Vulnerability scanning tools allow the automated scheduling of scans to take the
burden off administrators. Administrators may designate a schedule that
meets their security, compliance, and business requirements.
Many security teams configure their scans to produce automated email reports of scan
results. Many different factors influence how often an organization decides to conduct vulnerability scans against its systems:
- The organisation's **risk appetite** is its willingness to tolerate risk within the environment. If an organisation is extremely risk averse, it may choose to conduct scans more frequently to minimise the amount of time between when a vulnerability comes into existence and when it is detected by a scan.
- **Regulatory requirements**, such as those imposed by the Payment Card Industry Data Security Standard ([[Payment Card Industry Data Security Standard|PCI DSS]]) or the Federal Information Security Management Act (FISMA), may dictate a minimum frequency for vulnerability scans. These requirements may also come from corporate policies.
- **Technical constraints** may limit the frequency of scanning. For example, the scanning *system may only be capable of performing a certain number of scans per day*, and organisations may need to adjust scan frequency to ensure that all scans complete successfully.
- **Business constraints** may *limit* the organization from conducting resource-intensive vulnerability scans *during periods of high business activity* to avoid disruption of critical processes.
- **Licensing limitations** may curtail the bandwidth consumed by the scanner or the number of scans that may be conducted simultaneously.
It is usually wise to *begin small and slowly expand the scope and frequency of vulnerability scans over time* to avoid overwhelming the scanning infrastructure or enterprise systems.