DeftTrust

← Controls

IS-11:VM-06

Quarterly formal review of scan trends; critical/high closed or risk-accepted

Status
No evidence
Policy cadence
Quarterly
Last evidence
Next due
Owner
Security Officer / CTO
TSC
CC7.2
Evidence folder
03_Vulnerability_Management
Automatable
Yes
Policy
IS-11
Policy version
v1.1 (2026-06-03)

Collectors

CollectorRelationshipSamplesWhat it observes
scans.dependencies supports weekly Scans application lockfiles for known-vulnerable third-party components
scans.external supports monthly Monthly unauthenticated scan of everything we expose to the internet
scans.hosts supports weekly Weekly authenticated OS package CVE scan of every host in the inventory
Supporting evidence only. The collectors above produce material relevant to this control without discharging it, so the control stays overdue. Related evidence must never make a control read as current — the gap would then be invisible.

Evidence satisfying this control

CollectedCollectorResultSourceDigest
No artifact satisfies this control.
Evidenced by a person. Security Officer / CTO owes this. The scheduler opens a request 14 days before it comes due; none is open right now.

Definition history

ChangedFieldFromToSource
2026-09-10 03:32 attestation_lead_days 7 14 sync_controls
2026-09-10 03:32 attestation_instructions Quarterly scan-trend review: findings opened and closed thi… sync_controls
2026-09-10 03:32 attestation_role Security Officer / CTO sync_controls

A cadence change re-judges this control's existing evidence against the new interval, so its status can move the moment the change lands. That is why the change is recorded rather than just applied.