| name | SA-15(7)_automated-vulnerability-analysis |
| description | Require the developer of the system, system component, or system service [organization-defined] to: Perform an automated vulnerability analysis using |
| category | configuration |
| version | 5.2.0 |
| author | cyberstrike-official |
| tags | ["nist","sp800-53","rev5","sa-15-7","sa","enhancement"] |
| tech_stack | ["any"] |
| cwe_ids | ["CWE-16"] |
| chains_with | ["RA-5","SA-11"] |
| prerequisites | ["SA-15"] |
| severity_boost | {"RA-5":"Chain with RA-5 for comprehensive security coverage","SA-11":"Chain with SA-11 for comprehensive security coverage"} |
SA-15(7) Automated Vulnerability Analysis
Enhancement of: SA-15
High-Level Description
Family: System and Services Acquisition (SA)
Framework: NIST SP 800-53 Rev 5
Automated tools can be more effective at analyzing exploitable weaknesses or deficiencies in large and complex systems, prioritizing vulnerabilities by severity, and providing recommendations for risk mitigations.
What to Check
How to Test
Step 1: Review Documentation
Examine the System Security Plan (SSP) and related artifacts for SA-15(7) implementation details. Verify the organization has documented how this control is satisfied.
Step 2: Validate Implementation
# For cloud environments, use cloud-audit-mcp tools
# For on-premises, review system configurations directly
# Example: Check if account management policies exist
grep -r "account.management\|access.control" /etc/security/ 2>/dev/null
Step 3: Test Operating Effectiveness
Verify the control is actively functioning, not just documented. Check logs, configurations, and operational evidence.
Tools
| Tool | Purpose | Usage |
|---|
| Manual Review | Documentation and interview-based | N/A |
Remediation Guide
Control Statement
Require the developer of the system, system component, or system service [organization-defined] to:
Perform an automated vulnerability analysis using [organization-defined];
Determine the exploitation potential for discovered vulnerabilities;
Determine potential risk mitigations for delivered vulnerabilities; and
Deliver the outputs of the tools and results of the analysis to [organization-defined].
Implementation Guidance
Automated tools can be more effective at analyzing exploitable weaknesses or deficiencies in large and complex systems, prioritizing vulnerabilities by severity, and providing recommendations for risk mitigations.