Skip to main content

๐Ÿ’ผ 12.3.4 Hardware and software technologies in use are reviewed at least once every 12 months.

Descriptionโ€‹

Including at least the following:

  • Analysis that the technologies continue to receive security fixes from vendors promptly.
  • Analysis that the technologies continue to support (and do not preclude) the entity's PCI DSS compliance.
  • Documentation of any industry announcements or trends related to a technology, such as when a vendor has announced โ€œend of lifeโ€ plans for a technology.
  • Documentation of a plan, approved by senior management, to remediate outdated technologies, including those for which vendors have announced โ€œend of lifeโ€ plans.

Similarโ€‹

  • Sections
    • /frameworks/pci-dss-v4.0/12/03/04
    • /frameworks/aws-fsbp-v1.0.0/eks/02
    • /frameworks/aws-fsbp-v1.0.0/lambda/02

Similar Sections (Take Policies From)โ€‹

SectionSub SectionsInternal RulesPoliciesFlags
๐Ÿ’ผ AWS Foundational Security Best Practices v1.0.0 โ†’ ๐Ÿ’ผ [EKS.2] EKS clusters should run on a supported Kubernetes version
๐Ÿ’ผ AWS Foundational Security Best Practices v1.0.0 โ†’ ๐Ÿ’ผ [Lambda.2] Lambda functions should use supported runtimes
๐Ÿ’ผ PCI DSS v4.0 โ†’ ๐Ÿ’ผ 12.3.4 Hardware and software technologies in use are reviewed at least once every 12 months.

Similar Sections (Give Policies To)โ€‹

SectionSub SectionsInternal RulesPoliciesFlags
๐Ÿ’ผ PCI DSS v4.0 โ†’ ๐Ÿ’ผ 12.3.4 Hardware and software technologies in use are reviewed at least once every 12 months.

Sub Sectionsโ€‹

SectionSub SectionsInternal RulesPoliciesFlags