ISM-1163—ISM-1163
>Control Description
Systems have a continuous monitoring plan that includes:
· conducting vulnerability scans for systems at least fortnightly
· conducting vulnerability assessments and penetration tests for systems prior to deployment, including prior to deployment of significant changes, and at least annually thereafter
· analysing identified vulnerabilities to determine their potential impact
· implementing mitigations based on risk, effectiveness and cost.
>Cross-Framework Mappings
Ask AI
Configure your API key to use AI features.