RA-5(1): Update Tool Capability

Control Family:

Risk Assessment


  • Moderate
  • High
Warning icon.

Control is withdrawn in the next version of this control set and incorporated into: RA-5: Vulnerability Monitoring and Scanning.

Control Statement

The organization employs vulnerability scanning tools that include the capability to readily update the information system vulnerabilities to be scanned.

Supplemental Guidance

The vulnerabilities to be scanned need to be readily updated as new vulnerabilities are discovered, announced, and scanning methods developed. This updating process helps to ensure that potential vulnerabilities in the information system are identified and addressed as quickly as possible.