Skip to content
arrow_back
search
E8-PO-ML3.2 bolt ASD Essential Eight

At least fortnightly use of a vulnerability scanner for firmware

Use a vulnerability scanner every two weeks to find and update missing firmware patches.

record_voice_over

Plain language

This control means that every two weeks, your organisation uses a special tool to check if your devices need important updates for their firmware. Firmware is like the inner software for your hardware, and if it's not updated, your devices could be left open to attacks. Without these checks, hackers could exploit weaknesses in your devices, putting your entire system at risk.

Framework

ASD Essential Eight

Control effect

Detective

E8 mitigation strategy

PO

Classifications

N/A

Official last update

N/A

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML3

Official control statement

A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in firmware.
bolt ASD Essential Eight E8-PO-ML3.2
priority_high

Why it matters

Neglecting fortnightly firmware scans can leave critical hardware vulnerabilities exposed to persistent threats, endangering system integrity.

settings

Operational notes

Run a firmware vulnerability scanner at least fortnightly across all device types; keep signatures current and promptly patch or update any flagged firmware.

Mapping detail

Mapping

Direction

Controls