Skip to content

Vulnerability

What is Vulnerability?

A weakness in a system, application, or process that could be exploited by a threat actor to gain unauthorised access or cause harm. Vulnerabilities can exist in software, hardware, configurations, or procedures.

Information Security

Each of these is named in at least one of the same controls as vulnerability. The number is how many controls name both.

What the standards actually require on vulnerability

Requirements naming vulnerability across 6 standards, quoted from the control text.

Establishing a point of contact such as a CSIRT or PSIRT for receiving and handling vulnerability reports

30111-5.2 · Vulnerability handling team

A vulnerability scanner with an up-to-date vulnerability database is used for vulnerability scanning activities.

ISM-1808 · A vulnerability scanner with an up-to-date vulnerability database is used for vulnerabilit

Expected contents and format of vulnerability reports including technical details

29147-6.2 · Vulnerability report contents

Define, monitor and report vulnerability identification and remediation metrics at set intervals.

CCM-TVM-10 · Vulnerability Management Metrics
FedRAMP High8 controls

Vulnerability Monitoring and Scanning | Breadth and Depth of Coverage. Define the breadth and depth of vulnerability scanning coverage

RA-5(3) · Vulnerability Monitoring and Scanning | Breadth and Depth of Coverage. Define the breadth and depth of vulnerability scanning coverage
CIS Controls v87 controls

Perform automated vulnerability scans of externally-exposed enterprise assets using a SCAP-compliant vulnerability scanning tool. Perform scans on a monthly, or more frequent, basis.

CIS-7.6 · Perform Automated Vulnerability Scans of Externally-Exposed Enterprise Assets

Questions people ask about vulnerability

What is Vulnerability?
A weakness in a system, application, or process that could be exploited by a threat actor to gain unauthorised access or cause harm. Vulnerabilities can exist in software, hardware, configurations, or procedures.
Why is Vulnerability important for compliance?
Vulnerability is a key concept in Information Security. Understanding vulnerability helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Vulnerability?
Vulnerability appears in the requirement text of ISO/IEC 30111:2019, Australian Information Security Manual, ISO/IEC 29147:2018, Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1, FedRAMP High. Across these standards we have identified 64 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Vulnerability?
Explore our compliance framework pages to see how vulnerability applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Vulnerability applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.