Skip to main content

Repository → 💼 PCI DSS v4.0 → 💼 6 Develop and Maintain Secure Systems and Software → 💼 6.3 Security vulnerabilities are identified and addressed.

💼 6.3.1 Security vulnerabilities are identified and managed.

  • ID: /frameworks/pci-dss-v4.0/06/03/01

Description

As follows:

  • New security vulnerabilities are identified using industry-recognized sources for security vulnerability information, including alerts from international and national computer emergency response teams (CERTs).
  • Vulnerabilities are assigned a risk ranking based on industry best practices and consideration of potential impact.
  • Risk rankings identify, at a minimum, all vulnerabilities considered to be a high-risk or critical to the environment.
  • Vulnerabilities for bespoke and custom, and third-party software (for example operating systems and databases) are covered.

Similar

  • Sections
    • /frameworks/pci-dss-v3.2.1/06/01
    • /frameworks/pci-dss-v4.0.1/06/03/01
  • Internal
    • ID: dec-c-c25df04d

Similar Sections (Take Policies From)

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 PCI DSS v3.2.1 → 💼 6.1 Establish a process to identify security vulnerabilities, using reputable outside sources for security vulnerability information, and assign a risk ranking to newly discovered security vulnerabilities.no data
💼 PCI DSS v4.0.1 → 💼 6.3.1 Security vulnerabilities are identified and managed.no data

Similar Sections (Give Policies To)

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 PCI DSS v3.2.1 → 💼 6.1 Establish a process to identify security vulnerabilities, using reputable outside sources for security vulnerability information, and assign a risk ranking to newly discovered security vulnerabilities.no data
💼 PCI DSS v4.0.1 → 💼 6.3.1 Security vulnerabilities are identified and managed.no data

Sub Sections

SectionSub SectionsInternal RulesPoliciesFlagsCompliance