Usage guide

Topics on this page:

How to request a scan

Submit a request via the Enterprise Service Centre (ServiceNow).

  • The request form will require you to provide the application details (e.g. URL, hosting environment, criticality level).
  • The Risk Management team will schedule and execute the scan based on priority and availability.
  • Once completed, a report will be attached to your Enterprise Service Centre ticket with scan findings and recommendations.

Scan frequency

  • Scan frequency depends on application criticality and risk level.
  • Certain critical apps (e.g. REDCap) are scanned quarterly.
  • Teams should adjust frequency based on criticality and compliance requirements.

Requestor and scan requirements

Requestor requirements

  • Must be the service or application owner or have written approval
  • Must have authority to approve scans and implement mitigations

Prioritization criteria

  • Critical applications (e.g. those handling sensitive Level 3 and Level 4 data)
  • Applications approaching go-live
  • Applications with significant changes
  • Routine or periodic scans

Licensing constraints

  • License allows 50 scans per quarter
  • Requests may be queued or limited if demand exceeds capacity

Last modified: November 14, 2025