NIST 800-53 Rev 5
424 controls available
RA-5(11)lowmoderatehigh
Public Disclosure Program
Risk Assessment
Control Statement
Establish a public reporting channel for receiving reports of vulnerabilities in organizational systems and system components.
Discussion
The reporting channel is publicly discoverable and contains clear language authorizing good-faith research and the disclosure of vulnerabilities to the organization. The organization does not condition its authorization on an expectation of indefinite non-disclosure to the public by the reporting entity but may request a specific time period to properly remediate the vulnerability.
- Framework
- NIST SP 800-53 Rev 5
- Family
- Risk Assessment
- Baselines
- low, moderate, high
Related Frameworks
2 paths across 2 frameworks
Related Frameworks
SCF1 mapping
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
CCI1 mapping
CCI-004640
1.00
- DISA · 2025-01-23 · disa_cci_list · equivalent
Related STIGs
12 STIGs reach this control through 31 CCIs. Expand a row to see the responsible NICE and O*NET roles.
Operating System - Mainframe
2 STIGs
Operating System - Mainframe
2 STIGsMainframe Product Security Requirements Guide
32024-12-051 of 193 findings match
M1
Mainframe Product Security Requirements Guide
V3R42025-09-101 of 194 findings match
M1
Network Device
2 STIGs
Network Device
2 STIGsPalo Alto Networks Prisma Cloud Compute Security Technical Implementation Guide
22024-12-061 of 31 findings match
M1
Palo Alto Networks Prisma Cloud Compute Security Technical Implementation Guide
V2R32026-02-131 of 31 findings match
M1
Virtualization / Container
5 STIGs
Virtualization / Container
5 STIGsContainer Platform Security Requirements Guide
22025-05-151 of 187 findings match
M1
Container Platform Security Requirements Guide
V2R42025-09-101 of 188 findings match
M1
Mirantis Kubernetes Engine Security Technical Implementation Guide
V2R12024-08-271 of 44 findings match
M1
Red Hat OpenShift Container Platform 4.x Security Technical Implementation Guide
22025-05-151 of 83 findings match
M1
Red Hat OpenShift Container Platform 4.x Security Technical Implementation Guide
V2R52025-12-041 of 83 findings match
M1
Endpoint Security Management
1 STIG
Endpoint Security Management
1 STIGAxonius Federal Systems Ax-OS Security Technical Implementation Guide
V1R22025-11-251 of 16 findings match
M1
Uncategorized
2 STIGs
Uncategorized
2 STIGsMainframe Product Security Requirements Guide
V3R52026-05-231 of 194 findings match
M1
Red Hat OpenShift Container Platform 4.x Security Technical Implementation Guide
V2R62026-05-131 of 83 findings match
M1