Scan Coverage & Asset Scope Register
Exposes the gap between what the organisation owns and what is actually being scanned, which is the root cause of most programme failure.
Available soon
- Format
- Excel
- Size
- 95 KB
- Length
- 9 sheets
- Version
- 1.0
- Updated
What's inside
- Instructions
- Scope Register
- Summary
- Lists
- Definitions
- Framework References
Preview
The workbook's sheets as you will receive them, with its example rows and the values its formulas calculate. Highlighted [[text]] is for you to replace; rows marked EXAMPLE are for you to delete. Wide sheets scroll sideways. The cover, document control and changelog sheets are in the file.
Instructions
How to use this workbook
| Step | What to do |
|---|---|
| 1 | Set the As-at date on the Summary sheet. It shows today's date; type a fixed date over it to freeze a month-end report. Every calculated status uses this date. |
| 2 | On the Scope Register sheet, add one row per system from your asset inventory: servers, end-user devices (or one row per managed group of them), network and security devices, cloud accounts, business applications and websites. Give each a unique Asset ID and reuse that ID in the Vulnerability Remediation Tracker. |
| 3 | Complete the yellow columns. Criticality follows the Standard's Appendix A (Critical, High, Standard). Mark Internet-facing Yes if the system can be reached from the internet without first joining your private network. |
| 4 | Set In scanning scope to No only when the system cannot be scanned by you at all, such as a cloud software service with no access to the servers underneath. Record the reason; such systems stay on the register and are covered by supplier assurance instead. |
| 5 | Fill Date entered production for systems introduced since the register started. The register counts working days to Date added to scanning and flags any new system not added within 5 working days (VM-03). Leave it blank for older systems. |
| 6 | After each scanning cycle, update Last successful scan and Authenticated login result from your scanner's export. The register works out the required frequency from the Standard's table (section 4.3) and marks each system Scanned, Scan overdue or Not scanned. |
| 7 | For every system not scanned or overdue, record why and the date by which it will be scanned (VM-02). For every failed authenticated scan, record the date the failure was first seen; the register sets a fix date 5 working days later (VM-05). |
| 8 | For systems the vendor no longer supports, record the compensating controls, the planned retirement date and the date of the last quarterly review (VM-15). |
| 9 | Clear every Record check that does not say OK before the monthly report. Read the Summary sheet: coverage and authenticated success are measured against the Standard's 95% targets. |
| 10 | Delete the EXAMPLE rows before the register is approved. Do not type over the white calculated columns. |
Legend
Yellow cells are inputs. Everything else is calculated or fixed — do not overwrite formulas.
| EXAMPLE | Rows marked EXAMPLE in the first column show how a completed row looks. Delete them before approval. |
Tailoring — small organisation: one row per server and network device is enough; group laptops and desktops into a single row per managed group (for example, 'Staff laptops — 48 devices') and use the agent console's last check-in date as Last successful scan.
Tailoring — regulated financial entity: add a column naming the critical or important function each system supports, so you can show supervisors that every system behind such a function is in scope and scanned at least weekly, as Delegated Regulation (EU) 2024/1774, Article 10(2) requires. Keep superseded monthly copies as records.
Tailoring — IT run by a service provider: ask the provider to supply the scan export each cycle and fill this register from it; do not accept a 'scanned' statement without the export. Record the provider as Hosting and name your own internal asset owner, not the provider.
Frequencies: Weekly for internet-facing, Critical and High systems and cloud infrastructure; Quarterly for web applications that are not internet-facing; Monthly for everything else. If your Standard sets different frequencies, change the formula in the Required scan frequency column and the day counts on the Lists sheet.
Example rows use the template's revision date (2026-09-27) as their reference point, so their statuses change as the As-at date moves on.
Scope Register
One row per system. Yellow columns are inputs; white columns calculate. Status colours always carry a text label.
| Example | Asset ID | Asset name | Asset class | Hosting | Asset owner | Criticality | Internet-facing | In scanning scope | Out-of-scope reason | Date entered production | Date added to scanning | Onboarding working days | Onboarding status | Required scan frequency | Scan method | External scan in place | Last successful scan | Days since last scan | Scan status | Not-scanned reason | Scan-by date | Authenticated login result | Login failure first seen | Credential fix due | Vendor support | Compensating controls (unsupported) | Planned retirement date | Last unsupported review | Record check | Notes |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| EXAMPLE | AST-001 | Customer web portal | Web application or website | Cloud (we administer) | Digital Services Manager | Critical | Yes | Yes | 4 Mar 2024 | 1 Mar 2024 | 0 | On time | Weekly | Authenticated (credentials) | Yes | 24 Sep 2026 | 4 | Scanned | Success | Supported | OK | |||||||||
| EXAMPLE | AST-005 | Finance file server | Server | On-premises | IT Operations Manager | High | No | Yes | Weekly | Authenticated (credentials) | Not applicable | 10 Sep 2026 | 18 | Scan overdue | Service account password changed; scans fall back to unauthenticated | 2 Oct 2026 | Failed | 17 Sep 2026 | 24 Sep 2026 | Supported | Credential fix overdue | |||||||||
| EXAMPLE | AST-007 | Payroll application server | Server | On-premises | Finance Systems Lead | High | No | Yes | Weekly | Authenticated (credentials) | Not applicable | 23 Sep 2026 | 5 | Scanned | Success | Unsupported | Isolated network segment; access only from two finance workstations | 31 Mar 2027 | 15 Jul 2026 | OK | ||||||||||
| EXAMPLE | AST-012 | Warehouse stock system (new) | Business application | Run by a service provider | Logistics Manager | Standard | No | Yes | 14 Sep 2026 | 10 | Overdue | Monthly | Not scanned | Not applicable | Not scanned | Provider has not yet issued a scanning account | 9 Oct 2026 | Supported | Add to scanning now | |||||||||||
| EXAMPLE | AST-020 | Email and office suite | Business application | Cloud software service (SaaS) | IT Operations Manager | High | Yes | No | Cloud software service with no access to the underlying systems; covered by supplier assurance | Not applicable | Out of scope | Supported | OK |
Summary
Coverage summary
Every figure below is calculated from the Scope Register as at the date shown. Targets come from the Vulnerability & Exposure Management Standard.
| As-at date | 28 Sep 2026 | Shows today. Type a fixed date to freeze a report. |
| Measure | Result | Target | Status | What it means |
|---|---|---|---|---|
| In-scope systems | 4 | — | Systems on the register that you can and must scan (VM-01). | |
| Scanned within required frequency | 2 | — | In-scope systems whose last successful scan is recent enough for their class. | |
| Scan coverage | 50% | 95% | Below target | Scanned within frequency ÷ in-scope systems (VM-02). |
| Systems not scanned at all | 1 | 0 | Action needed | In scope, but no successful scan recorded. |
| Systems with an overdue scan | 1 | 0 | Action needed | Scanned once, but not within the required frequency. |
| Unscanned systems with no reason or scan-by date | 0 | 0 | Meets target | VM-02 requires a reason and a date for each. |
| Authenticated scans attempted | 3 | — | Systems whose last scan tried to log in (Success or Failed). | |
| Authenticated login success rate | 67% | 95% | Below target | Successful logins ÷ attempted (VM-05). |
| Credential failures not fixed within 5 working days | 1 | 0 | Action needed | VM-05: investigate and correct within 5 working days. |
| New systems not added within 5 working days | 1 | 0 | Action needed | In production, still not in scanning scope (VM-03). |
| New systems added late | 0 | 0 | Meets target | Now scanned, but added after the 5-working-day limit. |
| Internet-facing systems in scope | 1 | — | Each needs an external scan as well (VM-06). | |
| Internet-facing systems without an external scan | 0 | 0 | Meets target | What an outside attacker can reach and you cannot see. |
| Unsupported systems | 1 | — | No longer supported by their vendor (VM-15). | |
| Unsupported systems without a retirement date | 0 | 0 | Meets target | VM-15 requires compensating controls and a planned retirement date. |
| Systems out of scanning scope | 1 | — | Listed with a reason; covered by supplier assurance instead. | |
| Rows with a record check to resolve | 2 | 0 | Action needed | Any row whose Record check does not say OK. |
Coverage by criticality
| Criticality | In scope | Scanned | Coverage | Status |
|---|---|---|---|---|
| Critical | 1 | 1 | 100% | Meets target |
| High | 2 | 1 | 50% | Below target |
| Standard | 1 | 0 | 0% | Below target |
| All | 4 | 2 | 50% | Below target |
Lists
| YesNo | YesNoNA | AssetClass | Hosting | Criticality | ScanMethod | LoginResult | VendorSupport | ScanFrequency | FrequencyDays |
|---|---|---|---|---|---|---|---|---|---|
| Yes | Yes | Server | On-premises | Critical | Authenticated (credentials) | Success | Supported | Weekly | 7 |
| No | No | End-user device | Cloud (we administer) | High | Agent | Failed | Unsupported | Monthly | 31 |
| Not applicable | Network or security device | Run by a service provider | Standard | Unauthenticated only | Not applicable | Unknown | Quarterly | 92 | |
| Cloud infrastructure | Cloud software service (SaaS) | External only | |||||||
| Web application or website | Not scanned |
Business application
Other
Definitions
Definitions
| Term | Meaning in this workbook |
|---|---|
| Asset | Any system you own, run or have run for you: server, end-user device, network or security device, cloud account, business application or website. |
| Asset ID | Your unique reference for the asset, such as AST-001. The Vulnerability Remediation Tracker uses the same ID to link findings to this register. |
| Asset class | The kind of asset. It sets the required scan frequency together with criticality and internet exposure. |
| Hosting | Where the asset runs and who operates it: on your premises, in a cloud account you administer, by a service provider, or as a cloud software service (SaaS) where you have no access to the systems underneath. |
| Asset owner | The named person accountable for the asset and for fixing its vulnerabilities. Use a person in your organisation, even when a service provider operates the asset. |
| Criticality | Critical: failure or compromise would stop a core business service or expose highly sensitive data. High: significant disruption or data exposure. Standard: all other systems. |
| Internet-facing | Reachable from the internet, directly or through a published service, without first connecting to the organisation's private network. |
| In scanning scope | Yes if you can and must scan the asset under the Standard. No only when scanning is not possible for you, with the reason recorded. |
| Out-of-scope reason | Why an asset is not scanned by you, and what covers it instead (for example, supplier assurance for a cloud software service). |
| Onboarding working days | Working days (Monday to Friday, public holidays not deducted) from Date entered production to Date added to scanning, or to the As-at date while it has not been added. The Standard allows 5 (VM-03). |
| Onboarding status | On time: added within 5 working days. Pending: not yet added, still within the limit. Overdue: not yet added and past the limit. Added late: added, but after the limit. |
| Required scan frequency | Calculated from the Standard's minimum frequency table: Internet-facing systems (external scan) — Weekly; Critical and High criticality systems (internal) — Weekly; Standard criticality servers and network devices — Monthly; End-user devices (laptops, desktops) — Continuous (agent) or monthly; Cloud infrastructure and configuration — Continuous (posture tool) or weekly; Web applications and websites — Quarterly, and before major releases. The register counts Weekly as 7 days, Monthly as 31 and Quarterly as 92. |
| Scan method | Authenticated (credentials): the scanner logs in. Agent: software installed on the asset reports to the scanner. Unauthenticated only: the scanner looks from the network without logging in, and misses most missing patches. External only: scanned from outside your network. Not scanned: no scan yet. |
| Authenticated scan | A scan that logs in to the target system, or uses an installed agent, so it can see installed software and configuration. |
| External scan | A scan run from outside your network, showing what an attacker on the internet can reach (VM-06). |
| Last successful scan | The date of the most recent scan that completed against the asset. A scan that did not reach the asset does not count. |
| Scan status | Scanned: last successful scan is within the required frequency. Scan overdue: it is older than that. Not scanned: no successful scan recorded. Out of scope: not in scanning scope. |
| Scan coverage | In-scope systems scanned within their required frequency, divided by in-scope systems, as at the As-at date. The Standard's target is 95% (VM-02). |
| Not-scanned reason and scan-by date | Why an in-scope asset has not been scanned, and the date by which it will be. Required by VM-02 for every such asset. |
| Authenticated login result | Whether the last authenticated scan logged in: Success, Failed, or Not applicable where no login is attempted. |
| Authenticated login success rate | Assets with Success divided by assets with Success or Failed. The Standard's target is 95% (VM-05). |
| Credential fix due | 5 working days after the login failure was first seen (VM-05). |
| Unsupported system | An asset whose vendor no longer provides security updates. It needs compensating controls, a planned retirement date and a review at least quarterly (VM-15); the register treats a review older than 92 days as due. |
| Compensating control | A measure that reduces the risk of a weakness that cannot yet be fixed, such as isolating the system on its own network segment. |
| Supplier assurance | Checking a supplier's security through contracts, certificates, reports or questionnaires, instead of scanning their systems yourself. |
| Record check | A calculated prompt showing the first missing or late item on the row. OK means nothing is outstanding. |
| As-at date | The date every calculated status is measured against. Set on the Summary sheet; it defaults to today. |
| Working day | Monday to Friday. Public holidays are not deducted; adjust if your Standard counts them. |
| EXAMPLE row | A worked example showing how a completed row looks. Delete before approval. |
| VM-01, VM-02 … | Requirement numbers in the Vulnerability & Exposure Management Standard. |
Framework References
Framework references
These references indicate relevance only and do not reproduce the text of any standard.
| Framework | Reference | Supported by |
|---|---|---|
| ISO/IEC 27001:2022 | Annex A 5.9 — Inventory of information and other associated assets | Asset ID, owner and criticality columns |
| ISO/IEC 27001:2022 | Annex A 8.8 — Management of technical vulnerabilities | Scan status, coverage, authenticated scanning |
| NIST CSF 2.0 | ID.AM-01 — “Inventories of hardware managed by the organization are maintained” | The register as a whole |
| NIST CSF 2.0 | ID.AM-02 — “Inventories of software, services, and systems managed by the organization are maintained” | The register as a whole |
| NIST CSF 2.0 | ID.RA-01 — “Vulnerabilities in assets are identified, validated, and recorded” | Scan status, coverage |
| NIS2 — Directive (EU) 2022/2555 | Article 21(2)(e) — “security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure” | Coverage and scanning evidence |
| DORA — Regulation (EU) 2022/2554 | Article 8(1), (4) and (6) — identifying, classifying and documenting ICT assets, and keeping the inventories current | Scope, criticality, inventory |
| DORA — Delegated Regulation (EU) 2024/1774 | Article 10 — vulnerability and patch management, including automated vulnerability scanning at least weekly for ICT assets supporting critical or important functions | Required scan frequency |
| PCI DSS v4.0.1 | Requirement 12.5.1 — keeping a current inventory of in-scope system components | Scope columns |
| PCI DSS v4.0.1 | Requirement 11.3 — identifying, prioritising and addressing internal and external vulnerabilities regularly | External scan, scan frequency |
Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0; Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2022/2554 (DORA); PCI DSS v4.0.1