Australian Information Security Manual
Guidelines for cyber security documentation

Australian Information Security Manual ISM-1163: Systems have a continuous monitoring plan that includes: - conducting vulnerability scans

Systems have a continuous monitoring plan that includes: - conducting vulnerability scans for systems at least fortnightly - conducting vulnerability assessments and penetration tests for systems prior to deployment, including prior to deployment of significant changes, and at least annually thereafter - analysing identified vulnerabilities to determine their potential impact - implementing mitigations based on risk, effectiveness and cost.

Other controls in Guidelines for cyber security documentation

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.