NIST 800-53 r5 · Controls catalogue · Family RA
RA-5Vulnerability Monitoring and Scanning
Monitor and scan for vulnerabilities in the system and hosted applications {{ insert: param, ra-5_prm_1 }} and when new vulnerabilities potentially affecting the system are identified and reported; Employ vulnerability monitoring tools and techniques that facilitate interoperability among tools and automate parts of the vulnerability management process by using standards for: Enumerating platforms, software flaws, and improper configurations; Formatting checklists and test procedures; and Measuring vulnerability impact; Analyze vulnerability scan reports and results from vulnerability monitoring; Remediate legitimate vulnerabilities {{ insert: param, ra-05_odp.03 }} in accordance with an organizational assessment of risk; Share information obtained from the vulnerability monitoring process and control assessments with {{ insert: param, ra-05_odp.04 }} to help eliminate similar vulnerabilities in other systems; and Employ vulnerability monitoring tools that include the capability to readily update the vulnerabilities to be scanned.
Last updated: 22 August 2026 07:11 UTC
Implementations targeting this control (0)
- No implementations targeting this control yet.
ATT&CK techniques this control mitigates (107)
- T1011.001 Exfiltration Over Bluetooth Exfiltration
- T1021.001 Remote Desktop Protocol Lateral Movement
- T1021.003 Distributed Component Object Model Lateral Movement
- T1021.004 SSH Lateral Movement
- T1021.005 VNC Lateral Movement
- T1021.006 Windows Remote Management Lateral Movement
- T1046 Network Service Discovery Discovery
- T1047 Windows Management Instrumentation Execution
- T1052 Exfiltration Over Physical Medium Exfiltration
- T1052.001 Exfiltration over USB Exfiltration
- T1053 Scheduled Task/Job Execution, Persistence, Privilege Escalation
- T1053.002 At Execution, Persistence, Privilege Escalation
- T1053.003 Cron Execution, Persistence, Privilege Escalation
- T1053.005 Scheduled Task Execution, Persistence, Privilege Escalation
- T1059 Command and Scripting Interpreter Execution
- T1059.001 PowerShell Execution
- T1059.005 Visual Basic Execution
- T1059.007 JavaScript Execution
- T1068 Exploitation for Privilege Escalation Privilege Escalation
- T1078 Valid Accounts Stealth, Persistence, Privilege Escalation, Initial Access
- T1091 Replication Through Removable Media Lateral Movement, Initial Access
- T1092 Communication Through Removable Media Command And Control
- T1098.004 SSH Authorized Keys Persistence, Privilege Escalation
- T1127 Trusted Developer Utilities Proxy Execution Stealth, Execution
- T1127.001 MSBuild Stealth, Execution
- T1127.002 ClickOnce Stealth, Execution
- T1133 External Remote Services Persistence, Initial Access
- T1137 Office Application Startup Persistence
- T1137.001 Office Template Macros Persistence
- T1176 Software Extensions Persistence
- T1190 Exploit Public-Facing Application Initial Access
- T1195 Supply Chain Compromise Initial Access
- T1195.001 Compromise Software Dependencies and Development Tools Initial Access
- T1195.002 Compromise Software Supply Chain Initial Access
- T1204.003 Malicious Image Execution
- T1210 Exploitation of Remote Services Lateral Movement
- T1211 Exploitation for Stealth Stealth
- T1212 Exploitation for Credential Access Credential Access
- T1213 Data from Information Repositories Collection
- T1213.001 Confluence Collection
- T1213.002 Sharepoint Collection
- T1213.003 Code Repositories Collection
- T1213.005 Messaging Applications Collection
- T1218 System Binary Proxy Execution Stealth
- T1218.003 CMSTP Stealth
- T1218.004 InstallUtil Stealth
- T1218.005 Mshta Stealth
- T1218.008 Odbcconf Stealth
- T1218.009 Regsvcs/Regasm Stealth
- T1218.012 Verclsid Stealth
Weaknesses this control addresses (9)AI-assisted
CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.
| CWE | Name | CVEs | Why this control addresses it |
|---|---|---|---|
CWE-284 | Improper Access Control | 6,900+ | Scans identify improper access control implementations and missing protections on system resources. |
CWE-306 | Missing Authentication for Critical Function | 3,300+ | Tools routinely check for missing authentication on critical functions and exposed interfaces. |
CWE-732 | Incorrect Permission Assignment for Critical Resource | 1,900+ | Permission and ACL misconfigurations on critical resources are standard findings in automated scans. |
CWE-327 | Use of a Broken or Risky Cryptographic Algorithm | 700+ | Scanners flag use of broken or weak cryptographic algorithms via known-vulnerability databases. |
CWE-311 | Missing Encryption of Sensitive Data | 500+ | Monitoring detects missing encryption of sensitive data in storage or transit configurations. |
CWE-1188 | Initialization of a Resource with an Insecure Default | 300+ | Scans detect resources initialized with insecure defaults that create exploitable conditions. |
CWE-521 | Weak Password Requirements | 300+ | Vulnerability scans assess password policies and weak credential requirements against benchmarks. |
CWE-15 | External Control of System or Configuration Setting | 76 | Vulnerability scanners directly detect externally controllable or misconfigured settings using standardized checklists. |
CWE-1104 | Use of Unmaintained Third Party Components | 26 | Regular scanning with updatable vulnerability feeds directly identifies unmaintained third-party components. |
Top CVEs where this control is the strongest mitigation
| CVE | Risk | CVSS | EPSS | Match |
|---|---|---|---|---|
CVE-2024-10395 UPD | 6.4 | 8.6 | 0.0031 | good |
CVE-2026-5928 UPD | 5.8 | 7.5 | 0.0037 | good |
CVE-2025-20359 UPD | 5.1 | 6.5 | 0.0039 | good |
CVE-2025-32050 UPD | 4.8 | 5.9 | 0.0072 | good |
CVE-2024-25629 UPD | 3.6 | 4.4 | 0.0035 | good |
CVE-2026-44108 | 7.3 | 9.8 | 0.0046 | partial |
CVE-2026-14169 | 6.0 | 8.1 | 0.0029 | partial |
CVE-2025-31485 UPD | 5.9 | 7.5 | 0.0057 | partial |
CVE-2026-45033 UPD | 5.8 | 7.8 | 0.0035 | partial |
CVE-2026-35637 | 5.6 | 7.3 | 0.0025 | partial |
CVE-2025-0150 UPD | 5.5 | 7.1 | 0.0047 | partial |
CVE-2026-35627 | 5.2 | 6.5 | 0.0045 | partial |
CVE-2026-35652 | 5.2 | 6.5 | 0.0042 | partial |
CVE-2024-24853 UPD | 5.0 | 7.2 | 0.0023 | partial |
CVE-2026-35636 | 5.0 | 6.5 | 0.0026 | partial |
CVE-2024-30410 UPD | 4.5 | 5.8 | 0.0036 | partial |
CVE-2024-30389 UPD | 4.5 | 5.8 | 0.0036 | partial |
CVE-2026-35640 | 4.5 | 5.3 | 0.0044 | partial |
CVE-2024-35229 UPD | 4.4 | 5.3 | 0.0040 | partial |
CVE-2025-55114 UPD | 4.4 | 5.3 | 0.0039 | partial |
CVE-2025-9904 UPD | 4.4 | 5.3 | 0.0036 | partial |
CVE-2026-43002 UPD | 4.4 | 5.3 | 0.0037 | partial |
CVE-2026-67217 | 4.3 | 5.3 | 0.0025 | partial |
CVE-2021-47688 UPD | 4.2 | 5.7 | 0.0016 | partial |
CVE-2024-45157 UPD | 4.0 | 5.1 | 0.0024 | partial |