Cyber Resilience

NIST 800-53 r5 · Controls catalogue · Family RA

RA-5Vulnerability Monitoring and Scanning

Monitor and scan for vulnerabilities in the system and hosted applications {{ insert: param, ra-5_prm_1 }} and when new vulnerabilities potentially affecting the system are identified and reported; Employ vulnerability monitoring tools and techniques that facilitate interoperability among tools and automate parts of the vulnerability management process by using standards for: Enumerating platforms, software flaws, and improper configurations; Formatting checklists and test procedures; and Measuring vulnerability impact; Analyze vulnerability scan reports and results from vulnerability monitoring; Remediate legitimate vulnerabilities {{ insert: param, ra-05_odp.03 }} in accordance with an organizational assessment of risk; Share information obtained from the vulnerability monitoring process and control assessments with {{ insert: param, ra-05_odp.04 }} to help eliminate similar vulnerabilities in other systems; and Employ vulnerability monitoring tools that include the capability to readily update the vulnerabilities to be scanned.

Last updated: 22 August 2026 07:11 UTC

Implementations targeting this control (0)

ATT&CK techniques this control mitigates (107)

Weaknesses this control addresses (9)AI-assisted

CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.

CWE Name CVEs Why this control addresses it
CWE-284Improper Access Control6,900+Scans identify improper access control implementations and missing protections on system resources.
CWE-306Missing Authentication for Critical Function3,300+Tools routinely check for missing authentication on critical functions and exposed interfaces.
CWE-732Incorrect Permission Assignment for Critical Resource1,900+Permission and ACL misconfigurations on critical resources are standard findings in automated scans.
CWE-327Use of a Broken or Risky Cryptographic Algorithm700+Scanners flag use of broken or weak cryptographic algorithms via known-vulnerability databases.
CWE-311Missing Encryption of Sensitive Data500+Monitoring detects missing encryption of sensitive data in storage or transit configurations.
CWE-1188Initialization of a Resource with an Insecure Default300+Scans detect resources initialized with insecure defaults that create exploitable conditions.
CWE-521Weak Password Requirements300+Vulnerability scans assess password policies and weak credential requirements against benchmarks.
CWE-15External Control of System or Configuration Setting76Vulnerability scanners directly detect externally controllable or misconfigured settings using standardized checklists.
CWE-1104Use of Unmaintained Third Party Components26Regular scanning with updatable vulnerability feeds directly identifies unmaintained third-party components.

Top CVEs where this control is the strongest mitigation

CVE Risk CVSS EPSS Match
CVE-2024-10395 6.48.60.0031good
CVE-2026-5928 5.87.50.0037good
CVE-2025-20359 5.16.50.0039good
CVE-2025-32050 4.85.90.0072good
CVE-2024-25629 3.64.40.0035good
CVE-2026-441087.39.80.0046partial
CVE-2026-141696.08.10.0029partial
CVE-2025-31485 5.97.50.0057partial
CVE-2026-45033 5.87.80.0035partial
CVE-2026-356375.67.30.0025partial
CVE-2025-0150 5.57.10.0047partial
CVE-2026-356275.26.50.0045partial
CVE-2026-356525.26.50.0042partial
CVE-2024-24853 5.07.20.0023partial
CVE-2026-356365.06.50.0026partial
CVE-2024-30410 4.55.80.0036partial
CVE-2024-30389 4.55.80.0036partial
CVE-2026-356404.55.30.0044partial
CVE-2024-35229 4.45.30.0040partial
CVE-2025-55114 4.45.30.0039partial
CVE-2025-9904 4.45.30.0036partial
CVE-2026-43002 4.45.30.0037partial
CVE-2026-672174.35.30.0025partial
CVE-2021-47688 4.25.70.0016partial
CVE-2024-45157 4.05.10.0024partial

Other controls in family RA

RA-1 RA-10 RA-2 RA-3 RA-4 RA-6 RA-7 RA-8 RA-9