Internal vulnerability scans must be run at least every three months. All vulnerabilities ranked high-risk or critical under the entity's risk rankings from Requirement 6.3.1 must be resolved, and rescans must be run to confirm that every such high-risk and critical finding is fixed. The scanning tool must be kept current with the latest vulnerability information, and the people running scans must be qualified and organizationally independent of what they scan. Guidance (good practice): several scan reports may be combined to show full coverage within the three-month cycle, and scanning more often than quarterly is recommended where the environment warrants it. Applicability: a QSA or ASV is not needed for internal scans; qualified internal staff reasonably independent of the scanned components (for example, not the administrator of that network) may run them, or a specialist scanning firm may be used. Objective under the customized approach: automated tools that detect vulnerabilities inside the network periodically verify the security state of every system component, and findings are assessed and fixed using a formal risk assessment framework.
This control maps to 75 controls across 29 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-GV.OV-01 Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction
NIST-CSF-GV.OV-03 Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed
NIST-CSF-ID.IM-02 Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties
NIST-CSF-ID.RA-01 Vulnerabilities in assets are identified, validated, and recorded
NIST-CSF-ID.RA-04 Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded
NIST-CSF-ID.RA-05 Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization
You are reading one control. How much of PCI DSS 4.0 have you already done?
PCI DSS 4.0 11.3.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of PCI DSS 4.0 your existing evidence covers. Hold ISO 27001:2022 and 139 of 280 PCI DSS 4.0 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 415 were rejected on the ISO 27001:2022 pair alone.