Files
Anthropic-Cybersecurity-Skills/skills/performing-authenticated-scan-with-openvas/references/standards.md
T

2.9 KiB

Standards and References - Authenticated Scanning with OpenVAS

Primary Standards

NIST SP 800-115

NIST SP 800-53 Rev 5 - RA-5

CIS Controls v8 - Control 7

  • Title: Continuous Vulnerability Management
  • URL: https://www.cisecurity.org/controls/continuous-vulnerability-management
  • Sub-controls:
    • 7.1: Establish and maintain a vulnerability management process
    • 7.4: Perform authenticated vulnerability scanning with agents or credentialed scans
    • 7.5: Perform automated vulnerability scans of internal enterprise assets on a quarterly basis

PCI DSS v4.0 - Requirement 11.3

  • Title: External and Internal Vulnerabilities Are Regularly Identified, Prioritized, and Addressed
  • Requirement: Internal vulnerability scans must be performed at least quarterly and after any significant change; authenticated scanning is required for comprehensive assessment

OpenVAS/GVM Technical References

Greenbone Community Edition

GVM Architecture

  • Scanner: openvas-scanner performs the actual vulnerability tests
  • Manager: gvmd manages scan tasks, credentials, targets, and results
  • Web Interface: Greenbone Security Assistant (GSA) provides browser-based management
  • Database: PostgreSQL stores configurations and results
  • Cache: Redis provides high-speed NVT metadata caching

python-gvm Library

GMP Protocol

Compliance Mapping

Framework Control Authenticated Scan Requirement
NIST 800-53 RA-5 Credentialed scanning for host-level assessment
PCI DSS 4.0 11.3.1 Internal vulnerability scanning quarterly
CIS Controls v8 7.4 Authenticated vulnerability scanning
ISO 27001 A.8.8 Technical vulnerability management
HIPAA 164.312(a)(1) Technical safeguards evaluation
SOC 2 CC7.1 Vulnerability identification and remediation