Does the Applicant conduct regular vulnerability scans?
Scanning is the input to patching. Without it, the patch window answer elsewhere on the form has nothing driving it.
What the carrier is actually asking
The carrier is asking whether you scan for vulnerabilities on a regular basis, across which assets, and what happens to the results. Coverage and cadence matter as much as the existence of a scanner.
Why it is underwritten
Exploitation of known vulnerabilities remains a leading initial access vector. Scanning is how you know what you have before someone else finds it, and it is the mechanism that makes a critical patch window meaningful.
Where the answer lives in Microsoft 365, Entra ID, and Azure
Cloud-native vulnerability assessment is measurable. External scanning and on-premises coverage are attested.
| Platform | Where the setting lives | What has to be true |
|---|---|---|
| Azure | Vulnerability assessment solution on virtual machines | Deployed across the machine estate rather than a subset, and reporting |
| Azure | Database vulnerability assessment and its scan reports | Enabled with recurring scans and results routed somewhere |
| Azure | Defender for Cloud recommendations and their ageing | Findings closing rather than accumulating, which is the practical measure of the programme |
| External | External scanning of internet-facing assets | Regular external scanning with dated results. Attested |
| Coverage | Assets not covered by any scanner | Known gaps, since unscanned assets are where findings hide |
Unauthenticated scanning sees what an outsider sees. Authenticated scanning sees installed software versions and missing patches, which is where most of the real findings are. If your programme is unauthenticated, it is measuring a small fraction of your exposure.
What a defensible yes requires
- Scanning runs on a defined cadence, at least monthly internally and more often externally.
- Coverage includes servers, endpoints, cloud workloads, and internet-facing assets.
- Internal scanning is authenticated.
- Findings feed a remediation process with owners and deadlines.
- Coverage gaps are known and shrinking.
How this answer goes wrong
A scanner runs weekly against a range that was defined three years ago and no longer includes the cloud estate. Reports are generated and filed, and nothing drives remediation. The organisation answers yes to both this question and the patch window question with no connection between them.
Frequently asked
How often should we scan?
Internally monthly at minimum, externally weekly or continuously. Cloud estates change constantly, which makes infrequent scanning close to meaningless.
Do we need a commercial scanner?
Cloud-native assessment covers cloud workloads well. A dedicated product usually adds coverage for on-premises and for authenticated endpoint scanning.
What about web applications?
They need application-specific scanning, which infrastructure scanners do poorly. If you publish applications, this is a separate line of work.
What evidence works?
Trend data showing findings opened and closed over time. It demonstrates a programme rather than an activity.
Related questions
Stop answering this from memory
Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.
Assess your posture