [organization-defined] →Operating system generic exploit mitigation e.g. Data Execution Prevention (DEP), Address Space Layout Randomisation (ASLR) and Enhanced Mitigation Experience Toolkit (EMET).
ASD37-09 · OS generic exploit mitigation (Excellent) →Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded
NIST-CSF-ID.RA-04 · Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded →All ML2 requirements plus: Patches or vendor mitigations for office productivity suites, web browsers and their extensions, email clients, PDF software and security products are applied within 48 hours of release when vulnerabilities are critical or working ex...
E8-PATCHAPP-ML3 · Patch Applications (ML3) →Questions people ask about exploit
What is Exploit?
Why is Exploit important for compliance?
Which compliance frameworks address Exploit?
Where can I learn more about Exploit?
See how Exploit applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.