Vulnerability Scanning
What is Vulnerability Scanning?
Automated testing that identifies known security weaknesses in systems, networks, and applications by comparing them against databases of known vulnerabilities.
Terms that appear alongside vulnerability scanning
Each of these is named in at least one of the same controls as vulnerability scanning. The number is how many controls name both.
- vulnerability 40 shared controls
- remediation 9 shared controls
- patch management 8 shared controls
- penetration testing 8 shared controls
- nist 6 shared controls
- configuration management 5 shared controls
- software bill of materials 5 shared controls
- owasp 5 shared controls
Frameworks that govern vulnerability scanning
What the standards actually require on vulnerability scanning
Requirements naming vulnerability scanning across 6 standards, quoted from the control text.
Vulnerability Monitoring and Scanning | Breadth and Depth of Coverage. Define the breadth and depth of vulnerability scanning coverage
RA-5(3) · Vulnerability Monitoring and Scanning | Breadth and Depth of Coverage. Define the breadth and depth of vulnerability scanning coverage →Vulnerability Monitoring and Scanning | Breadth and Depth of Coverage. Define the breadth and depth of vulnerability scanning coverage
RA-5(3) · Vulnerability Monitoring and Scanning | Breadth and Depth of Coverage. Define the breadth and depth of vulnerability scanning coverage →Scan for vulnerabilities in systems and applications at a defined cadence and remediate identified vulnerabilities within risk-based timeframes.
171-RA-2 · Vulnerability Scanning and Remediation →Run regular authenticated vulnerability scans of SWIFT systems and feed findings into a tracked remediation process.
CSCF-2.7 · Vulnerability Scanning →Vulnerability scanning and management. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: Risk Assessment & Management.
BSI-14 · Vulnerability scanning and management →Vulnerability scanning and management. Implements CyFun ID.RA-1 / DE.CM-8: vulnerability scans are performed and identified vulnerabilities are managed to remediation.
BE-CF-14 · Vulnerability scanning and management →Questions people ask about vulnerability scanning
What is Vulnerability Scanning?
Why is Vulnerability Scanning important for compliance?
Which compliance frameworks address Vulnerability Scanning?
Where can I learn more about Vulnerability Scanning?
See how Vulnerability Scanning applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.