TVM-07: Are processes, procedures, and technical measures defined, implemented, and
evaluated for vulnerability detection on organizationally managed assets at least
monthly?
The integrated TVM system should track vulnerabilities to closure and report them to build oversight of residual risks. Furthermore, the system should retain information that can be reused in future remediation activities.
Organizations should consider establishing an external-facing vulnerability disclosure program to allow external parties to communicate detected vulnerabilities.
Control implemented
Control ownership
Description
Define, implement and evaluate processes, procedures and technical
measures for the detection of vulnerabilities on organizationally managed assets
at least monthly.