VM — Vulnerability Management
23 controls in the Vulnerability Management domain
VM-01Vulnerability Scans
VM-02Vulnerability Scans: Cardholder Data Environment
VM-03Vulnerability Scans: Audit Log Review
VM-04Vulnerability Scans: Trend Analysis
VM-05Approved Scanning Vendor
VM-06Application Penetration Testing
VM-07Application Penetration Testing: Cardholder Data Environment
VM-08Infrastructure Patch Management
VM-09Enterprise Antivirus
VM-10Enterprise Antivirus Tampering
VM-11Enterprise Antivirus Scope
VM-12Maintenance Tools: Inspect Media
VM-13Code Security Check
VM-14Code Security Check: Cardholder Data Environment
VM-15Third-Party Library Check
VM-16Non-disclosure of Error Detail
VM-17Embedded Authenticators
VM-18External Information Security Inquiries
VM-19External Alerts and Advisories
VM-20Third-Party Security Assessment
VM-21Security Testing Window
VM-22Vulnerability Remediation
VM-23Backlog Prioritization