Skip to content
arrow_back
search
E8-PO-ML1.4 bolt ASD Essential Eight

Use a vulnerability scanner fortnightly to find missing OS patches

Use a vulnerability scanner every two weeks to check for missing OS updates on internal systems.

record_voice_over

Plain language

Using a vulnerability scanner every two weeks helps make sure your computers and servers are safe from known security weaknesses. Without regular checks, hackers might exploit these weaknesses to access your systems and data, leading to potential data loss or business disruption.

Framework

ASD Essential Eight

Control effect

Detective

E8 mitigation strategy

PO

Classifications

N/A

Official last update

N/A

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML1

Official control statement

A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices.
bolt ASD Essential Eight E8-PO-ML1.4
priority_high

Why it matters

Missing your fortnightly scan may leave critical OS vulnerabilities unnoticed, allowing attackers to exploit them and potentially disrupt business operations.

settings

Operational notes

Run the vulnerability scanner at least fortnightly and review findings the same day to identify missing OS patches on workstations and non-internet-facing servers/devices.

Mapping detail

Mapping

Direction

Controls