PCI SSF
Vulnerability Management

PCI SSF SSLC-8.1: Vulnerability Disclosure and Response

The vendor must operate a vulnerability disclosure program that allows external researchers to report vulnerabilities, and must respond to reported vulnerabilities within defined timeframes.

Maintained by Gerard BlokdykControl text last updated

Other controls in Vulnerability Management

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.