ASD ISM 2118Conduct Vulnerability Assessments and Penetration Tests
Vulnerability assessments and penetration tests are conducted before systems are deployed, before significant changes are deployed, and at least every six months thereafter.
Plain language
This control is about testing systems for security weaknesses before you roll them out, before you deploy any big changes, and then at least every six months. It helps catch vulnerabilities before someone else does, keeping systems and data safe. If you skip these checks, attackers might find and exploit weaknesses, causing data breaches or disruptions.
Framework
ASD Information Security Manual (ISM)
Control effect
Detective
Classifications
NC, OS, P, S, TS
ISM last updated
Sept 2026
Control Stack last updated
05 Sept 2026
E8 maturity levels
N/A
Guideline
Guidelines for security assuranceSection
Security assessmentsTopic
Vulnerability assessments and penetration tests
Official control statement
Vulnerability assessments and penetration tests are conducted for systems prior to their deployment, including prior to the deployment of significant changes, and at least every six months thereafter.
Why it matters
If this control is not followed, systems may go live with unaddressed security flaws, leaving them open to cyber attacks. Attackers could exploit these weaknesses to steal data, disrupt services, or damage your reputation, possibly resulting in regulatory penalties and loss of customer trust.
Operational notes
Regularly update the tools and techniques used for vulnerability assessments and penetration tests to reflect evolving threats. Ensure all significant system changes trigger a vulnerability assessment and penetration test before the change is deployed to maintain security integrity. Foster an organisational culture where security testing is a routine part of system management, not an afterthought.
Implementation tips
- Before launching a new system, conduct a comprehensive vulnerability assessment using an automated vulnerability scanning tool. Have knowledgeable personnel run the scan to identify security defects.
- For penetration tests, simulate attacks on your system to test its defences. Engage a certified ethical hacker or a security consultant to conduct these tests in a controlled manner before any new deployment.
- Whenever significant changes are planned for existing systems, schedule a vulnerability assessment and penetration test to be completed before the change is deployed. Use project change logs to identify updates that would trigger these checks.
- Establish a routine schedule to ensure that vulnerability assessments and penetration tests are performed at least every six months. Use reminders in project management tools to alert IT security staff when these tests are due.
- Develop a process for documenting and tracking vulnerabilities and penetration test results. Ensure there is a system in place for prioritising and addressing identified issues, and record remediation actions taken.
Audit / evidence tips
- AskRequest documentation for vulnerability assessments conducted before system deployment and before the deployment of significant changes.Look atEnsure the documentation includes detailed scan reports showing the date and scope of the assessments.GoodReports clearly show vulnerabilities identified, with assessment dates falling before deployment and before significant changes were deployed, and remediation actions logged.
- AskAsk for records of penetration test activities conducted prior to deployment and significant system changes.Look atReview the test reports to confirm they include objectives, methodologies used, findings, and any corrective actions.GoodA comprehensive report that outlines testing procedures, discovered vulnerabilities, and steps taken to mitigate them.
- AskRequest the scheduling register for vulnerability assessments and penetration tests.Look atCheck scheduled dates against the requirement for six-monthly testing and pre-deployment/major changes.GoodA log showing a consistent pattern of assessments conducted on schedule, including tests completed before major changes were deployed.
- AskAsk for the change management records for recent significant changes to in-scope systems.Look atCross-check the deployment date of each significant change against the dates of the corresponding vulnerability assessment and penetration test reports.GoodEvery significant change has a vulnerability assessment and penetration test report dated before the change went live.
- AskRequest the vulnerability assessment and penetration test reports for the last twelve months for a sample of deployed systems.Look atCheck the interval between consecutive assessments and tests for each system in the sample.GoodNo system in the sample shows a gap of more than six months between successive vulnerability assessments and penetration tests.
Cross-framework mappings
How ISM-2118 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
layersPartially meets(1)expand_less | ||
| Annex A 8.8 | ISM-2118 requires organisations to conduct vulnerability assessments and penetration tests prior to deployment/significant changes and at... | |
E8
| Control | Notes | Details |
|---|---|---|
handshakeSupports(1)expand_less | ||
| E8-PA-ML3.1 | ISM-2118 requires vulnerability assessments and penetration tests before deployment and at least every six months to identify security we... | |
linkRelated(2)expand_less | ||
| E8-PO-ML1.1 | ISM-2118 requires vulnerability assessments and penetration tests to be performed before deployment and periodically thereafter | |
| E8-PA-ML2.1 | ISM-2118 requires vulnerability assessments and penetration tests before deployment (and significant changes) and at least every six mont... | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Security assurance
See all Guidelines for security assurance controls, or browse the full ASD ISM library.