From the course: CompTIA CySA+ (CS0-002) Cert Prep: 2 Vulnerability Management (2020)

Unlock the full course today

Join today to access over 22,500 courses taught by industry experts or purchase this course individually.

Scan frequency

Scan frequency

- [Instructor] Once you've used your asset inventory to develop a list of systems that you'd like to scan, you next need to figure out how often you'd like to scan them. This may sound like a simple question. After all, why wouldn't you just want to scan all for your systems all of the time? But there are some constraints that require you to think carefully about your scanning schedule. First, you may have specific requirements imposed upon you that dictate how often you conduct scans. These may come from external sources such as laws and regulations. For example, if you're subject to PCI DSS, you'll need to run scans at least quarterly or you may have corporate policy requirements that dictate the frequency of scanning systems. Once you've cleared those regulatory requirements, you'll also need to consider your organization's risk appetite. How long are you willing to go without detecting a new vulnerability? Does…

Contents