PCI DSS 4.0
Req 6: Secure Systems and Software

PCI DSS 4.0 6.3.2: 6.3.2 Inventory of bespoke software and components

The entity must keep an inventory covering the custom and bespoke software it runs, together with the third-party software components built into that software, so that vulnerability and patch management can be carried out. The testing procedures also check that the inventory is actually used to find and deal with vulnerabilities. It applies to all entities. Objective under the customized approach: known weaknesses in third-party components cannot be exploited by way of custom or bespoke software the entity owns. Future-dated: treated as a best practice up to 31 March 2025 and mandatory since then.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 57 controls across 21 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

CIS Controls v8 · 7 controls

  • CIS-12.1 Ensure Network Infrastructure is Up-to-Date
  • CIS-16.4 Establish and Manage an Inventory of Third-Party Software Components
  • CIS-16.5 Use Up-to-Date and Trusted Third-Party Software Components
  • CIS-2.1 Establish and Maintain a Software Inventory
  • CIS-2.2 Ensure Authorized Software is Currently Supported
  • CIS-2.3 Address Unauthorized Software
  • CIS-7.1 Establish and Maintain a Vulnerability Management Process

FedRAMP High · 5 controls

  • CM-10 Software Usage Restrictions
  • CM-7(5) Authorized Software Allow-by-Exception
  • CM-8 System Component Inventory
  • CM-8(1) Updates During Installation and Removal
  • SA-10 Developer Configuration Management

FedRAMP Moderate · 5 controls

  • CM-10 Software Usage Restrictions
  • CM-7(5) Authorized Software Allow-by-Exception
  • CM-8 System Component Inventory
  • CM-8(1) Updates During Installation and Removal
  • SA-10 Developer Configuration Management
  • NIST-CSF-ID.AM-02 Inventories of software, services, and systems managed by the organization are maintained
  • NIST-CSF-ID.AM-07 Inventories of data and corresponding metadata for designated data types are maintained
  • NIST-CSF-ID.AM-08 Systems, hardware, software, services, and data are managed throughout their life cycles
  • NIST-CSF-PR.PS-02 Software is maintained, replaced, and removed commensurate with risk

NIST SP 800-53 Rev 5 · 4 controls

HIPAA Security Rule · 3 controls

ISO 27001:2022 · 3 controls

  • 5.21 Managing information security in the information and communication technology (ICT) supply chain
  • 5.9 Inventory of information and other associated assets
  • 8.8 Management of technical vulnerabilities

ISO 27002:2022 · 3 controls

  • 5.21 Managing information security in the ICT supply chain
  • 5.9 Inventory of information and other associated assets
  • 8.8 Management of technical vulnerabilities

NIST SP 800-172 · 3 controls

  • 3.11.6e Supply Chain Risk Assessment, Response, and Monitoring
  • 3.14.3e Include Systems in Scope of Enhanced Requirements or Segregate into Purpose-Specific Networks
  • 3.4.1e Authoritative Source for Software and Firmware

NIST SP 800-218 · 3 controls

NIST SP 800-66 Rev 2 · 3 controls

CMMC 2.0 · 2 controls

ISO 27701:2019 · 2 controls

  • 6.11 Systems acquisition, development and maintenance
  • 6.9.6 Technical vulnerability management

NIST SP 800-161 Rev 1 · 2 controls

SOC 2 · 2 controls

  • SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11)
  • SOC2-CC8.1 CC8.1 Managing changes to procedures, software, data and infrastructure
  • ANSSI-HYG-35 Anticipate the End of Maintenance of Software and Systems
  • SEC11-BP05 Centralize services for packages and dependencies
  • DS-2 Ensure software supply chain security
  • P2-3.3.3 P2-3.3.3 APIs to the 3DE identified, defined and tested

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Req 6: Secure Systems and Software

You are reading one control. How much of PCI DSS 4.0 have you already done?

PCI DSS 4.0 6.3.2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of PCI DSS 4.0 your existing evidence covers. Hold ISO 27001:2022 and 139 of 280 PCI DSS 4.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 415 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 57 it maps to, and the evidence behind each claim, over MCP and REST.