AD

Scan Governance

Scanning is automated, but permission to scan is not. These controls decide who may start a scan, which endpoints may be scanned, and when scanning is allowed to run.

Windows & limits

Approval status before execution

Scans queued against governed endpoints

  • SC-001Full Scan — PAYROLL-DB-01Pending ApprovalProduction · window 20:00–06:00
  • SC-002Incremental Scan — CRM-APP-01ApprovedProduction · window 20:00–06:00
  • SC-003Targeted Scan — CUSTOMER-PORTALApprovedProduction · window 20:00–06:00
  • SC-004On-Demand Scan — FIN-SRV-02Pending ApprovalProduction · window 20:00–06:00
  • SC-005Re-scan — EMP-FILES-NASApprovedProduction · window 20:00–06:00
8 records
ControlGovernance ControlConfigured ValueApplies ToEnforcement
SG-001Who can create scansDiscovery Operator, Privacy AdminAll endpointsEnforced
SG-002Who can approve scansIT Security Lead, Data Protection OfficerProduction endpointsEnforced
SG-003Who can stop scansDiscovery Operator, IT Security LeadAll endpointsEnforced
SG-004Scannable endpointsOnly endpoints with a verified agent or connectorAll endpointsEnforced
SG-005Allowed scan window20:00 – 06:00 ISTProduction endpointsEnforced
SG-006Blackout periodFinancial close: 28th – 2nd of each monthFinance endpointsEnforced
SG-007Maximum concurrent scans4Tenant wideEnforced
SG-008Resource limit per scan15% CPU, 512 MB memoryAll agentsAdvisory