RA-5 Vulnerability Scanning
Description
This Control addresses how the university monitors and scans for security vulnerabilities in information resources to prevent inappropriate or unauthorized access to information systems.
Applicability
- A Unit head, or designee, will ensure that all information resources that connect to the University’s network undergo periodic security vulnerability assessments conducted centrally by the University's Technology Services.
Implementation
-
1A vulnerability assessment may include assessment(s) of any of the following information resources:
-
2The Technology Services security team is authorized to conduct security vulnerability and network scanning of devices attached to the University network on a periodic basis, or when significant new vulnerabilities potentially affecting the system are identified and reported. Information gathered from such scans will be used for assessing and managing security, which includes:
- 2.1Notifying owners/custodians of vulnerabilities,
- 2.2Identifying incorrectly configured systems,
- 2.3Assessing vulnerability impact and overall risk to the University,
- 2.4Taking necessary actions to reduce risk to the University,
- 2.5Responding to cybersecurity incidents,
- 2.6Validating firewall access requests, and
- 2.7Gathering network census data.
-
3Coordinate with Texas A&M System to establish a public reporting channel for receiving reports of vulnerabilities in university systems and system components.
-
4Custodians of information resources found to be vulnerable will be contacted concerning any identified risk. The custodian is responsible for ensuring that the identified risk is remediated in a timely manner.
-
5If identified vulnerabilities are not remediated, the affected information resource(s) may be isolated or disconnected from the campus network by the Technology Services security team.
-
6Vulnerability and network scanning of devices attached to the university's network may only be conducted by the Technology Services or a person authorized by the CISO or designee. Scanning conducted by entities other than the Technology Services security team may not transit a router maintained by Technology Services without permission from the CISO or designee.
-
7Vulnerability and network scanning may not be conducted by students, including student systems in Residence Halls. There is no coursework or extracurricular activity that is exempt from this prohibition.
GuidanceTexas A&M University System Cyber Operations serves as the central point of contact for public reporting of vulnerabilities in organizational systems and system components. Upon receiving a report from a public source, Cyber Operations will validate the report, determine the scope of impact across system members, implement global countermeasures to mitigate the immediate impact of the reported vulnerabilities across all affected members, and coordinate with information resource custodians to remediate the reported vulnerabilities for specific affected information systems.
Related Resource