Skip to main content

πŸ’Ό 11.3.1 Internal vulnerability scans are performed.

  • ID: /frameworks/pci-dss-v4.0/11/03/01

Description​

As follows:

  • At least once every three months.
  • High-risk and critical vulnerabilities (per the entity's vulnerability risk rankings defined at Requirement 6.3.1) are resolved.
  • Rescans are performed that confirm all high-risk and critical vulnerabilities (as noted above) have been resolved.
  • Scan tool is kept up to date with latest vulnerability information.
  • Scans are performed by qualified personnel and organizational independence of the tester exists.

Similar​

  • Sections
    • /frameworks/pci-dss-v3.2.1/11/02/01
    • /frameworks/pci-dss-v4.0.1/11/03/01
  • Internal
    • ID: dec-c-468c6e02

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
πŸ’Ό PCI DSS v3.2.1 β†’ πŸ’Ό 11.2.1 Perform quarterly internal vulnerability scans. Address vulnerabilities and perform rescans to verify all β€œhigh risk” vulnerabilities are resolved in accordance with the entity's vulnerability ranking.2no data
πŸ’Ό PCI DSS v4.0.1 β†’ πŸ’Ό 11.3.1 Internal vulnerability scans are performed.32no data

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
πŸ’Ό PCI DSS v3.2.1 β†’ πŸ’Ό 11.2.1 Perform quarterly internal vulnerability scans. Address vulnerabilities and perform rescans to verify all β€œhigh risk” vulnerabilities are resolved in accordance with the entity's vulnerability ranking.2no data
πŸ’Ό PCI DSS v4.0.1 β†’ πŸ’Ό 11.3.1 Internal vulnerability scans are performed.32no data

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
πŸ’Ό 11.3.1.1 All other applicable vulnerabilities (those not ranked as high-risk or critical) are managed.no data
πŸ’Ό 11.3.1.2 Internal vulnerability scans are performed via authenticated scanning.no data
πŸ’Ό 11.3.1.3 Internal vulnerability scans are performed after any significant change.no data

Policies (2)​

PolicyLogic CountFlagsCompliance
πŸ›‘οΈ AWS Inspector EC2 Scanning is not enabled🟒1🟒 x6no data
πŸ›‘οΈ AWS Inspector ECR Scanning is not enabled🟒1🟒 x6no data