CyberTRIZPEDIA

Vulnerability Management and Secure Development

Control
PCI-R6-001
Regulation
PCI DSS
Category
technical
Priority
critical
Frequency
monthly
Type
technical

What this control requires

Implement a vulnerability management programme: deploy and maintain antivirus, apply security patches within defined timeframes (critical within 30 days, high within 60 days, others within 90 days), use application security testing for web applications, and follow secure development lifecycle for all code changes.

Other PCI DSS controls