IS-11:VM-06
Quarterly formal review of scan trends; critical/high closed or risk-accepted
Collectors
| Collector | Relationship | Samples | What it observes |
|---|---|---|---|
| scans.dependencies | supports | weekly | Scans application lockfiles for known-vulnerable third-party components |
| scans.external | supports | monthly | Monthly unauthenticated scan of everything we expose to the internet |
| scans.hosts | supports | weekly | Weekly authenticated OS package CVE scan of every host in the inventory |
Supporting evidence only. The collectors above produce material relevant to this
control without discharging it, so the control stays overdue. Related evidence must never
make a control read as current — the gap would then be invisible.
Evidence satisfying this control
| Collected | Collector | Result | Source | Digest |
|---|---|---|---|---|
| No artifact satisfies this control. | ||||
Evidenced by a person. Security Officer / CTO owes this. The
scheduler opens a request 14 days
before it comes due; none is open right now.
Definition history
| Changed | Field | From | To | Source |
|---|---|---|---|---|
| 2026-09-10 03:32 | attestation_lead_days | 7 | 14 | sync_controls |
| 2026-09-10 03:32 | attestation_instructions | — | Quarterly scan-trend review: findings opened and closed thi… | sync_controls |
| 2026-09-10 03:32 | attestation_role | — | Security Officer / CTO | sync_controls |
A cadence change re-judges this control's existing evidence against the new interval, so its status can move the moment the change lands. That is why the change is recorded rather than just applied.