PCI DSS 4.0
Req 11: Test Security Regularly

PCI DSS 4.0 11.3.1: 11.3.1 Quarterly internal vulnerability scans

Internal vulnerability scans must be run at least every three months. All vulnerabilities ranked high-risk or critical under the entity's risk rankings from Requirement 6.3.1 must be resolved, and rescans must be run to confirm that every such high-risk and critical finding is fixed. The scanning tool must be kept current with the latest vulnerability information, and the people running scans must be qualified and organizationally independent of what they scan. Guidance (good practice): several scan reports may be combined to show full coverage within the three-month cycle, and scanning more often than quarterly is recommended where the environment warrants it. Applicability: a QSA or ASV is not needed for internal scans; qualified internal staff reasonably independent of the scanned components (for example, not the administrator of that network) may run them, or a specialist scanning firm may be used. Objective under the customized approach: automated tools that detect vulnerabilities inside the network periodically verify the security state of every system component, and findings are assessed and fixed using a formal risk assessment framework.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 75 controls across 29 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 7 controls

  • NIST800-PM-14 PM-14 Testing, Training, and Monitoring
  • NIST800-PM-6 PM-6 Measures of Performance
  • NIST800-RA-1 RA-1 Policy and Procedures
  • NIST800-RA-3 RA-3 Risk Assessment
  • NIST800-RA-5 RA-5 Vulnerability Monitoring and Scanning
  • SP800-53-CA Assessment, Authorization, and Monitoring Family
  • SP800-53-SI System and Information Integrity Family
  • NIST-CSF-GV.OV-01 Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction
  • NIST-CSF-GV.OV-03 Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed
  • NIST-CSF-ID.IM-02 Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties
  • NIST-CSF-ID.RA-01 Vulnerabilities in assets are identified, validated, and recorded
  • NIST-CSF-ID.RA-04 Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded
  • NIST-CSF-ID.RA-05 Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization

HIPAA Security Rule · 5 controls

NIST SP 800-66 Rev 2 · 5 controls

CIS Controls v8 · 4 controls

  • CIS-7.1 Establish and Maintain a Vulnerability Management Process
  • CIS-7.2 Establish and Maintain a Remediation Process
  • CIS-7.5 Perform Automated Vulnerability Scans of Internal Enterprise Assets
  • CIS-7.7 Remediate Detected Vulnerabilities

FedRAMP High · 4 controls

  • CM-7(1) Periodic Review
  • RA-5 Vulnerability Monitoring and Scanning
  • SI-2 Flaw Remediation
  • SR-10 Inspection of Systems or Components (SR-10)

FedRAMP Moderate · 4 controls

  • CM-7(1) Periodic Review
  • RA-5 Vulnerability Monitoring and Scanning
  • SI-2 Flaw Remediation
  • SR-10 Inspection of Systems or Components (SR-10)

SOC 2 · 4 controls

  • SOC2-CC3.1 CC3.1 Objectives specified clearly enough to assess risk (COSO principle 6)
  • SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16)
  • SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities
  • SOC2-CC7.2 CC7.2 Monitoring system components for anomalies

ISO 27001:2022 · 3 controls

  • 5.36 Compliance with policies, rules and standards for information security
  • 5.7 Threat intelligence
  • 8.8 Management of technical vulnerabilities

ISO 27701:2019 · 3 controls

  • 5.8.2 Continual improvement
  • 6.9.6 Technical vulnerability management
  • 7.4.3 Accuracy and quality

ACSC Essential Eight · 2 controls

  • E8-PATCHAPP-ML3 Patch Applications (ML3)
  • E8-PATCHOS-ML1 Patch Operating Systems (ML1)

APRA CPS 234 · 2 controls

  • CPS234-22 Systematic Control Testing Program
  • CPS234-P17 Active Maintenance of Capability Against Change

C5 (Germany) · 2 controls

  • C5-OPS-18 Managing Vulnerabilities, Malfunctions and Errors - Concept
  • C5-OPS-22 Testing and Documentation of known Vulnerabilities
  • CFTC-SS-13 Vulnerability Testing
  • CFTC-SS-33 Regular Periodic Objective Testing and Review of Automated Systems

ISO 22301:2019 · 2 controls

  • 10.1 Nonconformity and corrective action
  • 9.3 Management review

ISO 27002:2022 · 2 controls

  • 5.30 ICT readiness for business continuity
  • 8.8 Management of technical vulnerabilities

ISO/IEC 42001:2023 · 2 controls

  • 6.1 Actions to address risks and opportunities
  • 9.3 Management review

NIST SP 800-218 · 2 controls

  • P1-4.2.2 P1-4.2.2 Quarterly internal and external vulnerability scans
  • P1-4.2.3 P1-4.2.3 Scans run by qualified parties, external by an ASV
  • ANSSI-HYG-38 Carry Out Regular Security Checks and Audits and Apply the Corrective Actions
  • AUCDR-IS-4 Formal vulnerability management program
  • PV-5 Perform vulnerability assessments

CMMC 2.0 · 1 control

NIS2 Directive · 1 control

  • Art.21.2.e Security in acquisition, development and maintenance, including vulnerability handling and disclosure
  • 03.11.02 Vulnerability Monitoring and Scanning

NIST SP 800-172 · 1 control

  • 3.12.1e Penetration Testing by Independent Agents

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Req 11: Test Security Regularly

You are reading one control. How much of PCI DSS 4.0 have you already done?

PCI DSS 4.0 11.3.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of PCI DSS 4.0 your existing evidence covers. Hold ISO 27001:2022 and 139 of 280 PCI DSS 4.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 415 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 75 it maps to, and the evidence behind each claim, over MCP and REST.