PCI DSS 4.0
Req 11: Test Security Regularly

PCI DSS 4.0 11.3.2: 11.3.2 Quarterly ASV external vulnerability scans

External vulnerability scans must meet these conditions: they run at least every three months; an Approved Scanning Vendor (ASV) listed by the PCI SSC performs them; with vulnerabilities resolved and the ASV Program Guide conditions for a passing scan met; and with rescans run as needed to confirm resolution under those passing-scan conditions. Applicability: for the first PCI DSS assessment against this requirement, four passing scans within 12 months are not required if the assessor confirms (1) the latest scan passed, (2) documented policies and procedures mandate quarterly scanning, meaning at least every three months, plus (3) rescans show the reported vulnerabilities were fixed. From the second year onward, a passing scan is needed for every three-month period. Details of the target environment (load balancers, third parties, ISPs, configurations, protocols, scan interference) are for the ASV and the scan customer to settle between them, with the ASV Program Guide describing scan customer responsibilities. Customized approach objective: not eligible for the customized approach.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 47 controls across 22 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

FedRAMP High · 6 controls

  • CA-2(1) Independent Assessors
  • CA-7(1) Independent Assessment
  • CM-7(1) Periodic Review
  • RA-5 Vulnerability Monitoring and Scanning
  • SI-2 Flaw Remediation
  • SR-10 Inspection of Systems or Components (SR-10)

FedRAMP Moderate · 6 controls

  • CA-2(1) Independent Assessors
  • CA-7(1) Independent Assessment
  • CM-7(1) Periodic Review
  • RA-5 Vulnerability Monitoring and Scanning
  • SI-2 Flaw Remediation
  • SR-10 Inspection of Systems or Components (SR-10)
  • NIST-CSF-DE.CM-01 Networks and network services are monitored to find potentially adverse events
  • NIST-CSF-GV.SC-05 Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties
  • NIST-CSF-ID.RA-01 Vulnerabilities in assets are identified, validated, and recorded
  • NIST-CSF-ID.RA-04 Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded
  • NIST-CSF-ID.RA-05 Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization
  • NIST-CSF-PR.PS-01 Configuration management practices are established and applied

NIST SP 800-53 Rev 5 · 3 controls

  • NIST800-RA-1 RA-1 Policy and Procedures
  • NIST800-RA-5 RA-5 Vulnerability Monitoring and Scanning
  • SP800-53-CA Assessment, Authorization, and Monitoring Family

C5 (Germany) · 2 controls

  • C5-OPS-18 Managing Vulnerabilities, Malfunctions and Errors - Concept
  • C5-OPS-22 Testing and Documentation of known Vulnerabilities

CIS Controls v8 · 2 controls

  • CIS-7.6 Perform Automated Vulnerability Scans of Externally-Exposed Enterprise Assets
  • CIS-7.7 Remediate Detected Vulnerabilities

HIPAA Security Rule · 2 controls

NIST SP 800-66 Rev 2 · 2 controls

  • P1-4.2.2 P1-4.2.2 Quarterly internal and external vulnerability scans
  • P1-4.2.3 P1-4.2.3 Scans run by qualified parties, external by an ASV

SOC 2 · 2 controls

  • SOC2-CC6.6 CC6.6 Protection against threats from outside the system boundary
  • SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities
  • E8-PATCHAPP-ML1 Patch Applications (ML1)
  • ANSSI-HYG-38 Carry Out Regular Security Checks and Audits and Apply the Corrective Actions

APRA CPS 234 · 1 control

  • CPS234-P30 Independence and Skill of Testing Personnel
  • PV-5 Perform vulnerability assessments

CMMC 2.0 · 1 control

ISO 27001:2022 · 1 control

  • 8.8 Management of technical vulnerabilities

ISO 27002:2022 · 1 control

  • 8.8 Management of technical vulnerabilities

ISO 27701:2019 · 1 control

  • 6.9.6 Technical vulnerability management
  • 03.11.02 Vulnerability Monitoring and Scanning

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Req 11: Test Security Regularly

You are reading one control. How much of PCI DSS 4.0 have you already done?

PCI DSS 4.0 11.3.2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of PCI DSS 4.0 your existing evidence covers. Hold ISO 27001:2022 and 139 of 280 PCI DSS 4.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 415 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 47 it maps to, and the evidence behind each claim, over MCP and REST.