Skip to main content

๐Ÿ’ผ 6.5.6 All โ€œhigh riskโ€ vulnerabilities identified in the vulnerability identification process.

  • ID: /frameworks/pci-dss-v3.2.1/06/05/06

Descriptionโ€‹

As defined in PCI DSS Requirement 6.1

Similarโ€‹

  • Sections
    • /frameworks/pci-dss-v4.0/06/02/04
  • Internal
    • ID: dec-c-2a68e591

Similar Sections (Take Policies From)โ€‹

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
๐Ÿ’ผ PCI DSS v4.0 โ†’ ๐Ÿ’ผ 6.2.4 Software engineering techniques or other methods are defined and in use by software development personnel to prevent or mitigate common software attacks and related vulnerabilities in bespoke and custom software.5no data

Similar Sections (Give Policies To)โ€‹

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
๐Ÿ’ผ PCI DSS v4.0 โ†’ ๐Ÿ’ผ 6.2.4 Software engineering techniques or other methods are defined and in use by software development personnel to prevent or mitigate common software attacks and related vulnerabilities in bespoke and custom software.5no data

Sub Sectionsโ€‹

SectionSub SectionsInternal RulesPoliciesFlagsCompliance

Policies (5)โ€‹

PolicyLogic CountFlagsCompliance
๐Ÿ›ก๏ธ AWS ECR Repository Manual Scanning is enabled๐ŸŸข1๐ŸŸข x6no data
๐Ÿ›ก๏ธ AWS ELB Application Load Balancer is not configured to drop invalid HTTP headers๐ŸŸข1๐ŸŸข x6no data
๐Ÿ›ก๏ธ AWS ELB Load Balancer is not configured with defensive or strictest desync mitigation mode๐ŸŸข1๐ŸŸข x6no data
๐Ÿ›ก๏ธ AWS Inspector Lambda Code Scanning is not enabled๐ŸŸข1๐ŸŸข x6no data
๐Ÿ›ก๏ธ AWS Inspector Lambda Standard Scanning is not enabled๐ŸŸข1๐ŸŸข x6no data