DeftTrust

← Controls

IS-11:VM-04

CVSS-based risk scoring and P0–P5 prioritisation applied to all findings

Status
Event-driven
Policy cadence
Per scan
Last evidence
Next due
Owner
Security Officer / CTO
TSC
CC7.2
Evidence folder
03_Vulnerability_Management
Automatable
Yes
Policy
IS-11
Policy version
v1.1 (2026-06-03)

Collectors

CollectorRelationshipSamplesWhat it observes
scans.dependencies satisfies weekly Scans application lockfiles for known-vulnerable third-party components
scans.external satisfies monthly Monthly unauthenticated scan of everything we expose to the internet
scans.hosts satisfies weekly Weekly authenticated OS package CVE scan of every host in the inventory

Evidence satisfying this control

CollectedCollectorResultSourceDigest
No artifact satisfies this control.