Skip to content
arrow_back
policyASD Information Security Manual (ISM)

ASD ISM 2118Conduct Vulnerability Assessments and Penetration Tests

Vulnerability assessments and penetration tests are conducted before systems are deployed, before significant changes are deployed, and at least every six months thereafter.

record_voice_over

Plain language

This control is about testing systems for security weaknesses before you roll them out, before you deploy any big changes, and then at least every six months. It helps catch vulnerabilities before someone else does, keeping systems and data safe. If you skip these checks, attackers might find and exploit weaknesses, causing data breaches or disruptions.

Framework

ASD Information Security Manual (ISM)

Control effect

Detective

Classifications

NC, OS, P, S, TS

ISM last updated

Sept 2026

Control Stack last updated

05 Sept 2026

E8 maturity levels

N/A

Topic

Vulnerability assessments and penetration tests

Official control statement

Vulnerability assessments and penetration tests are conducted for systems prior to their deployment, including prior to the deployment of significant changes, and at least every six months thereafter.
policyASD Information Security Manual (ISM)ISM-2118
priority_high

Why it matters

If this control is not followed, systems may go live with unaddressed security flaws, leaving them open to cyber attacks. Attackers could exploit these weaknesses to steal data, disrupt services, or damage your reputation, possibly resulting in regulatory penalties and loss of customer trust.

settings

Operational notes

Regularly update the tools and techniques used for vulnerability assessments and penetration tests to reflect evolving threats. Ensure all significant system changes trigger a vulnerability assessment and penetration test before the change is deployed to maintain security integrity. Foster an organisational culture where security testing is a routine part of system management, not an afterthought.

build

Implementation tips

  • Before launching a new system, conduct a comprehensive vulnerability assessment using an automated vulnerability scanning tool. Have knowledgeable personnel run the scan to identify security defects.
  • For penetration tests, simulate attacks on your system to test its defences. Engage a certified ethical hacker or a security consultant to conduct these tests in a controlled manner before any new deployment.
  • Whenever significant changes are planned for existing systems, schedule a vulnerability assessment and penetration test to be completed before the change is deployed. Use project change logs to identify updates that would trigger these checks.
  • Establish a routine schedule to ensure that vulnerability assessments and penetration tests are performed at least every six months. Use reminders in project management tools to alert IT security staff when these tests are due.
  • Develop a process for documenting and tracking vulnerabilities and penetration test results. Ensure there is a system in place for prioritising and addressing identified issues, and record remediation actions taken.
fact_check

Audit / evidence tips

  • AskRequest documentation for vulnerability assessments conducted before system deployment and before the deployment of significant changes.Look atEnsure the documentation includes detailed scan reports showing the date and scope of the assessments.GoodReports clearly show vulnerabilities identified, with assessment dates falling before deployment and before significant changes were deployed, and remediation actions logged.
  • AskAsk for records of penetration test activities conducted prior to deployment and significant system changes.Look atReview the test reports to confirm they include objectives, methodologies used, findings, and any corrective actions.GoodA comprehensive report that outlines testing procedures, discovered vulnerabilities, and steps taken to mitigate them.
  • AskRequest the scheduling register for vulnerability assessments and penetration tests.Look atCheck scheduled dates against the requirement for six-monthly testing and pre-deployment/major changes.GoodA log showing a consistent pattern of assessments conducted on schedule, including tests completed before major changes were deployed.
  • AskAsk for the change management records for recent significant changes to in-scope systems.Look atCross-check the deployment date of each significant change against the dates of the corresponding vulnerability assessment and penetration test reports.GoodEvery significant change has a vulnerability assessment and penetration test report dated before the change went live.
  • AskRequest the vulnerability assessment and penetration test reports for the last twelve months for a sample of deployed systems.Look atCheck the interval between consecutive assessments and tests for each system in the sample.GoodNo system in the sample shows a gap of more than six months between successive vulnerability assessments and penetration tests.
link

Cross-framework mappings

How ISM-2118 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
layersPartially meets(1)expand_less
Annex A 8.8ISM-2118 requires organisations to conduct vulnerability assessments and penetration tests prior to deployment/significant changes and at...

E8

ControlNotesDetails
handshakeSupports(1)expand_less
E8-PA-ML3.1ISM-2118 requires vulnerability assessments and penetration tests before deployment and at least every six months to identify security we...
linkRelated(2)expand_less
E8-PO-ML1.1ISM-2118 requires vulnerability assessments and penetration tests to be performed before deployment and periodically thereafter
E8-PA-ML2.1ISM-2118 requires vulnerability assessments and penetration tests before deployment (and significant changes) and at least every six mont...

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for security assurance controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls