PlumbTrackLive demoGRC Risk System

← control library

Vulnerability Monitoring and Scanning RA-5

Risk Assessment · Low baseline ✗ Not implemented

Status — program-wide

What references this control

No risks name this control in their Framework field yet.

No policies reference it yet.


Link a risk or policy to this control

Attaching adds RA-5 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.

Source: NIST SP 800-53 Rev.5, Risk Assessment family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.

Control guide — plain-English, per NIST SP 800-53

RA-5 (Vulnerability Monitoring and Scanning) requires you to scan the system for known weaknesses on a defined schedule and when new flaws are announced, analyze the results, and remediate or track what you find. CVE (Common Vulnerabilities and Exposures) findings feed the risk picture. It carries into the Moderate baseline.

What good looks like

Framework mapping

How to move it toward Implemented