Scan Governance
Scanning is automated, but permission to scan is not. These controls decide who may start a scan, which endpoints may be scanned, and when scanning is allowed to run.
Windows & limits
Approval status before execution
Scans queued against governed endpoints
- SC-001Full Scan — PAYROLL-DB-01Pending ApprovalProduction · window 20:00–06:00
- SC-002Incremental Scan — CRM-APP-01ApprovedProduction · window 20:00–06:00
- SC-003Targeted Scan — CUSTOMER-PORTALApprovedProduction · window 20:00–06:00
- SC-004On-Demand Scan — FIN-SRV-02Pending ApprovalProduction · window 20:00–06:00
- SC-005Re-scan — EMP-FILES-NASApprovedProduction · window 20:00–06:00
8 records
| Control | Governance Control | Configured Value | Applies To | Enforcement |
|---|---|---|---|---|
| SG-001 | Who can create scans | Discovery Operator, Privacy Admin | All endpoints | Enforced |
| SG-002 | Who can approve scans | IT Security Lead, Data Protection Officer | Production endpoints | Enforced |
| SG-003 | Who can stop scans | Discovery Operator, IT Security Lead | All endpoints | Enforced |
| SG-004 | Scannable endpoints | Only endpoints with a verified agent or connector | All endpoints | Enforced |
| SG-005 | Allowed scan window | 20:00 – 06:00 IST | Production endpoints | Enforced |
| SG-006 | Blackout period | Financial close: 28th – 2nd of each month | Finance endpoints | Enforced |
| SG-007 | Maximum concurrent scans | 4 | Tenant wide | Enforced |
| SG-008 | Resource limit per scan | 15% CPU, 512 MB memory | All agents | Advisory |