PCI SSF
Risk Management

PCI SSF SSLC-4.1: Threat Identification and Risk Mitigation

The vendor must establish processes to identify threats to the software, assess associated risks, and mitigate or accept those risks through documented decisions.

Maintained by Gerard BlokdykControl text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.