Under active development Content is continuously updated and improved

VM-02Vulnerability Scans: Cardholder Data Environment

>Control Description

Vulnerability scans are conducted against cardholder environments at least quarterly or after significant change; critical vulnerability resolution is confirmed via a rescan.

Theme

Process

Type

Detective

Policy/Standard

Vulnerability Management Policy

>Implementation Guidance

1. Ensure that the requirements for quarterly vulnerability scans against cardholder data environement are defined and documented. 2. Ensure a process is established to initiate a scan after every significant change. 3. Ensure all critical vulnerabilities are tracked to resolution and confirmed via a rescan

>Testing Procedure

1. Inspect and validate whether the requirements for quarterly vulnerability scans against cardholder data environement are defined and documented. 2. Validate that a process is established to initiate a scan after every significant change. 3. Validate for a sample critical vulnerability whether it was tracked to resolution and confirmed via a rescan

>Audit Artifacts

E-VM-01
E-VM-04

>Framework Mappings

Cross-framework mappings provided by Adobe CCF Open Source under Creative Commons License.

Ask AI

Configure your API key to use AI features.