{"type":"rich","version":"1.0","provider_name":"Transistor","provider_url":"https://transistor.fm","author_name":"Framework: The NIST Cybersecurity Framework (CSF)","title":"ID.RA-01 - Identifying and Recording Asset Vulnerabilities","html":"<iframe width=\"100%\" height=\"180\" frameborder=\"no\" scrolling=\"no\" seamless src=\"https://share.transistor.fm/e/d062a0b7\"></iframe>","width":"100%","height":180,"duration":1204,"description":"ID.RA-01 involves identifying, validating, and documenting vulnerabilities in organizational assets, including software, hardware, and facilities. This process uses tools and assessments to pinpoint weaknesses—like unpatched software or physical security gaps—that could be exploited. Recording these vulnerabilities ensures a clear record for tracking and remediation.\nThis subcategory supports risk management by providing a comprehensive view of potential entry points for threats, enabling prioritized responses. It includes monitoring external intelligence for new vulnerabilities, keeping the organization ahead of emerging risks. ID.RA-01 is a critical first step in understanding and mitigating asset-specific threats.","thumbnail_url":"https://img.transistorcdn.com/ZQAUShkq6bmReWtsoCApAiEqnASSjulPAjN3RZCtsFI/rs:fill:0:0:1/w:400/h:400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS84YTE2/ZTU4ZDc5YjBhMjRj/MDkxMTllN2RmZDU5/YmU2My5wbmc.webp","thumbnail_width":300,"thumbnail_height":300}