Skip to main content

πŸ’Ό 11.3.2 External vulnerability scans are performed.

Description​

As follows:

  • At least once every three months.
  • By a PCI SSC Approved Scanning Vendor (ASV).
  • Vulnerabilities are resolved and ASV Program Guide requirements for a passing scan are met.
  • Rescans are performed as needed to confirm that vulnerabilities are resolved per the ASV Program Guide requirements for a passing scan.

Similar​

  • Sections
    • /frameworks/pci-dss-v3.2.1/11/02/02
    • /frameworks/pci-dss-v4.0.1/11/03/02

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό PCI DSS v3.2.1 β†’ πŸ’Ό 11.2.2 Perform quarterly external vulnerability scans, via an Approved Scanning Vendor (ASV) approved by the Payment Card Industry Security Standards Council (PCI SSC).
πŸ’Ό PCI DSS v4.0.1 β†’ πŸ’Ό 11.3.2 External vulnerability scans are performed.1

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό PCI DSS v3.2.1 β†’ πŸ’Ό 11.2.2 Perform quarterly external vulnerability scans, via an Approved Scanning Vendor (ASV) approved by the Payment Card Industry Security Standards Council (PCI SSC).
πŸ’Ό PCI DSS v4.0.1 β†’ πŸ’Ό 11.3.2 External vulnerability scans are performed.1

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό 11.3.2.1 External vulnerability scans are performed after any significant change.