NIST CSF 2.0 · derived mapping target
ID.RA-01Vulnerabilities identified and recorded
Find weaknesses in your assets, confirm they are real, and record them so they can be tracked and fixed. Unrecorded vulnerabilities tend to be forgotten.
Mapping at a glance
ID.RA-01Vulnerabilities identified and recordedNIST CSF 2.0
ID.RA-01 is covered by 21 Sekit CSF controls. +16 more in the table below. Open in the full graph →
Mapped from the Sekit CSF
The Sekit controls that cover this requirement, lens by lens.
RCF-0007Risk assessment · PolicyRCF-0008Risk assessment · ProcessRCF-0009Risk assessment · TechnicalRCF-0118Threat modeling · PolicyRCF-0119Threat modeling · ProcessRCF-0120Threat modeling · TechnicalRCF-0154Patch management · PolicyRCF-0155Patch management · ProcessRCF-0156Patch management · TechnicalRCF-0217Vulnerability scanning · PolicyRCF-0218Vulnerability scanning · ProcessRCF-0219Vulnerability scanning · TechnicalRCF-0226Baseline compliance · PolicyRCF-0227Baseline compliance · ProcessRCF-0228Baseline compliance · TechnicalRCF-0232Exposure management · PolicyRCF-0233Exposure management · ProcessRCF-0234Exposure management · TechnicalRCF-0355Privacy risk assessments (DPIA) · PolicyRCF-0356Privacy risk assessments (DPIA) · ProcessRCF-0357Privacy risk assessments (DPIA) · Technical
ISO/IEC 27001:2022 counterparts
Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.
ISO/IEC 42001:2023 — Annex A counterparts
Cyber Essentials counterparts
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
Patch management report
The proof that security updates are applied on time across devices and systems, with tracking of what is still outstanding.
From the Sekit evidence catalog
Related controls
Via the shared Sekit CSF topic, not the framework's own index.
Ask Sekura: “What evidence proves ID.RA-01?”
Also via MCP, free with account