9.2. Vulnerability Analysis Objective: Recommended Control 1: Recommended Control 2: Recommended Control 3: Exploitable information system weaknesses can be identified by vulnerability analyses and inform risks to systems Agencies should implement a vulnerability analysis strategy by: monitoring public domain information about new vulnerabilities in operating systems and application software considering the use of automated tools to perform vulnerability assessments on systems in a controlled manner running manual checks against system configurations to ensure that only allowed services are active and that disallowed services are prevented using security checklists for operating systems and common applications examining any significant incidents on the agency’s systems Agencies should conduct vulnerability assessments in order to establish a baseline: before a system is first used after any significant incident after a significant change to the system after changes to standards, policies and guidelines as specified by an ITSM or the system owner Agencies should analyse and treat all vulnerabilities and subsequent security risks to their systems identified during a vulnerability assessment Vulnerabilities may be unintentionally introduced and new vulnerabilities are constantly identified, presenting ongoing risks to information systems security. Vulnerabilities may occur as a result of poorly designed or implemented information security practices, accidental activities or malicious activities, and not just as the result of a technical issue. A baseline or known point of origin is the basis of any comparison and allows measurement of changes and improvements when further information security monitoring activities are conducted. 38

Select target paragraph3