data.gift
  • Datasets

http://cyfun.data.gift/data/requirement_ID_RA_08_2

http://cyfun.data.gift/data/requirement_ID_RA_08_2
Concept

  • http://cyfun.data.gift/data/CyFun2025

    • External link
    • Internal link
  • http://cyfun.data.gift/data/CyFun2025_delta_IMPORTANT_to_ESSENTIAL

    • External link
    • Internal link
  • http://cyfun.data.gift/data/CyFun2025_ESSENTIAL

    • External link
    • Internal link

  • http://cyfun.data.gift/data/subcategory_ID.RA-08

    • External link
    • Internal link

Properties and relations

Direct links from the subject.

Property Value

type

The subject is an instance of a class.

  • External link
  • Internal link

http://cyfun.data.gift/ontology#Requirement

  • External link
  • Internal link

type

The subject is an instance of a class.

  • External link
  • Internal link

Concept

An idea or notion; a unit of thought.

  • External link
  • Internal link

label

A human-readable name for the subject.

  • External link
  • Internal link

ID.RA-08.2: The organisation shall implement automated mechanisms for disseminating and track- ing remedial measures related to vulnerability information that automatically handles vulnerability data collection, disseminates information, tracks remedial measures, includes reporting and accountability, and enables continuous monitoring.

http://cyfun.data.gift/ontology#requirementId

  • External link
  • Internal link

ID.RA-08.2

http://cyfun.data.gift/ontology#foundIn

  • External link
  • Internal link

http://cyfun.data.gift/data/loc_CyFun2025_Booklet_ESSENTIAL_E_p72

  • External link
  • Internal link

has broader

Relates a concept to a concept that is more general in meaning.

  • External link
  • Internal link

http://cyfun.data.gift/data/subcategory_ID.RA-08

  • External link
  • Internal link

note

A general note, for any purpose.

  • External link
  • Internal link

The goal of this control is to ensure that vulnerability-related information is automatically collected, dissem- inated, tracked, and acted upon through a documented and automated vulnerability management process. This includes enabling continuous monitoring, reporting, and accountability to support timely and effective remediation. To achieve this goal, the organisation should: - Automate Vulnerability Data Collection and Distribution Vulnerability information should be gathered from internal sources (e.g. audits, OT/IT scans) and external sources (e.g. ENISA advisories, threat intelligence feeds, vendor bulletins). This information should be auto- matically distributed to relevant stakeholders using dashboards, alerts, or integrated communication tools. - Track Remediation Actions and Monitor Progress Automated systems should track the implementation of remediation measures such as patching, configura- tion changes, or compensating controls. Progress should be monitored to ensure timely resolution. - Generate Reports and Ensure Accountability Regular reports should be generated to provide visibility into vulnerability status, assigned responsibilities, and remediation progress. These reports should support transparency and management oversight. - Enable Continuous Monitoring Through Automation Automated mechanisms should be in place to continuously monitor for new vulnerabilities and ensure that remediation workflows are updated accordingly. - Evaluate Automation Effectiveness The effectiveness of automation should be assessed regularly to determine improvements in response time, efficiency, and stakeholder awareness. Adjustments should be made if objectives are not met. - Ensure OT-Specific Coverage The automation process should include OT environments, addressing legacy systems, vendor-managed components, and embedded firmware. Coordination with engineering teams may be required for reme- diation in these environments.

note

A general note, for any purpose.

  • External link
  • Internal link

The goal of this control is to ensure that vulnerability-related information is automatically collected, dissem- inated, tracked, and acted upon through a documented and automated vulnerability management process. This includes enabling continuous monitoring, reporting, and accountability to support timely and effective remediation. To achieve this goal, the organisation should: • Automate Vulnerability Data Collection and Distribution Vulnerability information should be gathered from internal sources (e.g. audits, OT/IT scans) and external sources (e.g. ENISA advisories, threat intelligence feeds, vendor bulletins). This information should be auto- matically distributed to relevant stakeholders using dashboards, alerts, or integrated communication tools. • Track Remediation Actions and Monitor Progress Automated systems should track the implementation of remediation measures such as patching, configura- tion changes, or compensating controls. Progress should be monitored to ensure timely resolution. • Generate Reports and Ensure Accountability Regular reports should be generated to provide visibility into vulnerability status, assigned responsibilities, and remediation progress. These reports should support transparency and management oversight. • Enable Continuous Monitoring Through Automation Automated mechanisms should be in place to continuously monitor for new vulnerabilities and ensure that remediation workflows are updated accordingly. • Evaluate Automation Effectiveness The effectiveness of automation should be assessed regularly to determine improvements in response time, efficiency, and stakeholder awareness. Adjustments should be made if objectives are not met. • Ensure OT-Specific Coverage The automation process should include OT environments, addressing legacy systems, vendor-managed components, and embedded firmware. Coordination with engineering teams may be required for reme- diation in these environments.

note

A general note, for any purpose.

  • External link
  • Internal link

<div><p>The goal of this control is to ensure that vulnerability-related information is automatically collected, dissem- inated, tracked, and acted upon through a documented and automated vulnerability management process. This includes enabling continuous monitoring, reporting, and accountability to support timely and effective remediation. To achieve this goal, the organisation should:</p><ul><li>Automate Vulnerability Data Collection and Distribution Vulnerability information should be gathered from internal sources (e.g. audits, OT/IT scans) and external sources (e.g. ENISA advisories, threat intelligence feeds, vendor bulletins). This information should be auto- matically distributed to relevant stakeholders using dashboards, alerts, or integrated communication tools.</li><li>Track Remediation Actions and Monitor Progress Automated systems should track the implementation of remediation measures such as patching, configura- tion changes, or compensating controls. Progress should be monitored to ensure timely resolution.</li><li>Generate Reports and Ensure Accountability Regular reports should be generated to provide visibility into vulnerability status, assigned responsibilities, and remediation progress. These reports should support transparency and management oversight.</li><li>Enable Continuous Monitoring Through Automation Automated mechanisms should be in place to continuously monitor for new vulnerabilities and ensure that remediation workflows are updated accordingly.</li><li>Evaluate Automation Effectiveness The effectiveness of automation should be assessed regularly to determine improvements in response time, efficiency, and stakeholder awareness. Adjustments should be made if objectives are not met.</li><li>Ensure OT-Specific Coverage The automation process should include OT environments, addressing legacy systems, vendor-managed components, and embedded firmware. Coordination with engineering teams may be required for reme- diation in these environments.</li></ul></div>

note

A general note, for any purpose.

  • External link
  • Internal link

The goal of this control is to ensure that vulnerability-related information is automatically collected, dissem- inated, tracked, and acted upon through a documented and automated vulnerability management process. This includes enabling continuous monitoring, reporting, and accountability to support timely and effective remediation. To achieve this goal, the organisation should: - Automate Vulnerability Data Collection and Distribution Vulnerability information should be gathered from internal sources (e.g. audits, OT/IT scans) and external sources (e.g. ENISA advisories, threat intelligence feeds, vendor bulletins). This information should be auto- matically distributed to relevant stakeholders using dashboards, alerts, or integrated communication tools. - Track Remediation Actions and Monitor Progress Automated systems should track the implementation of remediation measures such as patching, configura- tion changes, or compensating controls. Progress should be monitored to ensure timely resolution. - Generate Reports and Ensure Accountability Regular reports should be generated to provide visibility into vulnerability status, assigned responsibilities, and remediation progress. These reports should support transparency and management oversight. - Enable Continuous Monitoring Through Automation Automated mechanisms should be in place to continuously monitor for new vulnerabilities and ensure that remediation workflows are updated accordingly. - Evaluate Automation Effectiveness The effectiveness of automation should be assessed regularly to determine improvements in response time, efficiency, and stakeholder awareness. Adjustments should be made if objectives are not met. - Ensure OT-Specific Coverage The automation process should include OT environments, addressing legacy systems, vendor-managed components, and embedded firmware. Coordination with engineering teams may be required for reme- diation in these environments.

notation

A notation, also known as classification code, is a string of characters such as "T58.5" or "303.4833" used to uniquely identify a concept within the scope of a given concept scheme.

  • External link
  • Internal link

ID.RA-08.2

alternative label

skos:prefLabel, skos:altLabel and skos:hiddenLabel are pairwise disjoint properties.

  • External link
  • Internal link

Automated vulnerability remediation tracking

preferred label

A resource has no more than one value of skos:prefLabel per language tag, and no more than one value of skos:prefLabel without language tag.

  • External link
  • Internal link

The organisation shall implement automated mechanisms for disseminating and track- ing remedial measures related to vulnerability information that automatically handles vulnerability data collection, disseminates information, tracks remedial measures, includes reporting and accountability, and enables continuous monitoring.

is in scheme

Relates a resource (for example a concept) to a concept scheme in which it is included.

  • External link
  • Internal link

http://cyfun.data.gift/data/CyFun2025

  • External link
  • Internal link

is in scheme

Relates a resource (for example a concept) to a concept scheme in which it is included.

  • External link
  • Internal link

http://cyfun.data.gift/data/CyFun2025_delta_IMPORTANT_to_ESSENTIAL

  • External link
  • Internal link

is in scheme

Relates a resource (for example a concept) to a concept scheme in which it is included.

  • External link
  • Internal link

http://cyfun.data.gift/data/CyFun2025_ESSENTIAL

  • External link
  • Internal link

http://cyfun.data.gift/ontology#level

  • External link
  • Internal link

http://cyfun.data.gift/data/level_ESSENTIAL

  • External link
  • Internal link

triple count

The number of triples associated with the subject.

  • External link
  • Internal link

17

in dataset

Specifies the dataset the subject is part of.

  • External link
  • Internal link

http://data.gift/d/datasets/69E8863AA6CE46D9ACD13109

  • External link
  • Internal link

Resultaten 1 - 19 of 19

References

Inverse links to the subject.

Property Subject

http://cyfun.data.gift/ontology#hasRequirement

  • External link
  • Internal link

http://cyfun.data.gift/data/subcategory_ID.RA-08

  • External link
  • Internal link

has narrower

Relates a concept to a concept that is more specific in meaning.

  • External link
  • Internal link

http://cyfun.data.gift/data/subcategory_ID.RA-08

  • External link
  • Internal link

Resultaten 1 - 1 of 1

© 2024 redpencil.io. All rights reserved.