11.3.1.3 Internal scans after significant changes
Internal vulnerability scans are performed after any significant change, with high-risk and critical vulnerabilities resolved.
5
artefacts
4
held by a system
0
at each review
easy
to go live
Vulnerability scanner / patch tooling
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Change tickets linked to triggered scans · Vulnerability scanner / patch tooling
- Scan reports post-change · Vulnerability scanner / patch tooling
- Remediation tickets with closure · Vulnerability scanner / patch tooling
- Re-scan evidence · Vulnerability scanner / patch tooling
periodic reviewEvidence produced at each review
none for this control
governing documentDocuments that govern the control
- Defined criteria for significant change · Policy repository / GRC workspace
First move
Automate the pull from your Vulnerability scanner / patch tooling. Scan schedule, findings and remediation age straight from the scanner; patch compliance from the patch console.
Common gaps auditors find
- Significant change undefined
- Scans not triggered
- Findings open
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheet11.3.1.2 Authenticated internal scans · 11.3.2 External vulnerability scans quarterly by ASV