PCI DSS 4.0 6.3.1: 6.3.1 Vulnerability identification and risk ranking
Security vulnerabilities must be identified and managed so that: new vulnerabilities come to light through sources of vulnerability information that the industry recognises, such as alerts issued by national and international computer emergency response teams (CERTs); each vulnerability receives a risk ranking based on industry good practice and its possible impact; the rankings at minimum pick out every vulnerability the environment treats as critical or high-risk; and vulnerabilities in bespoke and custom software and in third-party software (such as operating systems and databases) are all included. It applies to all entities. Applicability: this is separate from, and additional to, the internal and external vulnerability scans (11.3.1, 11.3.2); it is a process to actively watch industry sources and for the entity to assign its own risk ranking to each vulnerability. Objective under the customized approach: new system and software vulnerabilities able to affect cardholder or sensitive authentication data are tracked, catalogued and risk assessed.
This control maps to 119 controls across 26 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-DE.AE-07 Cyber threat intelligence and other contextual information are integrated into the analysis
NIST-CSF-ID.AM-08 Systems, hardware, software, services, and data are managed throughout their life cycles
NIST-CSF-ID.RA-01 Vulnerabilities in assets are identified, validated, and recorded
NIST-CSF-ID.RA-02 Cyber threat intelligence is received from information sharing forums and sources
NIST-CSF-ID.RA-04 Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded
NIST-CSF-ID.RA-05 Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization
NIST-CSF-PR.PS-06 Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle
You are reading one control. How much of PCI DSS 4.0 have you already done?
PCI DSS 4.0 6.3.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of PCI DSS 4.0 your existing evidence covers. Hold ISO 27001:2022 and 139 of 280 PCI DSS 4.0 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 415 were rejected on the ISO 27001:2022 pair alone.