Independent thinking. Informed defence.

CISO Times

Intelligence for the people behind the defence.

The CISO Decision Brief

Scan Coverage & Asset Scope Register

Exposes the gap between what the organisation owns and what is actually being scanned, which is the root cause of most programme failure.

Available soon

Format
Excel
Size
95 KB
Length
9 sheets
Version
1.0
Updated

What's inside

  • Instructions
  • Scope Register
  • Summary
  • Lists
  • Definitions
  • Framework References

Preview

The workbook's sheets as you will receive them, with its example rows and the values its formulas calculate. Highlighted [[text]] is for you to replace; rows marked EXAMPLE are for you to delete. Wide sheets scroll sideways. The cover, document control and changelog sheets are in the file.

Instructions

How to use this workbook

StepWhat to do
1Set the As-at date on the Summary sheet. It shows today's date; type a fixed date over it to freeze a month-end report. Every calculated status uses this date.
2On the Scope Register sheet, add one row per system from your asset inventory: servers, end-user devices (or one row per managed group of them), network and security devices, cloud accounts, business applications and websites. Give each a unique Asset ID and reuse that ID in the Vulnerability Remediation Tracker.
3Complete the yellow columns. Criticality follows the Standard's Appendix A (Critical, High, Standard). Mark Internet-facing Yes if the system can be reached from the internet without first joining your private network.
4Set In scanning scope to No only when the system cannot be scanned by you at all, such as a cloud software service with no access to the servers underneath. Record the reason; such systems stay on the register and are covered by supplier assurance instead.
5Fill Date entered production for systems introduced since the register started. The register counts working days to Date added to scanning and flags any new system not added within 5 working days (VM-03). Leave it blank for older systems.
6After each scanning cycle, update Last successful scan and Authenticated login result from your scanner's export. The register works out the required frequency from the Standard's table (section 4.3) and marks each system Scanned, Scan overdue or Not scanned.
7For every system not scanned or overdue, record why and the date by which it will be scanned (VM-02). For every failed authenticated scan, record the date the failure was first seen; the register sets a fix date 5 working days later (VM-05).
8For systems the vendor no longer supports, record the compensating controls, the planned retirement date and the date of the last quarterly review (VM-15).
9Clear every Record check that does not say OK before the monthly report. Read the Summary sheet: coverage and authenticated success are measured against the Standard's 95% targets.
10Delete the EXAMPLE rows before the register is approved. Do not type over the white calculated columns.

Legend

Yellow cells are inputs. Everything else is calculated or fixed — do not overwrite formulas.

EXAMPLERows marked EXAMPLE in the first column show how a completed row looks. Delete them before approval.

Tailoring — small organisation: one row per server and network device is enough; group laptops and desktops into a single row per managed group (for example, 'Staff laptops — 48 devices') and use the agent console's last check-in date as Last successful scan.

Tailoring — regulated financial entity: add a column naming the critical or important function each system supports, so you can show supervisors that every system behind such a function is in scope and scanned at least weekly, as Delegated Regulation (EU) 2024/1774, Article 10(2) requires. Keep superseded monthly copies as records.

Tailoring — IT run by a service provider: ask the provider to supply the scan export each cycle and fill this register from it; do not accept a 'scanned' statement without the export. Record the provider as Hosting and name your own internal asset owner, not the provider.

Frequencies: Weekly for internet-facing, Critical and High systems and cloud infrastructure; Quarterly for web applications that are not internet-facing; Monthly for everything else. If your Standard sets different frequencies, change the formula in the Required scan frequency column and the day counts on the Lists sheet.

Example rows use the template's revision date (2026-09-27) as their reference point, so their statuses change as the As-at date moves on.

Scope Register

One row per system. Yellow columns are inputs; white columns calculate. Status colours always carry a text label.

ExampleAsset IDAsset nameAsset classHostingAsset ownerCriticalityInternet-facingIn scanning scopeOut-of-scope reasonDate entered productionDate added to scanningOnboarding working daysOnboarding statusRequired scan frequencyScan methodExternal scan in placeLast successful scanDays since last scanScan statusNot-scanned reasonScan-by dateAuthenticated login resultLogin failure first seenCredential fix dueVendor supportCompensating controls (unsupported)Planned retirement dateLast unsupported reviewRecord checkNotes
EXAMPLEAST-001Customer web portalWeb application or websiteCloud (we administer)Digital Services ManagerCriticalYesYes4 Mar 20241 Mar 20240On timeWeeklyAuthenticated (credentials)Yes24 Sep 20264ScannedSuccessSupportedOK
EXAMPLEAST-005Finance file serverServerOn-premisesIT Operations ManagerHighNoYesWeeklyAuthenticated (credentials)Not applicable10 Sep 202618Scan overdueService account password changed; scans fall back to unauthenticated2 Oct 2026Failed17 Sep 202624 Sep 2026SupportedCredential fix overdue
EXAMPLEAST-007Payroll application serverServerOn-premisesFinance Systems LeadHighNoYesWeeklyAuthenticated (credentials)Not applicable23 Sep 20265ScannedSuccessUnsupportedIsolated network segment; access only from two finance workstations31 Mar 202715 Jul 2026OK
EXAMPLEAST-012Warehouse stock system (new)Business applicationRun by a service providerLogistics ManagerStandardNoYes14 Sep 202610OverdueMonthlyNot scannedNot applicableNot scannedProvider has not yet issued a scanning account9 Oct 2026SupportedAdd to scanning now
EXAMPLEAST-020Email and office suiteBusiness applicationCloud software service (SaaS)IT Operations ManagerHighYesNoCloud software service with no access to the underlying systems; covered by supplier assuranceNot applicableOut of scopeSupportedOK

Summary

Coverage summary

Every figure below is calculated from the Scope Register as at the date shown. Targets come from the Vulnerability & Exposure Management Standard.

As-at date28 Sep 2026Shows today. Type a fixed date to freeze a report.
MeasureResultTargetStatusWhat it means
In-scope systems4—Systems on the register that you can and must scan (VM-01).
Scanned within required frequency2—In-scope systems whose last successful scan is recent enough for their class.
Scan coverage50%95%Below targetScanned within frequency ÷ in-scope systems (VM-02).
Systems not scanned at all10Action neededIn scope, but no successful scan recorded.
Systems with an overdue scan10Action neededScanned once, but not within the required frequency.
Unscanned systems with no reason or scan-by date00Meets targetVM-02 requires a reason and a date for each.
Authenticated scans attempted3—Systems whose last scan tried to log in (Success or Failed).
Authenticated login success rate67%95%Below targetSuccessful logins ÷ attempted (VM-05).
Credential failures not fixed within 5 working days10Action neededVM-05: investigate and correct within 5 working days.
New systems not added within 5 working days10Action neededIn production, still not in scanning scope (VM-03).
New systems added late00Meets targetNow scanned, but added after the 5-working-day limit.
Internet-facing systems in scope1—Each needs an external scan as well (VM-06).
Internet-facing systems without an external scan00Meets targetWhat an outside attacker can reach and you cannot see.
Unsupported systems1—No longer supported by their vendor (VM-15).
Unsupported systems without a retirement date00Meets targetVM-15 requires compensating controls and a planned retirement date.
Systems out of scanning scope1—Listed with a reason; covered by supplier assurance instead.
Rows with a record check to resolve20Action neededAny row whose Record check does not say OK.

Coverage by criticality

CriticalityIn scopeScannedCoverageStatus
Critical11100%Meets target
High2150%Below target
Standard100%Below target
All4250%Below target

Lists

YesNoYesNoNAAssetClassHostingCriticalityScanMethodLoginResultVendorSupportScanFrequencyFrequencyDays
YesYesServerOn-premisesCriticalAuthenticated (credentials)SuccessSupportedWeekly7
NoNoEnd-user deviceCloud (we administer)HighAgentFailedUnsupportedMonthly31
Not applicableNetwork or security deviceRun by a service providerStandardUnauthenticated onlyNot applicableUnknownQuarterly92
Cloud infrastructureCloud software service (SaaS)External only
Web application or websiteNot scanned

Business application

Other

Definitions

Definitions

TermMeaning in this workbook
AssetAny system you own, run or have run for you: server, end-user device, network or security device, cloud account, business application or website.
Asset IDYour unique reference for the asset, such as AST-001. The Vulnerability Remediation Tracker uses the same ID to link findings to this register.
Asset classThe kind of asset. It sets the required scan frequency together with criticality and internet exposure.
HostingWhere the asset runs and who operates it: on your premises, in a cloud account you administer, by a service provider, or as a cloud software service (SaaS) where you have no access to the systems underneath.
Asset ownerThe named person accountable for the asset and for fixing its vulnerabilities. Use a person in your organisation, even when a service provider operates the asset.
CriticalityCritical: failure or compromise would stop a core business service or expose highly sensitive data. High: significant disruption or data exposure. Standard: all other systems.
Internet-facingReachable from the internet, directly or through a published service, without first connecting to the organisation's private network.
In scanning scopeYes if you can and must scan the asset under the Standard. No only when scanning is not possible for you, with the reason recorded.
Out-of-scope reasonWhy an asset is not scanned by you, and what covers it instead (for example, supplier assurance for a cloud software service).
Onboarding working daysWorking days (Monday to Friday, public holidays not deducted) from Date entered production to Date added to scanning, or to the As-at date while it has not been added. The Standard allows 5 (VM-03).
Onboarding statusOn time: added within 5 working days. Pending: not yet added, still within the limit. Overdue: not yet added and past the limit. Added late: added, but after the limit.
Required scan frequencyCalculated from the Standard's minimum frequency table: Internet-facing systems (external scan) — Weekly; Critical and High criticality systems (internal) — Weekly; Standard criticality servers and network devices — Monthly; End-user devices (laptops, desktops) — Continuous (agent) or monthly; Cloud infrastructure and configuration — Continuous (posture tool) or weekly; Web applications and websites — Quarterly, and before major releases. The register counts Weekly as 7 days, Monthly as 31 and Quarterly as 92.
Scan methodAuthenticated (credentials): the scanner logs in. Agent: software installed on the asset reports to the scanner. Unauthenticated only: the scanner looks from the network without logging in, and misses most missing patches. External only: scanned from outside your network. Not scanned: no scan yet.
Authenticated scanA scan that logs in to the target system, or uses an installed agent, so it can see installed software and configuration.
External scanA scan run from outside your network, showing what an attacker on the internet can reach (VM-06).
Last successful scanThe date of the most recent scan that completed against the asset. A scan that did not reach the asset does not count.
Scan statusScanned: last successful scan is within the required frequency. Scan overdue: it is older than that. Not scanned: no successful scan recorded. Out of scope: not in scanning scope.
Scan coverageIn-scope systems scanned within their required frequency, divided by in-scope systems, as at the As-at date. The Standard's target is 95% (VM-02).
Not-scanned reason and scan-by dateWhy an in-scope asset has not been scanned, and the date by which it will be. Required by VM-02 for every such asset.
Authenticated login resultWhether the last authenticated scan logged in: Success, Failed, or Not applicable where no login is attempted.
Authenticated login success rateAssets with Success divided by assets with Success or Failed. The Standard's target is 95% (VM-05).
Credential fix due5 working days after the login failure was first seen (VM-05).
Unsupported systemAn asset whose vendor no longer provides security updates. It needs compensating controls, a planned retirement date and a review at least quarterly (VM-15); the register treats a review older than 92 days as due.
Compensating controlA measure that reduces the risk of a weakness that cannot yet be fixed, such as isolating the system on its own network segment.
Supplier assuranceChecking a supplier's security through contracts, certificates, reports or questionnaires, instead of scanning their systems yourself.
Record checkA calculated prompt showing the first missing or late item on the row. OK means nothing is outstanding.
As-at dateThe date every calculated status is measured against. Set on the Summary sheet; it defaults to today.
Working dayMonday to Friday. Public holidays are not deducted; adjust if your Standard counts them.
EXAMPLE rowA worked example showing how a completed row looks. Delete before approval.
VM-01, VM-02 …Requirement numbers in the Vulnerability & Exposure Management Standard.

Framework References

Framework references

These references indicate relevance only and do not reproduce the text of any standard.

FrameworkReferenceSupported by
ISO/IEC 27001:2022Annex A 5.9 — Inventory of information and other associated assetsAsset ID, owner and criticality columns
ISO/IEC 27001:2022Annex A 8.8 — Management of technical vulnerabilitiesScan status, coverage, authenticated scanning
NIST CSF 2.0ID.AM-01 — “Inventories of hardware managed by the organization are maintained”The register as a whole
NIST CSF 2.0ID.AM-02 — “Inventories of software, services, and systems managed by the organization are maintained”The register as a whole
NIST CSF 2.0ID.RA-01 — “Vulnerabilities in assets are identified, validated, and recorded”Scan status, coverage
NIS2 — Directive (EU) 2022/2555Article 21(2)(e) — “security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure”Coverage and scanning evidence
DORA — Regulation (EU) 2022/2554Article 8(1), (4) and (6) — identifying, classifying and documenting ICT assets, and keeping the inventories currentScope, criticality, inventory
DORA — Delegated Regulation (EU) 2024/1774Article 10 — vulnerability and patch management, including automated vulnerability scanning at least weekly for ICT assets supporting critical or important functionsRequired scan frequency
PCI DSS v4.0.1Requirement 12.5.1 — keeping a current inventory of in-scope system componentsScope columns
PCI DSS v4.0.1Requirement 11.3 — identifying, prioritising and addressing internal and external vulnerabilities regularlyExternal scan, scan frequency

Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0; Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2022/2554 (DORA); PCI DSS v4.0.1