IS-11:VM-02
Monthly external-facing system vulnerability scans (the quarterly third-party validation half of this control is tracked as VM-02-3P)
Collectors
| Collector | Relationship | Samples | What it observes |
|---|---|---|---|
| scans.external | satisfies | monthly | Monthly unauthenticated scan of everything we expose to the internet |
| probes.external_ports | supports | monthly | Proves only the UFW-permitted ports answer from the public internet |
| probes.ssh_posture | supports | monthly | Proves remote production access is SSH-2 only, with no unencrypted alternative |
| probes.tls_posture | supports | weekly | TLS protocol, cipher and certificate expiry for every public domain |
Evidence satisfying this control
| Collected | Collector | Result | Source | Digest |
|---|---|---|---|---|
| No artifact satisfies this control. | ||||
Evidenced by a person. Security Officer / CTO owes this. The
scheduler opens a request 7 days
before it comes due; none is open right now.
Definition history
| Changed | Field | From | To | Source |
|---|---|---|---|---|
| 2026-09-10 03:32 | attestation_instructions | — | Run the external scan from a network outside our own infras… | sync_controls |
| 2026-09-10 03:32 | attestation_role | — | Security Officer / CTO | sync_controls |
A cadence change re-judges this control's existing evidence against the new interval, so its status can move the moment the change lands. That is why the change is recorded rather than just applied.