Skip to content
arrow_back
search
E8-PA-ML2.1 bolt ASD Essential Eight

Fortnightly vulnerability scanning for non-core applications

Use a vulnerability scanner every two weeks to find missing patches in non-core applications.

record_voice_over

Plain language

This control is about regularly checking less critical applications, which aren't part of the typical office suite, for security gaps or vulnerabilities every two weeks. It's important because if these applications aren't updated, hackers could exploit weaknesses in them to access sensitive information or disrupt operations, even though they're not as commonly targeted as core applications.

Framework

ASD Essential Eight

Control effect

Detective

E8 mitigation strategy

Patch applications

Classifications

N/A

Official last update

N/A

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML2

Official control statement

A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in applications other than office productivity suites, web browsers and their extensions, email clients, PDF software, and security products.
bolt ASD Essential Eight E8-PA-ML2.1
priority_high

Why it matters

Without fortnightly scanning, unpatched non-core applications can harbour known vulnerabilities, enabling initial access, data theft, or disruption.

settings

Operational notes

Run vulnerability scans at least fortnightly across all non-core applications; track findings, validate coverage, and prioritise patching by severity and exposure.

Mapping detail

Mapping

Direction

Controls