5.3.2.1 Periodic scan frequency per targeted risk analysis
If periodic scans are used to meet 5.3.2, the frequency is defined in the entity's targeted risk analysis.
5
artefacts
1
held by a system
0
at each review
hard
to go live
Document repository
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Evidence of scans at defined cadence · Vulnerability scanner / patch tooling
periodic reviewEvidence produced at each review
none for this control
governing documentDocuments that govern the control
- Targeted risk analysis document · Document repository
- Frequency with rationale · Document repository
- Management approval · Document repository
- Linkage to 12.3.1 · Document repository
First move
Mostly documents and reviews. Pull the 1 system-held artefact from your Vulnerability scanner / patch tooling on a schedule; put the documents under version control with an owner and review date, and log each review as a dated record with a named reviewer.
Common gaps auditors find
- Frequency not justified
- No analysis document
- Cadence not followed
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheet5.3.2 The anti-malware solution(s): • Performs periodic scans and active or real-time scans. OR • Performs continuous behavioral analysis of systems or processes · 5.3.3 For removable electronic media, the anti- malware solution(s): • Performs automatic scans of when the media is inserted, connected, or logically mounted, OR • Performs continuous behavioral analysis of systems or processes when the