RA-5c
        
          
    
    
    
      
        Application Vulnerability Scanning
        
           
          
          
          
          Progress Bar
          Progress Bar
          Progress Bar
         
        
        
        
        
        
        
       
      
      
     
    
    Data.goy Analyzes vulnerability scan reports and results from security control assessments
  - Nexpose and Tenable Nessus reports are reviewed and analyzed at least weekly and appropriate actions taken on discovery of vulnerabilities within the 18F Cloud Infrastructure and applications and from security control assessments conducted on its information systems.
 
  - Webinspect monthly scan reports generated by the GSA SecOps team are review and vetted with 18F DevOps, ISSOs and GSA ISO SecOps.