Skip to main content

💼 11.3.2.1 External vulnerability scans are performed after any significant change.

Description​

As follows:

  • Vulnerabilities that are scored 4.0 or higher by the CVSS are resolved.
  • Rescans are conducted as needed.
  • Scans are performed by qualified personnel and organizational independence of the tester exists (not required to be a QSA or ASV).

Similar​

  • Sections
    • /frameworks/pci-dss-v3.2.1/11/02/03
    • /frameworks/pci-dss-v4.0.1/11/03/02/01
  • Internal
    • ID: dec-c-db6b7ec4

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
💼 PCI DSS v3.2.1 → 💼 11.2.3 Perform internal and external scans, and rescans as needed, after any significant change.
💼 PCI DSS v4.0.1 → 💼 11.3.2.1 External vulnerability scans are performed after any significant change.

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
💼 PCI DSS v3.2.1 → 💼 11.2.3 Perform internal and external scans, and rescans as needed, after any significant change.
💼 PCI DSS v4.0.1 → 💼 11.3.2.1 External vulnerability scans are performed after any significant change.

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags