9.2.
Vulnerability Analysis
Objective:
Recommended Control 1:
Recommended Control 2:
Recommended Control 3:
Exploitable information system weaknesses can be identified by
vulnerability analyses and inform risks to systems
Agencies should implement a vulnerability analysis strategy by:
monitoring public domain information about new
vulnerabilities in operating systems and application
software
considering the use of automated tools to perform
vulnerability assessments on systems in a controlled
manner
running manual checks against system configurations to
ensure that only allowed services are active and that
disallowed services are prevented
using security checklists for operating systems and common
applications
examining any significant incidents on the agency’s systems
Agencies should conduct vulnerability assessments in order to
establish a baseline:
before a system is first used
after any significant incident
after a significant change to the system
after changes to standards, policies and guidelines
as specified by an ITSM or the system owner
Agencies should analyse and treat all vulnerabilities and
subsequent security risks to their systems identified during a
vulnerability assessment
Vulnerabilities may be unintentionally introduced and new vulnerabilities are constantly identified,
presenting ongoing risks to information systems security.
Vulnerabilities may occur as a result of poorly designed or implemented information security
practices, accidental activities or malicious activities, and not just as the result of a technical issue.
A baseline or known point of origin is the basis of any comparison and allows measurement of
changes and improvements when further information security monitoring activities are conducted.
38