Require the developer of the system, system component, or system service frequency to: Perform an automated vulnerability analysis using tools; Determine the exploitation potential for discovered vulnerabilities; Determine potential risk mitigations for delivered vulnerabilities; and Deliver the outputs of the tools and results of the analysis to personnel or roles.
Automated tools can be more effective at analyzing exploitable weaknesses or deficiencies in large and complex systems, prioritizing vulnerabilities by severity, and providing recommendations for risk mitigations.
the developer of the system, system component, or system service is required to perform automated vulnerability analysis frequency using tools; the developer of the system, system component, or system service is required to determine the exploitation potential for discovered vulnerabilities frequency; the developer of the system, system component, or system service is required to determine potential risk mitigations frequency for delivered vulnerabilities; the developer of the system, system component, or system service is required to deliver the outputs of the tools and results of the analysis frequency to personnel or roles.
No cross-framework mappings available