1Overview
RA.L2-3.11.2 is the family's five-point requirement and it puts risk assessment into regular technical practice. It requires that the organization scan for vulnerabilities in its systems and applications periodically and when new vulnerabilities affecting them are identified, so that weaknesses are found before they are exploited. It is a five-point requirement with five assessment objectives, and it cannot be deferred on a plan of action.
Vulnerabilities appear constantly, as new flaws are discovered in software already in use, and a system that was secure last month may be exposed today. This control requires vulnerability scanning on two triggers: periodically, at a defined frequency, and additionally whenever new vulnerabilities affecting the systems or applications are identified. Both triggers apply to both systems and applications. Scanning on a schedule catches drift; scanning on new-vulnerability news catches the freshly disclosed flaws that attackers move on quickly. Its five-point weight reflects that unfound vulnerabilities are the openings that attacks exploit.
Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified.
The requirement combines a defined scanning frequency with an event trigger, applied across systems and applications. The five assessment objectives spell this out: define the frequency, then scan systems and scan applications at that frequency, and scan systems and scan applications when new affecting vulnerabilities are identified. Covering both the periodic cadence and the new-vulnerability trigger, for both systems and applications, is what keeps the vulnerability picture current.
2The Assessment Objectives
NIST SP 800-171A decomposes 3.11.2 into five objectives: define the frequency, scan systems and applications on that frequency, and scan systems and applications when new vulnerabilities are identified.
The frequency to scan for vulnerabilities is defined. How often scanning occurs is set.
Vulnerability scans are performed on systems with the defined frequency. Systems are scanned on schedule.
Vulnerability scans are performed on applications with the defined frequency. Applications are scanned on schedule.
Vulnerability scans are performed on systems when new vulnerabilities affecting them are identified. Systems are scanned on new-vulnerability news.
Vulnerability scans are performed on applications when new vulnerabilities affecting them are identified. Applications are scanned on new-vulnerability news.
The five objectives cover the frequency, periodic scanning of systems and applications, and event-triggered scanning of both. The common gaps are at objectives [c] and [e], applications, which are often left out of scanning aimed at infrastructure, and at [d] and [e], the new-vulnerability trigger, which is skipped when scanning is treated as purely periodic. The assessor looks for all five.
3Failure Patterns
The failures are about scanning that is incomplete in coverage or trigger.
Applications not scanned
Scanning that covers infrastructure but omits applications leaves application vulnerabilities unfound. Both systems and applications have to be scanned.
Only periodic, never on disclosure
Scanning only on a schedule misses the window when a newly disclosed vulnerability is most exploited. Scanning when new affecting vulnerabilities are identified catches those.
No defined frequency
Without a defined scanning frequency, periodic scanning has no cadence and tends to lapse. Defining the frequency anchors the periodic scans.
Scans run but not on the systems that matter
Scanning that does not cover the CUI systems and their applications leaves the important assets unexamined. Coverage has to include the systems in scope.
4Ownership
This is an IT and security-owned technical control.
| Role | Responsibility for this control |
|---|---|
| IT and security | Runs vulnerability scans on systems and applications, periodically and on new-vulnerability news. Owns the scan evidence. |
| Security or compliance lead | Defines the scanning frequency and confirms coverage and triggers. |
| Program lead | Reviews scan cadence and retains the scan records. |
5Tooling
The control is delivered by vulnerability scanning on a defined cadence and on new-vulnerability triggers.
| Objectives | Tooling | What it provides |
|---|---|---|
| [a] | Defined scanning frequency | A set cadence for scans. |
| [b], [c] | Vulnerability scanner covering systems and applications | Periodic scanning of both. |
| [d], [e] | New-vulnerability trigger process | Scanning of systems and applications when new flaws are identified. |
The caveat is that coverage has to span systems and applications and both triggers. A scanner run on a schedule but only against infrastructure, or never re-run when a major vulnerability is disclosed, leaves objectives unmet. The assessor examines all five, so the frequency, the periodic scans of both subjects, and the event-triggered scans all have to hold.
6Evidence
The satisfied version of 3.11.2 shows scanning across systems and applications on both triggers.
| Evidence | What it demonstrates |
|---|---|
| Defined scanning frequency | Objective [a]. The scanning cadence. |
| Scan reports for systems and applications | Objectives [b], [c]. Periodic scanning of both. |
| Event-triggered scan records | Objectives [d], [e]. Scanning on new-vulnerability news. |
The evidence should show a defined frequency, periodic scans of systems and applications, and scans triggered by newly identified vulnerabilities. The scan reports across both subjects and both triggers are the clearest demonstration, and because this control cannot sit on a plan of action, the practice has to be real at the time of assessment.
Yesterday's secure system can be today's open one
Vulnerabilities emerge continuously, so this five-point control asks for scanning of both systems and applications, on a defined cadence and whenever new flaws are disclosed. Building complete vulnerability scanning is part of the onsite readiness work this practice does, and it is one of the controls that must be met rather than deferred.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.11.2. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.11.2[a] through 3.11.2[e]. csrc.nist.gov
- 32 CFR 170.24, CMMC Scoring Methodology, listing RA.L2-3.11.2 among the five-point derived security requirements. ecfr.gov