Control detail

External attack surface scanning

ctl-015 · DETECTIVE · WEEKLY

ctl-015

Internet-facing assets are scanned weekly for exposure.

Type
DETECTIVE
Automation
AUTOMATED
Frequency
WEEKLY
Owner
Information Security

Control Design Assessment (CDA)

Procedures evaluating whether the control is designed adequately.

No design-assessment procedures defined yet.

Control Operating Effectiveness (COE)

Procedures evaluating whether the control operated over the testing period.

No operating-effectiveness procedures defined yet.

Linked risks

  • Cloud misconfiguration exposuremitigation 2
  • Third-party software vulnerabilitymitigation 2

Framework mappings & latest test

I&S-09TVM-08
Latest test:PASS2026-05-01