Skip to main content

๐Ÿ’ผ 12.3.4 Hardware and software technologies in use are reviewed at least once every 12 months.

Descriptionโ€‹

Including at least the following:

  • Analysis that the technologies continue to receive security fixes from vendors promptly.
  • Analysis that the technologies continue to support (and do not preclude) the entity's PCI DSS compliance.
  • Documentation of any industry announcements or trends related to a technology, such as when a vendor has announced โ€œend of lifeโ€ plans for a technology.
  • Documentation of a plan, approved by senior management, to remediate outdated technologies, including those for which vendors have announced โ€œend of lifeโ€ plans.

Similarโ€‹

  • Sections
    • /frameworks/pci-dss-v4.0.1/12/03/04

Similar Sections (Take Policies From)โ€‹

SectionSub SectionsInternal RulesPoliciesFlags
๐Ÿ’ผ PCI DSS v4.0.1 โ†’ ๐Ÿ’ผ 12.3.4 Hardware and software technologies in use are reviewed at least once every 12 months.

Similar Sections (Give Policies To)โ€‹

SectionSub SectionsInternal RulesPoliciesFlags
๐Ÿ’ผ PCI DSS v4.0.1 โ†’ ๐Ÿ’ผ 12.3.4 Hardware and software technologies in use are reviewed at least once every 12 months.

Sub Sectionsโ€‹

SectionSub SectionsInternal RulesPoliciesFlags