← Field notesThe control explained · 21 Sep 2026

Control 2402: monthly is fixed, the timeline is yours.

Control 2402 of Def Stan 05-138 Issue 4 is the one an assessor will use to test your vulnerability management. It applies at Cyber Risk Profile Levels 1, 2 and 3. Verbatim, it asks for three things.

  1. Vulnerability scans on a monthly basis and during any major system or application updates.
  2. Vendor patches or fixes prioritised using CVSS v3 scoring.
  3. A Risk Treatment Plan to address identified vulnerabilities.

Then: vulnerabilities addressed in accordance with the Supplier's internal remediation timelines and in line with reasonable industry standards.

Two things people get wrong about it.

First, the scan cadence is fixed. Monthly. A quarterly scan does not meet it, however good the report.

Second, the remediation timeline is not fixed. The standard points at your own policy and asks whether you met it. That means the policy you write is the thing you will be assessed against. Write one you can meet, then keep the evidence that you did.

What an assessor will ask for: dated scan reports for each month, the treatment plan, and the record of what was fixed, accepted or deferred, and why.

Source: Def Stan 05-138 Issue 4, control 2402 Vulnerability management, read at source. Levels from the control table (L1, L2, L3).

Written by Ben Brand, Velinor. The method behind these notes runs as Picket by Velinor.

More notes