Explanatory publication Four textsNo scanning, no auditsNothing for sale

WebOps DeskSite security, plainly
Editorial team

How the texts are written

The drafting and review procedure, and why no schedules or thresholds are published.

Writing and review

  • Each text is written by one person and reviewed by another before publication.
  • We describe how controls work and how they fail, not the interface of any product.
  • Where an answer depends on what the system does, we say so instead of giving one rule.
  • Legal duties are pointed to at the competent authority rather than summarised as deadlines here.
  • Examples are generic and do not correspond to real incidents or organisations.

Why no numbers

A scan interval or a severity threshold only means something alongside a system, its change rate and what it holds. Publishing one produces either wasted effort where it is too aggressive or false confidence where it is too relaxed. Both are worse than explaining what determines the answer.

Updating

We review the texts periodically and whenever something described demonstrably changes. The date on each text is the date of the last review.