CCI-001641
CCI-001641 Definition
Status | |
Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
DoD has defined the requirement for vulnerability scanning periodicity of every 30 days. If the organization being inspected/assessed has determined a requirement for random scanning they must document that process. DoD has defined the frequency as every 30 days or as directed by an authoritative source (e.g. IAVM, CTOs, DTMs, STIGs).
Validation Procedures
The organization conducting the inspection/assessment obtains and examines random vulnerability process documentation (if applicable) to validate the organization has clearly defined and documented a process for conducting random vulnerability scans on the information system and hosted applications. If the organization being inspected/assessed has determined they have no requirement for random scanning, there is no requirement for a process.
Compelling Evidence
1.) System security plan (SSP). 2.) Reference to system security plan (SSP) section pertaining to vulnerability scanning procedures.