Usage guide
Topics on this page:
How to request a scan
Submit a request via the Enterprise Service Centre (ServiceNow).
- The request form will require you to provide the application details (e.g. URL, hosting environment, criticality level).
- The Risk Management team will schedule and execute the scan based on priority and availability.
- Once completed, a report will be attached to your Enterprise Service Centre ticket with scan findings and recommendations.
Scan frequency
- Scan frequency depends on application criticality and risk level.
- Certain critical apps (e.g. REDCap) are scanned quarterly.
- Teams should adjust frequency based on criticality and compliance requirements.
Requestor and scan requirements
Requestor requirements
- Must be the service or application owner or have written approval
- Must have authority to approve scans and implement mitigations
Prioritization criteria
- Critical applications (e.g. those handling sensitive Level 3 and Level 4 data)
- Applications approaching go-live
- Applications with significant changes
- Routine or periodic scans
Licensing constraints
- License allows 50 scans per quarter
- Requests may be queued or limited if demand exceeds capacity
Last modified: November 14, 2025
