Cyber Insurance Subjectivity Tracker

Controls / Patching

Automated asset discovery and an up-to-date vulnerability scanner run on the schedules in the requirements

What the applicant reports, the rules behind it in each jurisdiction, and the evidence an assessor asks for. In the applicant's words: run an up-to-date vulnerability scanner, and automated asset discovery, on the schedules the rule sets.

In Australia

Maturity Level One

ClauseThe held text, and the evidence an assessor asks for
ISM-1698
Essential Eight, Maturity Level One

A vulnerability scanner is used at least daily to identify missing patches or updates for vulnerabilities in online services. Required at Maturity Levels One, Two and Three of the Patch applications mitigation strategy (Appendices A, B and C); ISM control ISM-1698 in ASD's Essential Eight to ISM mapping (December 2023).

The requirement's own words: at least daily

evidence an assessor asks for Daily scan schedule and last seven days of scan results for online services; Inventory of internet-facing online services in scan scope

ISM-1699
Essential Eight, Maturity Level One

A vulnerability scanner is used at least weekly to identify missing patches or updates for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF software, and security products. Required at Maturity Levels One, Two and Three of the Patch applications mitigation strategy (Appendices A, B and C); ISM control ISM-1699 in ASD's Essential Eight to ISM mapping (December 2023).

The requirement's own words: at least weekly

evidence an assessor asks for Weekly authenticated scan results for office suites, browsers and extensions, email clients, PDF software and security products; Scan policy naming those application classes

ISM-1807
Essential Eight, Maturity Level One

An automated method of asset discovery is used at least fortnightly to support the detection of assets for subsequent vulnerability scanning activities. Required at Maturity Levels One, Two and Three of the Patch applications mitigation strategy (Appendices A, B and C); ISM control ISM-1807 in ASD's Essential Eight to ISM mapping (December 2023).

The requirement's own words: at least fortnightly

evidence an assessor asks for Asset discovery tool schedule showing runs at least fortnightly; Latest discovery output reconciled to the vulnerability scanning target list

ISM-1808
Essential Eight, Maturity Level One

A vulnerability scanner with an up-to-date vulnerability database is used for vulnerability scanning activities. Required at Maturity Levels One, Two and Three of the Patch applications mitigation strategy (Appendices A, B and C); ISM control ISM-1808 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Vulnerability scanner console showing the date of the last plugin or database update; Scanner licence and update configuration record

ISM-1701
Essential Eight, Maturity Level One

A vulnerability scanner is used at least daily to identify missing patches or updates for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices. Required at Maturity Levels One, Two and Three of the Patch operating systems mitigation strategy (Appendices A, B and C); ISM control ISM-1701 in ASD's Essential Eight to ISM mapping (December 2023).

The requirement's own words: at least daily

evidence an assessor asks for Daily scan schedule and results for operating systems of internet-facing servers and network devices; List of internet-facing hosts and devices in daily scan scope

ISM-1702
Essential Eight, Maturity Level One

A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices. Required at Maturity Levels One, Two and Three of the Patch operating systems mitigation strategy (Appendices A, B and C); ISM control ISM-1702 in ASD's Essential Eight to ISM mapping (December 2023).

The requirement's own words: at least fortnightly

evidence an assessor asks for Fortnightly scan results for workstation, non-internet-facing server and internal network device operating systems; Credentialed scan configuration for internal hosts

Maturity Level Two

Above the target when the underwriter picks Maturity Level One: shown as "above your target level", never a gap.

ClauseThe held text, and the evidence an assessor asks for
ISM-1700
Essential Eight, Maturity Level Two

A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in applications other than office productivity suites, web browsers and their extensions, email clients, PDF software, and security products. Required at Maturity Levels Two and Three of the Patch applications mitigation strategy (Appendices B and C); ISM control ISM-1700 in ASD's Essential Eight to ISM mapping (December 2023).

The requirement's own words: at least fortnightly

evidence an assessor asks for Fortnightly scan results covering applications other than the named classes; Scan policy that includes line-of-business and other installed applications

PCI DSS v4.0.1, when it applies

Any business that stores, processes or transmits payment card data, in any of the three jurisdictions.

ClauseThe held text, and the evidence an assessor asks for
PCI DSS 11.3.1
PCI DSS v4.0.1 (add-on)
Quarterly internal vulnerability scans

Internal vulnerability scans must be run at least every three months. All vulnerabilities ranked high-risk or critical under the entity's risk rankings from Requirement 6.3.1 must be resolved, and rescans must be run to confirm that every such high-risk and critical finding is fixed. The scanning tool must be kept current with the latest vulnerability information, and the people running scans must be qualified and organizationally independent of what they scan. Guidance (good practice): several scan reports may be combined to show full coverage within the three-month cycle, and scanning more often than quarterly is recommended where the environment warrants it. Applicability: a QSA or ASV is not needed for internal scans; qualified internal staff reasonably independent of the scanned components (for example, not the administrator of that network) may run them, or a specialist scanning firm may be used. Objective under the customized approach: automated tools that detect vulnerabilities inside the network periodically verify the security state of every system component, and findings are assessed and fixed using a formal risk assessment framework.

The requirement's own words: every three months

evidence an assessor asks for Four quarters of internal scan reports covering all in-scope system components; Rescan reports showing high-risk and critical findings closed; Scan tool plugin or signature update logs; Vulnerability risk ranking criteria from Requirement 6.3.1; Scanner qualifications and evidence of independence from the scanned systems

In the United States

ClauseThe held text, and the evidence an assessor asks for
CIS 7.5
CIS Controls v8.1
Perform Automated Vulnerability Scans of Internal Enterprise Assets

Scan internal enterprise assets for vulnerabilities automatically at least once a quarter, running both authenticated and unauthenticated scans with a SCAP-compliant scanner.

The requirement's own words: at least once a quarter

evidence an assessor asks for Quarterly authenticated and unauthenticated internal scan reports from a SCAP-compliant scanner; Scanner configuration showing credentials and scope; Scanning standard requiring quarterly authenticated and unauthenticated internal scans; Scan schedule export showing recurring internal jobs and credential test success per target range; Scanner coverage reconciliation against the asset inventory, listing hosts not scanned

CIS 7.6
CIS Controls v8.1
Perform Automated Vulnerability Scans of Externally-Exposed Enterprise Assets

Scan externally exposed enterprise assets for vulnerabilities automatically with a SCAP-compliant scanner, at least once a month.

The requirement's own words: at least once a month

evidence an assessor asks for Monthly external vulnerability scan reports from a SCAP-compliant scanner; Scan scope list matched to externally exposed assets; External scanning procedure naming the monthly schedule and who reconciles the public IP and domain list; Scheduled external scan job settings and the public IP and DNS list fed to the scanner; Month-by-month external scan history with no missed months and findings routed to remediation

ID.RA-01
NIST CSF 2.0

Vulnerabilities in assets are identified, validated, and recorded. Control from NIST Cybersecurity Framework 2.0 framework, domain: ID - Identify.

evidence an assessor asks for Vulnerability scanning coverage report; Vulnerability triage workflow with severity SLAs; Validated findings with proof and remediation status; Asset coverage exceptions register; Trend analysis on vulnerability backlog

PCI DSS v4.0.1, when it applies

Any business that stores, processes or transmits payment card data, in any of the three jurisdictions.

ClauseThe held text, and the evidence an assessor asks for
PCI DSS 11.3.1
PCI DSS v4.0.1 (add-on)
Quarterly internal vulnerability scans

Internal vulnerability scans must be run at least every three months. All vulnerabilities ranked high-risk or critical under the entity's risk rankings from Requirement 6.3.1 must be resolved, and rescans must be run to confirm that every such high-risk and critical finding is fixed. The scanning tool must be kept current with the latest vulnerability information, and the people running scans must be qualified and organizationally independent of what they scan. Guidance (good practice): several scan reports may be combined to show full coverage within the three-month cycle, and scanning more often than quarterly is recommended where the environment warrants it. Applicability: a QSA or ASV is not needed for internal scans; qualified internal staff reasonably independent of the scanned components (for example, not the administrator of that network) may run them, or a specialist scanning firm may be used. Objective under the customized approach: automated tools that detect vulnerabilities inside the network periodically verify the security state of every system component, and findings are assessed and fixed using a formal risk assessment framework.

The requirement's own words: every three months

evidence an assessor asks for Four quarters of internal scan reports covering all in-scope system components; Rescan reports showing high-risk and critical findings closed; Scan tool plugin or signature update logs; Vulnerability risk ranking criteria from Requirement 6.3.1; Scanner qualifications and evidence of independence from the scanned systems

FTC Safeguards Rule, when it applies

Financial institutions under FTC jurisdiction, for example tax preparers, mortgage brokers and auto dealers that arrange financing.

ClauseThe held text, and the evidence an assessor asks for
314.4(d)(2)
FTC Safeguards Rule (add-on)
314.4(d)(2) Continuous monitoring or annual penetration testing and six-monthly vulnerability assessment

For information systems, monitoring and testing include continuous monitoring or periodic penetration testing and vulnerability assessments; absent effective continuous monitoring or other systems that detect changes creating vulnerabilities on an ongoing basis, the institution conducts annual penetration testing of its information systems, scoped each year to the relevant risks identified in the risk assessment, and vulnerability assessments including systemic scans or reviews reasonably designed to find publicly known vulnerabilities, at least every six months, whenever there are material changes to operations or business arrangements, and whenever circumstances may have a material impact on the program. Not required of institutions holding information on fewer than 5,000 consumers (314.6).

The requirement's own words: every six months

evidence an assessor asks for Continuous monitoring capability, or annual penetration test reports scoped to the risk assessment; Vulnerability assessment reports at least every six months and after material changes

23 NYCRR 500, when it applies

Entities licensed by the New York Department of Financial Services. Section 500.19 sets limited exemptions for smaller covered entities: whether one applies is a question for the business, and this page never decides it.

ClauseThe held text, and the evidence an assessor asks for
500.5
23 NYCRR 500 (add-on)
Vulnerability Management

Conduct penetration testing at least annually by qualified internal or external party, automated scans of information systems and manual reviews of systems not covered by scans, document and report material issues, prioritize and remediate. Class A must use external experts at least every three years.

evidence an assessor asks for Annual penetration test report from qualified party; Automated vulnerability scan schedule and outputs; Manual review records for non-scannable systems; Remediation tickets with SLAs and closure evidence; Risk-based prioritization methodology; Class A external expert engagement letter (triennial); Monitoring of publicly disclosed vulnerabilities and CISA KEV tracking

In United Kingdom

No requirement in the core list for the United Kingdom covers this control; it is on the schedule as a condition beyond the core list.

PCI DSS v4.0.1, when it applies

Any business that stores, processes or transmits payment card data, in any of the three jurisdictions.

ClauseThe held text, and the evidence an assessor asks for
PCI DSS 11.3.1
PCI DSS v4.0.1 (add-on)
Quarterly internal vulnerability scans

Internal vulnerability scans must be run at least every three months. All vulnerabilities ranked high-risk or critical under the entity's risk rankings from Requirement 6.3.1 must be resolved, and rescans must be run to confirm that every such high-risk and critical finding is fixed. The scanning tool must be kept current with the latest vulnerability information, and the people running scans must be qualified and organizationally independent of what they scan. Guidance (good practice): several scan reports may be combined to show full coverage within the three-month cycle, and scanning more often than quarterly is recommended where the environment warrants it. Applicability: a QSA or ASV is not needed for internal scans; qualified internal staff reasonably independent of the scanned components (for example, not the administrator of that network) may run them, or a specialist scanning firm may be used. Objective under the customized approach: automated tools that detect vulnerabilities inside the network periodically verify the security state of every system component, and findings are assessed and fixed using a formal risk assessment framework.

The requirement's own words: every three months

evidence an assessor asks for Four quarters of internal scan reports covering all in-scope system components; Rescan reports showing high-risk and critical findings closed; Scan tool plugin or signature update logs; Vulnerability risk ranking criteria from Requirement 6.3.1; Scanner qualifications and evidence of independence from the scanned systems

Also cited: ISO/IEC 27001:2022 Annex A

A lens in any jurisdiction, never a gap on its own.

ClauseThe held text, and the evidence an assessor asks for
A.8.8
ISO/IEC 27001:2022 (lens)
Management of technical vulnerabilities

The organization is to gather information about technical vulnerabilities in the information systems it uses, assess how exposed it is, and take suitable action. Purpose (stated in ISO/IEC 27002:2022): prevents exploitation of technical vulnerabilities. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.8.

evidence an assessor asks for Statement of Applicability entry for control A.8.8, showing inclusion or justified exclusion, implementation status and the risks it treats; A software asset inventory with vendor, product, version, deployment location and responsible owner; Defined vulnerability management roles and a list of monitored vulnerability information sources; Authenticated scan results and penetration test reports by authorized testers, with verification scans after patching; Remediation timelines by severity with measured performance, and risk records weighing the vulnerability against update risk

Questions

What does the applicant report for this control?
Whether it is in place, partly in place, not in place or not sure. Partly, not in place and not sure are gaps; not sure reads as a question.
When is it due on the 90-day schedule?
Day 60 by the default rule for a core line, day 90 when it is beyond the core list for the jurisdiction or marked not sure. The underwriter or broker can move it.
Does this page check the control?
No. The applicant reports a closure with a date and a note; the schedule records it as reported and never checks it.

Put this control on a schedule