DeftTrust

← Controls

IS-11:VM-02

Monthly external-facing system vulnerability scans (the quarterly third-party validation half of this control is tracked as VM-02-3P)

Status
No evidence
Policy cadence
Monthly
Last evidence
Next due
Owner
Security Officer / CTO
TSC
CC7.1
Evidence folder
03_Vulnerability_Management
Automatable
Yes
Policy
IS-11
Policy version
v1.1 (2026-06-03)

Collectors

CollectorRelationshipSamplesWhat it observes
scans.external satisfies monthly Monthly unauthenticated scan of everything we expose to the internet
probes.external_ports supports monthly Proves only the UFW-permitted ports answer from the public internet
probes.ssh_posture supports monthly Proves remote production access is SSH-2 only, with no unencrypted alternative
probes.tls_posture supports weekly TLS protocol, cipher and certificate expiry for every public domain

Evidence satisfying this control

CollectedCollectorResultSourceDigest
No artifact satisfies this control.
Evidenced by a person. Security Officer / CTO owes this. The scheduler opens a request 7 days before it comes due; none is open right now.

Definition history

ChangedFieldFromToSource
2026-09-10 03:32 attestation_instructions Run the external scan from a network outside our own infras… sync_controls
2026-09-10 03:32 attestation_role Security Officer / CTO sync_controls

A cadence change re-judges this control's existing evidence against the new interval, so its status can move the moment the change lands. That is why the change is recorded rather than just applied.