CIS Controls v8 · Control 7: Continuous Vulnerability Management
7.1 Establish and maintain a vulnerability management process
Establish and maintain a documented vulnerability management process for enterprise assets.
Mapped across 10 provisions
Equivalent and related requirements in other frameworks and regulations.
- ISO 27001EquivalentOfficial mapping
Source: CIS Controls v8 / ISO/IEC 27001
A.8.8 Management of technical vulnerabilitiesVulnerability management
- NIST CSF 2.0EquivalentOfficial mapping
Source: CIS Controls v8 / NIST CSF 2.0
ID.RA-01 Vulnerabilities identified and recordedVulnerability management
- Cyber EssentialsEquivalentCuratedCE-5 Security update management
Vulnerability management
- Essential EightEquivalentCuratedE8-1 Patch applications
Vulnerability management
- Essential EightEquivalentCuratedE8-2 Patch operating systems
Vulnerability management
- GLBAPartialCurated§314.4(d) Regularly test or monitor safeguards
Vulnerability management
- NIST 800-171EquivalentCurated3.11.2 Scan for vulnerabilities
Vulnerability management
- NIST 800-53EquivalentCuratedRA-5 Vulnerability monitoring and scanning
Vulnerability management
- PCI DSSEquivalentCuratedReq. 11 Test security of systems and networks regularly
Vulnerability management
- SOC 2EquivalentCuratedCC7.1 Vulnerability detection and monitoring
Vulnerability management