PCI DSS 4.0 11.3.2: 11.3.2 Quarterly ASV external vulnerability scans
External vulnerability scans must meet these conditions: they run at least every three months; an Approved Scanning Vendor (ASV) listed by the PCI SSC performs them; with vulnerabilities resolved and the ASV Program Guide conditions for a passing scan met; and with rescans run as needed to confirm resolution under those passing-scan conditions. Applicability: for the first PCI DSS assessment against this requirement, four passing scans within 12 months are not required if the assessor confirms (1) the latest scan passed, (2) documented policies and procedures mandate quarterly scanning, meaning at least every three months, plus (3) rescans show the reported vulnerabilities were fixed. From the second year onward, a passing scan is needed for every three-month period. Details of the target environment (load balancers, third parties, ISPs, configurations, protocols, scan interference) are for the ASV and the scan customer to settle between them, with the ASV Program Guide describing scan customer responsibilities. Customized approach objective: not eligible for the customized approach.
This control maps to 47 controls across 22 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-DE.CM-01 Networks and network services are monitored to find potentially adverse events
NIST-CSF-GV.SC-05 Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties
NIST-CSF-ID.RA-01 Vulnerabilities in assets are identified, validated, and recorded
NIST-CSF-ID.RA-04 Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded
NIST-CSF-ID.RA-05 Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization
NIST-CSF-PR.PS-01 Configuration management practices are established and applied
You are reading one control. How much of PCI DSS 4.0 have you already done?
PCI DSS 4.0 11.3.2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of PCI DSS 4.0 your existing evidence covers. Hold ISO 27001:2022 and 139 of 280 PCI DSS 4.0 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 415 were rejected on the ISO 27001:2022 pair alone.