본문 바로가기
  • Home

A Study on the Importance of Control Items of NIST SP 800-53 by Mapping CVE and STIG/SRG

  • Journal of The Korea Society of Computer and Information
  • Abbr : JKSCI
  • 2024, 29(11), pp.173-185
  • DOI : 10.9708/jksci.2024.29.11.173
  • Publisher : The Korean Society Of Computer And Information
  • Research Area : Engineering > Computer Science
  • Received : September 30, 2024
  • Accepted : October 28, 2024
  • Published : November 29, 2024

Se-Eun Kim 1 Hyo-Beom Ahn 1

1국립공주대학교

Accredited

ABSTRACT

The U.S. federal government has established NIST SP 800-53 in response to the need for vulnerability management, and MITRE manages security vulnerabilities through CVE numbers. Although the relationship between NIST SP 800-53 and CVE is a crucial factor in vulnerability management, it is not clearly defined, making it challenging for security managers to identify control items that address the latest vulnerabilities. This study aims to analyze the relationship between NIST SP 800-53 and CVE to establish prioritization for evaluating security control items. Controls that are frequently associated with CVE should be prioritized for evaluation and improvement. The study derived the relevance between NIST SP 800-53 security controls through mapping CVE to STIG/SRG and used SecBERT, CyBERT, and RankT5 models to automate this mapping. The results confirmed the need to prioritize the improvement of specific security controls.

Citation status

* References for papers published after 2023 are currently being built.

This paper was written with support from the National Research Foundation of Korea.