Skip to main content

πŸ’Ό 11.3.2.1 External vulnerability scans are performed after any significant change.

Description​

As follows:

  • Vulnerabilities that are scored 4.0 or higher by the CVSS are resolved.
  • Rescans are conducted as needed.
  • Scans are performed by qualified personnel and organizational independence of the tester exists (not required to be a QSA or ASV).

Similar​

  • Sections
    • /frameworks/pci-dss-v3.2.1/11/02/03
    • /frameworks/pci-dss-v4.0.1/11/03/02/01

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό PCI DSS v3.2.1 β†’ πŸ’Ό 11.2.3 Perform internal and external scans, and rescans as needed, after any significant change.
πŸ’Ό PCI DSS v4.0.1 β†’ πŸ’Ό 11.3.2.1 External vulnerability scans are performed after any significant change.

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό PCI DSS v3.2.1 β†’ πŸ’Ό 11.2.3 Perform internal and external scans, and rescans as needed, after any significant change.
πŸ’Ό PCI DSS v4.0.1 β†’ πŸ’Ό 11.3.2.1 External vulnerability scans are performed after any significant change.

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags