8.8 Management of technical vulnerabilities
Requires information about technical vulnerabilities in the information systems in use to be obtained, the organisation's exposure to them to be evaluated, and appropriate measures to be taken. Older source material sets
5
artefacts
2
held by a system
1
at each review
moderate
to go live
Vulnerability scanner / patch tooling
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Scan results and vulnerability inventory for the period, with authenticated scanning where applicable · Vulnerability scanner / patch tooling
- Records of alternative measures where no patch exists, and the audit log of actions taken · Vulnerability scanner / patch tooling
periodic reviewEvidence produced at each review
- Risk assessment records weighing the vulnerability against the risk of applying the patch, and evidence of testing before deployment · Vulnerability scanner / patch tooling
governing documentDocuments that govern the control
- Defined roles and information sources for vulnerability identification, and the asset scope they cover · Policy repository / GRC workspace
- The defined reaction timeline by severity, and measurement of actual remediation against it · Policy repository / GRC workspace
First move
Start with the 2 of 5 artefacts that already live in a system (Vulnerability scanner / patch tooling); keep the periodic reviews but log each one as a dated record with a named reviewer.
Common gaps auditors find
- Scanning covers the network perimeter and misses internal, cloud, container and application layer exposure
- Remediation timelines defined and routinely breached, with no exception or risk acceptance record
- Unauthenticated scanning only, which understates exposure substantially
- Highest risk systems not prioritised, so remediation follows whatever is easiest to patch
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheet8.7 Protection against malware · 8.9 Configuration management