PlumbTrackLive demoGRC Risk System

← internal audit

Audit — RA-5 — Vulnerability Monitoring and Scanning

Framework: NIST SP 800-53 Rev.5 RA-5 · Mark each check Pass / Fail / N/A; a Fail is a finding to remediate. · open the item

0 pass · 0 finding(s) · 0 N/A · 0 of 7 checked
Examine Examine the vulnerability scanning schedule and scan logs to confirm scans of systems and hosted applications run at the organization-defined frequency and are also triggered when new significant vulnerabilities are reported (CIS Control 7).
Test Test scan coverage by reconciling the list of scanned targets against the authoritative asset inventory (CIS Controls 1 and 2) to confirm no in-scope hosts, network devices, or applications are missing from scans.
Examine Examine scanner configuration and plugin/feed update records to verify the tool and its vulnerability definitions are updated to current before scans, and that scanning uses standardized naming and scoring (CVE/CVSS, SCAP-capable tooling).
Interview Examine scan configuration or interview the scanning team to confirm authenticated/credentialed scanning is used where technically feasible so vulnerabilities are detected at the host level rather than only from the network perimeter.
Examine Examine remediation tracking (ticketing or POA&M) to verify identified vulnerabilities are remediated within organization-defined timeframes prioritized by risk/severity, and confirm overdue items are escalated.
Test Test remediation effectiveness by selecting a sample of previously reported findings and confirming a follow-up rescan validated that the vulnerability was actually closed (not just marked resolved).
Examine Examine dissemination records to verify scan results and remediation status are shared with organization-defined personnel and are fed back into the risk assessment (RA-3) and remediation prioritization process.