Direct implementation supportHigh confidence
Why: The practice is the scan cycle this requirement names: authenticated scanning across the full inventory on a cadence, with known-exploited disclosures triggering off-cycle attention. Its coverage metric — assets scanned over assets inventoried — makes the requirement's usual weak point measurable.
What this does not claim: Supports implementation of the requirement; it does not satisfy it on its own. The requirement covers applications as well as systems, and every asset in the assessed boundary — including network devices, cloud configuration, and whatever the scanner cannot reach — while the practice's coverage claim is only as good as the inventory it scans against. An assessor evaluates actual scope and cadence, not the existence of a scanning program.
Practice-side activities- Run authenticated scans across the full inventory on a defined cadence
- Check the estate against the known-exploited vulnerability catalogue as new entries land
- Measure scan coverage against the asset inventory and explain unscannable assets
Evidence this produces- Scan reports with coverage measured against the inventory
- Off-cycle scan records following major disclosures
- The scan-coverage metric trend over time
Where this holds: Holds for IT estates with an inventory to scan against; weakens wherever the inventory is incomplete, because coverage claims inherit its gaps.
Review status: Technical review complete · Reviewed by inDirectIT practitioner review — CUI security and NIST SP 800-171 engineering · updated 2026-08-06
Partial implementation supportModerate confidence
Why: Where OT systems fall inside the CUI boundary, the practice's advisory correlation — matching vendor and ICS advisories and the known-exploited catalogue against a validated inventory with firmware versions — is vulnerability identification fitted to equipment that active scanning could disrupt.
What this does not claim: May partially address the requirement, and only for OT assets actually within the assessed boundary — most OT sits outside it. The practice deliberately identifies vulnerabilities passively rather than by scanning, so the organization must be able to show an assessor that advisory correlation plus a validated inventory reaches what the requirement's periodic scanning intends; the requirement text does not contemplate control-system constraints, and the argument has to be made, not assumed.
Practice-side activities- Correlate vendor and ICS advisories against the validated inventory, including firmware versions
- Use passive monitoring with vulnerability correlation where active scanning would risk the process
- Record the identification cadence and match every finding to an inventoried device
Evidence this produces- Advisory-to-inventory correlation records
- Passive-monitoring vulnerability findings tied to inventoried devices
- The advisory-to-decision time metric
Where this holds: Production environments with networked control equipment inside a CUI boundary; the relationship does not exist for OT outside the boundary.
Review status: Technical review complete · Reviewed by inDirectIT practitioner review — CUI security and NIST SP 800-171 engineering · updated 2026-08-06