IS-11:VM-04
CVSS-based risk scoring and P0–P5 prioritisation applied to all findings
Collectors
| Collector | Relationship | Samples | What it observes |
|---|---|---|---|
| scans.dependencies | satisfies | weekly | Scans application lockfiles for known-vulnerable third-party components |
| scans.external | satisfies | monthly | Monthly unauthenticated scan of everything we expose to the internet |
| scans.hosts | satisfies | weekly | Weekly authenticated OS package CVE scan of every host in the inventory |
Evidence satisfying this control
| Collected | Collector | Result | Source | Digest |
|---|---|---|---|---|
| No artifact satisfies this control. | ||||