Controls / Patching
Automated asset discovery and an up-to-date vulnerability scanner run on the schedules in the requirements
What the applicant reports, the rules behind it in each jurisdiction, and the evidence an assessor asks for. In the applicant's words: run an up-to-date vulnerability scanner, and automated asset discovery, on the schedules the rule sets.
In Australia
Maturity Level One
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| ISM-1698 Essential Eight, Maturity Level One | A vulnerability scanner is used at least daily to identify missing patches or updates for vulnerabilities in online services. Required at Maturity Levels One, Two and Three of the Patch applications mitigation strategy (Appendices A, B and C); ISM control ISM-1698 in ASD's Essential Eight to ISM mapping (December 2023). The requirement's own words: at least daily evidence an assessor asks for Daily scan schedule and last seven days of scan results for online services; Inventory of internet-facing online services in scan scope |
| ISM-1699 Essential Eight, Maturity Level One | A vulnerability scanner is used at least weekly to identify missing patches or updates for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF software, and security products. Required at Maturity Levels One, Two and Three of the Patch applications mitigation strategy (Appendices A, B and C); ISM control ISM-1699 in ASD's Essential Eight to ISM mapping (December 2023). The requirement's own words: at least weekly evidence an assessor asks for Weekly authenticated scan results for office suites, browsers and extensions, email clients, PDF software and security products; Scan policy naming those application classes |
| ISM-1807 Essential Eight, Maturity Level One | An automated method of asset discovery is used at least fortnightly to support the detection of assets for subsequent vulnerability scanning activities. Required at Maturity Levels One, Two and Three of the Patch applications mitigation strategy (Appendices A, B and C); ISM control ISM-1807 in ASD's Essential Eight to ISM mapping (December 2023). The requirement's own words: at least fortnightly evidence an assessor asks for Asset discovery tool schedule showing runs at least fortnightly; Latest discovery output reconciled to the vulnerability scanning target list |
| ISM-1808 Essential Eight, Maturity Level One | A vulnerability scanner with an up-to-date vulnerability database is used for vulnerability scanning activities. Required at Maturity Levels One, Two and Three of the Patch applications mitigation strategy (Appendices A, B and C); ISM control ISM-1808 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Vulnerability scanner console showing the date of the last plugin or database update; Scanner licence and update configuration record |
| ISM-1701 Essential Eight, Maturity Level One | A vulnerability scanner is used at least daily to identify missing patches or updates for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices. Required at Maturity Levels One, Two and Three of the Patch operating systems mitigation strategy (Appendices A, B and C); ISM control ISM-1701 in ASD's Essential Eight to ISM mapping (December 2023). The requirement's own words: at least daily evidence an assessor asks for Daily scan schedule and results for operating systems of internet-facing servers and network devices; List of internet-facing hosts and devices in daily scan scope |
| ISM-1702 Essential Eight, Maturity Level One | A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices. Required at Maturity Levels One, Two and Three of the Patch operating systems mitigation strategy (Appendices A, B and C); ISM control ISM-1702 in ASD's Essential Eight to ISM mapping (December 2023). The requirement's own words: at least fortnightly evidence an assessor asks for Fortnightly scan results for workstation, non-internet-facing server and internal network device operating systems; Credentialed scan configuration for internal hosts |
Maturity Level Two
Above the target when the underwriter picks Maturity Level One: shown as "above your target level", never a gap.
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| ISM-1700 Essential Eight, Maturity Level Two | A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in applications other than office productivity suites, web browsers and their extensions, email clients, PDF software, and security products. Required at Maturity Levels Two and Three of the Patch applications mitigation strategy (Appendices B and C); ISM control ISM-1700 in ASD's Essential Eight to ISM mapping (December 2023). The requirement's own words: at least fortnightly evidence an assessor asks for Fortnightly scan results covering applications other than the named classes; Scan policy that includes line-of-business and other installed applications |
PCI DSS v4.0.1, when it applies
Any business that stores, processes or transmits payment card data, in any of the three jurisdictions.
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| PCI DSS 11.3.1 PCI DSS v4.0.1 (add-on) | Quarterly internal vulnerability scans Internal vulnerability scans must be run at least every three months. All vulnerabilities ranked high-risk or critical under the entity's risk rankings from Requirement 6.3.1 must be resolved, and rescans must be run to confirm that every such high-risk and critical finding is fixed. The scanning tool must be kept current with the latest vulnerability information, and the people running scans must be qualified and organizationally independent of what they scan. Guidance (good practice): several scan reports may be combined to show full coverage within the three-month cycle, and scanning more often than quarterly is recommended where the environment warrants it. Applicability: a QSA or ASV is not needed for internal scans; qualified internal staff reasonably independent of the scanned components (for example, not the administrator of that network) may run them, or a specialist scanning firm may be used. Objective under the customized approach: automated tools that detect vulnerabilities inside the network periodically verify the security state of every system component, and findings are assessed and fixed using a formal risk assessment framework. The requirement's own words: every three months evidence an assessor asks for Four quarters of internal scan reports covering all in-scope system components; Rescan reports showing high-risk and critical findings closed; Scan tool plugin or signature update logs; Vulnerability risk ranking criteria from Requirement 6.3.1; Scanner qualifications and evidence of independence from the scanned systems |
In the United States
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CIS 7.5 CIS Controls v8.1 | Perform Automated Vulnerability Scans of Internal Enterprise Assets Scan internal enterprise assets for vulnerabilities automatically at least once a quarter, running both authenticated and unauthenticated scans with a SCAP-compliant scanner. The requirement's own words: at least once a quarter evidence an assessor asks for Quarterly authenticated and unauthenticated internal scan reports from a SCAP-compliant scanner; Scanner configuration showing credentials and scope; Scanning standard requiring quarterly authenticated and unauthenticated internal scans; Scan schedule export showing recurring internal jobs and credential test success per target range; Scanner coverage reconciliation against the asset inventory, listing hosts not scanned |
| CIS 7.6 CIS Controls v8.1 | Perform Automated Vulnerability Scans of Externally-Exposed Enterprise Assets Scan externally exposed enterprise assets for vulnerabilities automatically with a SCAP-compliant scanner, at least once a month. The requirement's own words: at least once a month evidence an assessor asks for Monthly external vulnerability scan reports from a SCAP-compliant scanner; Scan scope list matched to externally exposed assets; External scanning procedure naming the monthly schedule and who reconciles the public IP and domain list; Scheduled external scan job settings and the public IP and DNS list fed to the scanner; Month-by-month external scan history with no missed months and findings routed to remediation |
| ID.RA-01 NIST CSF 2.0 | Vulnerabilities in assets are identified, validated, and recorded. Control from NIST Cybersecurity Framework 2.0 framework, domain: ID - Identify. evidence an assessor asks for Vulnerability scanning coverage report; Vulnerability triage workflow with severity SLAs; Validated findings with proof and remediation status; Asset coverage exceptions register; Trend analysis on vulnerability backlog |
PCI DSS v4.0.1, when it applies
Any business that stores, processes or transmits payment card data, in any of the three jurisdictions.
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| PCI DSS 11.3.1 PCI DSS v4.0.1 (add-on) | Quarterly internal vulnerability scans Internal vulnerability scans must be run at least every three months. All vulnerabilities ranked high-risk or critical under the entity's risk rankings from Requirement 6.3.1 must be resolved, and rescans must be run to confirm that every such high-risk and critical finding is fixed. The scanning tool must be kept current with the latest vulnerability information, and the people running scans must be qualified and organizationally independent of what they scan. Guidance (good practice): several scan reports may be combined to show full coverage within the three-month cycle, and scanning more often than quarterly is recommended where the environment warrants it. Applicability: a QSA or ASV is not needed for internal scans; qualified internal staff reasonably independent of the scanned components (for example, not the administrator of that network) may run them, or a specialist scanning firm may be used. Objective under the customized approach: automated tools that detect vulnerabilities inside the network periodically verify the security state of every system component, and findings are assessed and fixed using a formal risk assessment framework. The requirement's own words: every three months evidence an assessor asks for Four quarters of internal scan reports covering all in-scope system components; Rescan reports showing high-risk and critical findings closed; Scan tool plugin or signature update logs; Vulnerability risk ranking criteria from Requirement 6.3.1; Scanner qualifications and evidence of independence from the scanned systems |
FTC Safeguards Rule, when it applies
Financial institutions under FTC jurisdiction, for example tax preparers, mortgage brokers and auto dealers that arrange financing.
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| 314.4(d)(2) FTC Safeguards Rule (add-on) | 314.4(d)(2) Continuous monitoring or annual penetration testing and six-monthly vulnerability assessment For information systems, monitoring and testing include continuous monitoring or periodic penetration testing and vulnerability assessments; absent effective continuous monitoring or other systems that detect changes creating vulnerabilities on an ongoing basis, the institution conducts annual penetration testing of its information systems, scoped each year to the relevant risks identified in the risk assessment, and vulnerability assessments including systemic scans or reviews reasonably designed to find publicly known vulnerabilities, at least every six months, whenever there are material changes to operations or business arrangements, and whenever circumstances may have a material impact on the program. Not required of institutions holding information on fewer than 5,000 consumers (314.6). The requirement's own words: every six months evidence an assessor asks for Continuous monitoring capability, or annual penetration test reports scoped to the risk assessment; Vulnerability assessment reports at least every six months and after material changes |
23 NYCRR 500, when it applies
Entities licensed by the New York Department of Financial Services. Section 500.19 sets limited exemptions for smaller covered entities: whether one applies is a question for the business, and this page never decides it.
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| 500.5 23 NYCRR 500 (add-on) | Vulnerability Management Conduct penetration testing at least annually by qualified internal or external party, automated scans of information systems and manual reviews of systems not covered by scans, document and report material issues, prioritize and remediate. Class A must use external experts at least every three years. evidence an assessor asks for Annual penetration test report from qualified party; Automated vulnerability scan schedule and outputs; Manual review records for non-scannable systems; Remediation tickets with SLAs and closure evidence; Risk-based prioritization methodology; Class A external expert engagement letter (triennial); Monitoring of publicly disclosed vulnerabilities and CISA KEV tracking |
In United Kingdom
No requirement in the core list for the United Kingdom covers this control; it is on the schedule as a condition beyond the core list.
PCI DSS v4.0.1, when it applies
Any business that stores, processes or transmits payment card data, in any of the three jurisdictions.
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| PCI DSS 11.3.1 PCI DSS v4.0.1 (add-on) | Quarterly internal vulnerability scans Internal vulnerability scans must be run at least every three months. All vulnerabilities ranked high-risk or critical under the entity's risk rankings from Requirement 6.3.1 must be resolved, and rescans must be run to confirm that every such high-risk and critical finding is fixed. The scanning tool must be kept current with the latest vulnerability information, and the people running scans must be qualified and organizationally independent of what they scan. Guidance (good practice): several scan reports may be combined to show full coverage within the three-month cycle, and scanning more often than quarterly is recommended where the environment warrants it. Applicability: a QSA or ASV is not needed for internal scans; qualified internal staff reasonably independent of the scanned components (for example, not the administrator of that network) may run them, or a specialist scanning firm may be used. Objective under the customized approach: automated tools that detect vulnerabilities inside the network periodically verify the security state of every system component, and findings are assessed and fixed using a formal risk assessment framework. The requirement's own words: every three months evidence an assessor asks for Four quarters of internal scan reports covering all in-scope system components; Rescan reports showing high-risk and critical findings closed; Scan tool plugin or signature update logs; Vulnerability risk ranking criteria from Requirement 6.3.1; Scanner qualifications and evidence of independence from the scanned systems |
Also cited: ISO/IEC 27001:2022 Annex A
A lens in any jurisdiction, never a gap on its own.
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| A.8.8 ISO/IEC 27001:2022 (lens) | Management of technical vulnerabilities The organization is to gather information about technical vulnerabilities in the information systems it uses, assess how exposed it is, and take suitable action. Purpose (stated in ISO/IEC 27002:2022): prevents exploitation of technical vulnerabilities. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.8. evidence an assessor asks for Statement of Applicability entry for control A.8.8, showing inclusion or justified exclusion, implementation status and the risks it treats; A software asset inventory with vendor, product, version, deployment location and responsible owner; Defined vulnerability management roles and a list of monitored vulnerability information sources; Authenticated scan results and penetration test reports by authorized testers, with verification scans after patching; Remediation timelines by severity with measured performance, and risk records weighing the vulnerability against update risk |
Questions
- What does the applicant report for this control?
- Whether it is in place, partly in place, not in place or not sure. Partly, not in place and not sure are gaps; not sure reads as a question.
- When is it due on the 90-day schedule?
- Day 60 by the default rule for a core line, day 90 when it is beyond the core list for the jurisdiction or marked not sure. The underwriter or broker can move it.
- Does this page check the control?
- No. The applicant reports a closure with a date and a note; the schedule records it as reported and never checks it.