Independent thinking. Informed defence.

CISO Times

Intelligence for the people behind the defence.

The CISO Decision Brief

Vulnerability Scanner Configuration Review Checklist

Verifies that the scanning tooling is configured to produce trustworthy results before any metric derived from it is reported upward.

Available soon

Format
Excel
Size
60 KB
Length
9 sheets
Version
1.0
Updated

What's inside

  • Instructions
  • Checklist
  • Results & Sign-off
  • Lists
  • Definitions
  • Framework References

Preview

The workbook's sheets as you will receive them, with its example rows and the values its formulas calculate. Highlighted [[text]] is for you to replace; rows marked EXAMPLE are for you to delete. Wide sheets scroll sideways. The cover, document control and changelog sheets are in the file.

Instructions

How to use this workbook

StepWhat to do
1Fill in the review details at the top of the Results & Sign-off sheet: which scanners and engines are covered, who is reviewing, and the date. The review is required at least every 6 months.
2Read the four EXAMPLE rows at the top of the Checklist sheet to see how a completed row looks, then delete them — they are counted in the summary until you do.
3Work through the Checklist sheet area by area. For each check, look at the evidence named in the pass criterion. Record where the evidence is kept (a file name, ticket or report), who checked it, and the date.
4Set the Result to Pass only when the pass criterion is fully met. Otherwise set Fail and write the action and a due date. Use N/A only when the check truly does not apply, and write why.
5Fill the [[double-bracket]] values in the pass criteria with your own sample sizes and periods, or accept the suggested value. Change them before the first review, not during it.
6Watch the Record status column. It shows 'Reason missing', 'Action missing' or 'Evidence, owner or date missing' until each row is complete.
7Checks marked Yes in 'Affects reported figures' are the ones that make coverage, deadline or overdue figures wrong when they fail. The summary will not say 'Ready to report upward' while any of them has failed or is unchecked.
8Open the Results & Sign-off sheet. Read the result for each area and the overall answer to 'Ready to report upward?'. The standard owner records the decision and signs off.
9If the answer is not 'Ready', say so in the next report built from the Vulnerability Management Metrics Workbook, and name the failed checks as a limitation of the figures.
10To add your own checks, type them into the empty rows at the bottom of the Checklist table and choose an Area from the list; the summary counts them automatically.

Legend

Yellow cells are inputs. Everything else is calculated or fixed — do not overwrite formulas.

EXAMPLERows marked EXAMPLE in the first column show how a completed row looks. Delete them before approval.

Tailoring — small organisation: if a service provider or a single person runs everything, keep all nine areas but reduce the sample sizes (for example 3 instead of 10). Area 9 matters most when one account can change the scanner and hide its own results.

Tailoring — regulated financial entity: keep evidence for every Pass, not only for failures, because supervisors ask how the figures in management reports were assured. Add checks for any scanning frequency or scope set in your ICT risk management framework, and repeat the review before each report to the management body.

Tailoring — IT run by a service provider: ask the provider to complete the checklist and supply the evidence, and have the standard owner review it and sign off. Check AC-03 first — without read access to raw results you cannot verify anything else.

A Fail is a finding about the scanner, not about the people running it. Fix it, record it and re-run the check; the history of reviews is the evidence that the control works.

Checklist

One row per check. Yellow cells are yours to complete. Rows marked EXAMPLE show a completed row — delete them before the review is signed off.

Check IDAreaCheckPass criterionStandard referenceAffects reported figuresEvidence referenceChecked byDate checkedResultReason (N/A) or action and owner (Fail)Action dueRecord status
EXAMPLE3. Definitions and scanner healthVulnerability definitions update at least dailyAt the time of review, every scanning engine and agent policy shows a definitions update within the last 24 hours, and the update history shows no gap longer than 24 hours in the last 30 days.VM-07YesScreenshot of update history, 30 days, saved to [[evidence folder]]/2026-09IT Operations Manager14 Sep 2026PassComplete
EXAMPLE2. Authenticated scanning and credentialsAuthenticated logins succeedAt least 95% of authenticated scans in the last period logged in successfully, taken from the scanner's own login report rather than estimated.VM-05YesLogin success report for August: 88% (132 of 150)IT Operations Manager14 Sep 2026FailService account locked on 18 servers after password change. Reset and re-test.21 Sep 2026Complete
EXAMPLE5. External scanningPayment card scans are in place, where they applyWhere payment card data is handled: external scans at least every three months by an approved scanning vendor, with passing results retained. Otherwise mark N/A with the reason.§4.3 guidanceNoHead of Information Security15 Sep 2026N/ANo payment card data is stored, processed or transmitted; card payments are handled entirely by an outsourced payment page.Complete
EXAMPLE7. Exclusions and suppressionsEvery exclusion has a reason, an owner and a review dateEvery excluded system, address range or check is listed with the reason, the person who approved it and a review date.VM-02YesExclusions list exported 2026-09-15; 6 entries, all with reason, approver and review dateHead of Information Security15 Sep 2026PassComplete
SC-011. Scope and asset coverageScan targets match the asset registerEvery in-scope system in the Scan Coverage & Asset Scope Register is in at least one scan target group or has a working agent. Reconciled within the last [[30]] days; differences listed with a reason.VM-01, VM-02YesNot yet checked
SC-021. Scope and asset coverageCoverage in the last complete period meets the targetAt least 95% of in-scope systems were successfully scanned in the last complete period. Every system not scanned is listed with a reason and a date by which it will be.VM-02YesNot yet checked
SC-031. Scope and asset coverageNew systems enter scanning promptlyFor a sample of [[5]] systems that went live since the last review, each was added to scanning before, or within 5 working days of, going into production.VM-03NoNot yet checked
SC-041. Scope and asset coverageEvery network range and cloud account is coveredEvery internal network range and every cloud account or subscription the organisation administers is either a scan target or a recorded exclusion with a reason.VM-01YesNot yet checked
SC-051. Scope and asset coverageRetired systems have been removedSystems retired since the last review are removed from scan targets and the register, and their open findings are closed with the retirement recorded as evidence.VM-01NoNot yet checked
SC-061. Scope and asset coverageCriticality and internet-facing tags are correct in the scannerFor a sample of [[10]] systems, the criticality (Critical, High, Standard) and internet-facing flag held in the scanner or tracker match the register. Priorities depend on both.VM-01; §5.1YesNot yet checked
AU-012. Authenticated scanning and credentialsServers and end-user devices are scanned with credentials or an agentAuthenticated scanning or an installed agent is used wherever the technology allows. Systems scanned without credentials are listed with the technical reason.VM-04YesNot yet checked
AU-022. Authenticated scanning and credentialsAuthenticated logins succeedAt least 95% of authenticated scans in the last period logged in successfully, taken from the scanner's own login report rather than estimated.VM-05YesNot yet checked
AU-032. Authenticated scanning and credentialsCredential failures are fixed quicklyThe last [[5]] credential failures were each investigated and corrected within 5 working days.VM-05NoNot yet checked
AU-042. Authenticated scanning and credentialsScanning accounts have only the rights they needScanning uses dedicated accounts, not personal administrator accounts. Each has only the rights needed to read software and configuration, and interactive login is disabled where the platform allows.A.8.9NoNot yet checked
AU-052. Authenticated scanning and credentialsScanning credentials are stored and rotated safelyCredentials are held only in the scanner's encrypted store or a password vault — not in scripts, spreadsheets or email — and are changed [[every 12 months]] and when someone who knew them leaves.A.8.9NoNot yet checked
AU-062. Authenticated scanning and credentialsAgents are reporting inWhere agents are used, at least [[95%]] of devices have reported within the last [[7]] days. Devices whose agents have gone silent are listed with an owner.VM-02, VM-04YesNot yet checked
DU-013. Definitions and scanner healthVulnerability definitions update at least dailyAt the time of review, every scanning engine and agent policy shows a definitions update within the last 24 hours, and the update history shows no gap longer than 24 hours in the last 30 days.VM-07YesNot yet checked
DU-023. Definitions and scanner healthScanner software is supported and currentEvery scanning engine runs a version its supplier still supports, and no more than [[one]] release behind the current one.VM-07NoNot yet checked
DU-033. Definitions and scanner healthEvery scanning engine is onlineAll scanning engines, sensors and collectors are online and have completed a scan in the last [[7]] days. None has failed silently.VM-02YesNot yet checked
DU-043. Definitions and scanner healthUpdate and engine failures raise an alertA failed definitions update or an offline engine sends an alert to a named person, and the last such alert (or a test) is recorded.VM-07NoNot yet checked
SF-014. Scan schedulesInternet-facing systems are scanned on scheduleA schedule exists at the minimum frequency (weekly) and the last [[4]] runs completed.§4.3YesNot yet checked
SF-024. Scan schedulesCritical and High systems are scanned on scheduleInternal scans of Critical and High criticality systems run at least weekly, and the last [[4]] runs completed.§4.3YesNot yet checked
SF-034. Scan schedulesStandard servers and network devices are scanned on scheduleThese systems are scanned at least monthly, and the last [[3]] runs completed.§4.3YesNot yet checked
SF-044. Scan schedulesEnd-user devices are scanned on scheduleLaptops and desktops are scanned continuous (agent) or monthly, with results from the last period for at least [[95%]] of devices.§4.3YesNot yet checked
SF-054. Scan schedulesCloud infrastructure is assessed on scheduleCloud infrastructure and configuration are assessed continuous (posture tool) or weekly.§4.3YesNot yet checked
SF-064. Scan schedulesWeb applications are scanned on scheduleWeb applications and websites are scanned quarterly, and before major releases; the last major release had a scan before go-live.§4.3NoNot yet checked
SF-074. Scan schedulesScans are not cut shortNo scheduled scan in the last period was stopped by a time window or time-out without being re-run. Partial scans are visible in the scan history.VM-02YesNot yet checked
SF-084. Scan schedulesAn urgent scan can be run on demandWhen a widely exploited vulnerability is announced, internet-facing systems can be scanned for it within [[24 hours]]. The last occasion (or a test) is recorded.§4.3NoNot yet checked
EX-015. External scanningInternet-facing systems are scanned from outsideExternal scans run from outside the organisation's network against every internet-facing address and host name in the register.VM-06YesNot yet checked
EX-025. External scanningThe external target list is completeThe external target list was reconciled within the last [[90]] days against public name (DNS) records, public address allocations and cloud services with public addresses.VM-06YesNot yet checked
EX-035. External scanningPayment card scans are in place, where they applyWhere payment card data is handled: external scans at least every three months by an approved scanning vendor, with passing results retained. Otherwise mark N/A with the reason.§4.3 guidanceNoNot yet checked
SP-016. Scan settingsScans look at every relevant port and serviceInternet-facing systems are scanned across all network ports. Internal scans use the port range set in the scan policy; any 'common ports only' setting is a recorded decision.VM-02YesNot yet checked
SP-026. Scan settingsDisruptive checks are limited by decision, not by defaultChecks that could disrupt fragile systems (such as industrial equipment or old printers) are switched off only for those systems, by a recorded decision — not across the whole estate.A.8.9NoNot yet checked
SP-036. Scan settingsSeverity ratings are unmodifiedThe scanner's severity ratings (Critical, High, Medium, Low) come from the published rating method. Any local change to a rating is recorded and approved.§5.1YesNot yet checked
SP-046. Scan settingsExploited vulnerabilities are flaggedThe scanner, or the triage process, flags findings listed in a known-exploited vulnerabilities catalogue, so that Priority 1 and 2 can be set.§5.1YesNot yet checked
SP-056. Scan settingsChanges to the scanner are controlledChanges to scan targets, policies, schedules and exclusions since the last review appear in change records with who approved them.A.8.9NoNot yet checked
XS-017. Exclusions and suppressionsEvery exclusion has a reason, an owner and a review dateEvery excluded system, address range or check is listed with the reason, the person who approved it and a review date.VM-02YesNot yet checked
XS-027. Exclusions and suppressionsExclusions were reviewed at this reviewEach exclusion was reviewed at this review. Those no longer justified were removed and the systems brought back into scanning.VM-02YesNot yet checked
XS-037. Exclusions and suppressionsFalse-positive suppressions have evidence and approvalEvery finding suppressed as a false positive has recorded evidence and the standard owner's approval.VM-14YesNot yet checked
XS-047. Exclusions and suppressionsRisk-accepted suppressions match approved exceptionsEvery finding suppressed as an accepted risk matches an approved exception with an expiry no more than 90 days after approval. No suppression outlives its exception.VM-17YesNot yet checked
RI-018. Integrity of resultsEach finding is counted onceThe same vulnerability on the same system is counted once, even when it is found by more than one scanner, agent or scan.VM-11YesNot yet checked
RI-028. Integrity of resultsFindings close only on evidenceIn a sample of [[10]] closed findings, each was closed because a later scan no longer found it, or with other objective evidence attached — not because a ticket was marked done.VM-13YesNot yet checked
RI-038. Integrity of resultsThe first detection date is keptRescans and re-imports keep each finding's original first-detection date, so deadlines are counted from first detection.VM-08YesNot yet checked
RI-048. Integrity of resultsThe tracker agrees with the scannerThe number of open Priority 1–3 findings in the scanner matches the Vulnerability Remediation Tracker to within [[2%]], and the difference is explained.VM-11YesNot yet checked
RI-058. Integrity of resultsScan results are kept long enoughScan results and schedules are retained for [[12 months]], or the period set in the Standard's records table.§9NoNot yet checked
RI-068. Integrity of resultsReports use the agreed definitionsFigures reported upward are calculated with the definitions in the Vulnerability Management Metrics Workbook.VM-21NoNot yet checked
AC-019. Access to the scannerAdministrator access is limited and reviewedOnly named people can change the scanner. The list was reviewed at this review and leavers have been removed.A.8.9NoNot yet checked
AC-029. Access to the scannerSign-in to the scanner uses multi-factor authenticationEvery administrator sign-in to the scanner's management console requires multi-factor authentication.A.8.9NoNot yet checked
AC-039. Access to the scannerThe organisation can see raw resultsWhere a service provider runs the scanner, the organisation has read access to raw results and to the configuration, not only to summary reports.§13 tailoringNoNot yet checked
AC-049. Access to the scannerChanges on the scanner are loggedThe scanner's own activity log is switched on and retained, so changes to targets, exclusions and suppressions can be traced to a person.A.8.9NoNot yet checked

Results & Sign-off

Results and sign-off

Calculated from the Checklist sheet. Only the yellow cells are yours to complete. The answer to 'Ready to report upward?' is stated in words: there is no score, because one failed check that affects reported figures matters more than any number of passes.

Review details

FieldValue
Scanners and engines covered by this review[[e.g. internal scanner, endpoint agents, external scanning service]]
Reviewer (name and role)[[Name, role]]
Date of this review15 Sep 2026EXAMPLE date — replace

Date of the previous review

Next review due (at the latest)15 Mar 2027No more than 6 months after this review (VM-07).

Results by area

AreaChecksPassFailN/ANot yet checkedFailed, affects figuresArea status
1. Scope and asset coverage600060In progress
2. Authenticated scanning and credentials701061Blocking failure
3. Definitions and scanner health510040In progress
4. Scan schedules800080In progress
5. External scanning400130In progress
6. Scan settings500050In progress
7. Exclusions and suppressions510040In progress
8. Integrity of results600060In progress
9. Access to the scanner400040In progress

Includes the EXAMPLE rows until you delete them, and any checks you add with an Area chosen from the list.

Overall

MeasureCount
Checks in total50
Passed2
Failed1
Not applicable1
Not yet checked46
Failed checks that affect reported figures1
Unchecked checks that affect reported figures28
Rows missing a reason, action, evidence, owner or date0
Ready to report upward?Not ready
Why1 failed check(s) would make reported coverage, deadline or overdue figures wrong. Fix them first, or report the figures with this limitation stated and approved by the standard owner.

Sign-off

FieldValue
Reviewed by (name, role)[[Name, role]]

Reviewer's date

Standard owner's decision

Standard owner (name)[[Name]]

Decision date

Conditions or comments[[e.g. report coverage with the note that 18 servers were scanned without credentials in August]]

The decision should follow the answer above. If the owner decides to report despite a 'Not ready' answer, the conditions must say which figures are affected and how.

Lists

ResultYesNoAreaDecision
PassYes1. Scope and asset coverageFigures may be reported upward
FailNo2. Authenticated scanning and credentialsReport with the limitations stated
N/A3. Definitions and scanner healthDo not report until fixed

4. Scan schedules

5. External scanning

6. Scan settings

7. Exclusions and suppressions

8. Integrity of results

9. Access to the scanner

Definitions

Definitions

TermMeaning in this workbook
Affects reported figuresA check marked Yes here would make scan coverage, deadline adherence or overdue figures wrong if it failed. The summary will not show 'Ready' while any of these has failed or is unchecked.
AgentSoftware installed on a device that reports its installed software and configuration to the scanner, instead of the scanner logging in over the network.
Authenticated scanA scan that logs in to the target system with valid credentials, or uses an installed agent, so it can see installed software and configuration. It finds far more missing patches than a scan that does not log in.
Definitions (vulnerability definitions)The scanner supplier's list of known vulnerabilities and how to detect them, updated as new vulnerabilities are published. A scanner with old definitions reports a clean result for vulnerabilities it does not yet know.
ExclusionA system, address range or check deliberately left out of scanning. Every exclusion lowers true coverage, so each needs a reason, an approver and a review date.
External scanA scan run from outside the organisation's network, showing what an attacker on the internet can reach.
False positiveA finding reported by the scanner that is not actually present. Suppressing one needs evidence and approval (VM-14).
Internet-facingReachable from the internet, directly or through a published service, without first connecting to the organisation's private network.
N/A (not applicable)The check does not apply to this organisation or this scanner — for example, payment card scans where no card data is handled. Always give the reason.
Scan coverageThe percentage of in-scope systems successfully scanned in the period (VM-02).
Scanning engineThe component that actually runs scans — a server, appliance, cloud service or sensor. Larger estates have several.
SuppressionA setting that hides a finding from reports, usually for a false positive or an accepted risk. A suppression that outlives its reason hides real exposure.
Standard referenceThe requirement in the Vulnerability & Exposure Management Standard that the check tests (VM-xx), or its section number. A.8.9 marks checks that come from configuration management rather than the Standard.

Framework References

Framework references

These references indicate relevance only and do not reproduce the text of any standard.

FrameworkReferenceSupported by
ISO/IEC 27001:2022Annex A 8.8 — Management of technical vulnerabilitiesAreas 1 to 8
ISO/IEC 27001:2022Annex A 8.9 — Configuration managementAreas 2, 6 and 9
NIST CSF 2.0ID.RA-01 — “Vulnerabilities in assets are identified, validated, and recorded”Areas 1 to 8
NIST CSF 2.0PR.PS-01 — “Configuration management practices are established and applied”Areas 2, 6 and 9
PCI DSS v4.0.1Requirement 11.3 — identifying, prioritising and addressing internal and external vulnerabilities regularlyAreas 2, 4 and 5
DORA — Regulation (EU) 2022/2554Article 9 — protection and prevention, including documented policies for patches and updates (Article 9(4)(f))Whole checklist
DORA — Delegated Regulation (EU) 2024/1774Article 10 — vulnerability and patch management, including automated vulnerability scanning at least weekly for ICT assets supporting critical or important functionsAreas 1, 4 and 8

Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0; Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2022/2554 (DORA); PCI DSS v4.0.1