# RA-05 Vulnerability Monitoring and Scanning — NIST 800-53 Rev5 control

> FedRAMP Consolidated Rules for 2026 v2026.07.14.01 · updated 2026-07-14
> Canonical page: /control/ra-5

Canonical id: `ra-5` · family `RA`

> a. Monitor and scan for vulnerabilities in the system and hosted applications [organization-defined frequency and/or randomly in accordance with organization-defined process] and when new vulnerabilities potentially affecting the system are identified and reported; b. Employ vulnerability monitoring tools and techniques that facilitate interoperability among tools and automate parts of the vulnerability management process by using standards for: 1. Enumerating platforms, software flaws, and improper configurations; 2. Formatting checklists and test procedures; and 3. Measuring vulnerability impact; c. Analyze vulnerability scan reports and results from vulnerability monitoring; d. Remediate legitimate vulnerabilities [response times] in accordance with an organizational assessment of risk; e. Share information obtained from the vulnerability monitoring process and control assessments with [personnel or roles] to help eliminate similar vulnerabilities in other systems; and f. Employ vulnerability monitoring tools that include the capability to readily update the vulnerabilities to be scanned.

_Control title and statement: NIST SP 800-53 Rev5 catalog (the pinned commit is in `/api` under `control_text`). The FedRAMP rules reference these controls by id only; everything below is what FedRAMP says about this id._

## Rev5 baseline membership

- certification class B (in the annual independent assessment)
- certification class C (in the annual independent assessment)
- certification class D (in the annual independent assessment)

## Key Security Indicators that reach it

- `KSI-SCR-MON` — Monitoring Supply Chain Risk (Supply Chain Risk)
  Third party software information resources are automatically monitored for upstream vulnerabilities using mechanisms that may include contractual notification requirements or active monitoring services.

## FedRAMP guidance

{
  "guidance": [
    "Follow the FedRAMP Vulnerability Detection and Response and Vulnerability Evaluation and Reporting rules."
  ]
}

## Annual independent assessment

In the annual assessment subset for class B, C, D.
