NIST 800-171 Controls · Risk Assessment
RA.2.002 — Scan for Vulnerabilities Periodically
Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified.
What RA.2.002 means in plain English
Run automated scans on your computers and network at least once a month to find security holes — missing patches, misconfigured settings, outdated software with known weaknesses. Think of it like a health checkup for your computers. Tools like Nessus Essentials (free for up to 16 IPs) or Windows built-in tools can do this. When a major new vulnerability is announced (like Log4j was), scan again right away to check if you are affected.
The assessment question
“Do you perform automated vulnerability scans on your systems and network at least monthly, and do you perform additional scans when new critical vulnerabilities are publicly disclosed?”
How to implement RA.2.002
- Download and install Nessus Essentials (free for up to 16 IP addresses) from tenable.com. Run your first scan on your internal network to establish a baseline of vulnerabilities.
- Schedule monthly vulnerability scans: set Nessus or your chosen tool to run automatically on the first weekend of each month. Review results the following Monday.
- For each scan result, triage vulnerabilities by severity: Critical and High should be remediated within 30 days, Medium within 90 days, Low can be addressed in the next patch cycle.
- Subscribe to CISA Known Exploited Vulnerabilities (KEV) alerts at cisa.gov to get notified when new critical vulnerabilities are announced, and run an ad-hoc scan immediately after.
- Save scan reports as PDF and store them with your compliance documentation. Track remediation progress in your POA&M.
Evidence your assessor will ask for
- Vulnerability scan reports from the past 12 months showing at least monthly scans
- Evidence of remediation for critical and high vulnerabilities found in scans
- Written vulnerability scanning procedure describing frequency and scope
- POA&M entries for any open vulnerabilities that are not yet remediated
- Evidence of ad-hoc scans performed in response to newly announced critical vulnerabilities
Does AI prompt monitoring help with this control? Honestly, no.
RA.2.002 is met through the remediation steps above, not through AI traffic controls — an AI prompt firewall neither satisfies nor substitutes for it. We map AI monitoring only to the controls it genuinely evidences (flow control, boundary protection, audit, and incident support); for the full picture of where it does help, see the mapping guide linked below.
Full mapping: which 800-171 controls AI prompt monitoring evidences →
More Risk Assessment controls
Score yourself against all 110 controls
The free ShieldReady assessment walks every NIST 800-171 requirement, computes your SPRS score, and shows exactly which gaps cost the most points.