πΌ 11.3.1 Internal vulnerability scans are performed.
-
Contextual name: πΌ 11.3.1 Internal vulnerability scans are performed.
-
ID:
/frameworks/pci-dss-v4.0.1/11/03/01
-
Located in: πΌ 11.3 External and internal vulnerabilities are regularly identified, prioritized, and addressed.
Descriptionβ
As follows:
- At least once every three months.
- Vulnerabilities that are either high-risk or critical (according to the entity's vulnerability risk rankings defined at Requirement 6.3.1) are resolved.
- Rescans are performed that confirm all high-risk and critical vulnerabilities (as noted above) have been resolved.
- Scan tool is kept up to date with latest vulnerability information.
- Scans are performed by qualified personnel and organizational independence of the tester exists.
Similarβ
- Sections
/frameworks/pci-dss-v4.0/11/03/01
/frameworks/aws-fsbp-v1.0.0/inspector/01
/frameworks/aws-fsbp-v1.0.0/inspector/02
Similar Sections (Take Policies From)β
Section | Sub Sections | Internal Rules | Policies | Flags |
---|---|---|---|---|
πΌ AWS Foundational Security Best Practices v1.0.0 β πΌ [Inspector.1] Amazon Inspector EC2 scanning should be enabled | ||||
πΌ AWS Foundational Security Best Practices v1.0.0 β πΌ [Inspector.2] Amazon Inspector ECR scanning should be enabled | ||||
πΌ PCI DSS v4.0 β πΌ 11.3.1 Internal vulnerability scans are performed. | 3 |
Similar Sections (Give Policies To)β
Section | Sub Sections | Internal Rules | Policies | Flags |
---|---|---|---|---|
πΌ PCI DSS v4.0 β πΌ 11.3.1 Internal vulnerability scans are performed. | 3 |