CyberTRIZPEDIA

Implement Vulnerability Management for CDE Systems

Control
PCI-VULN-001
Regulation
PCI DSS
Category
operational
Priority
high
Frequency
annually
Type
operational

What this control requires

Implement a vulnerability management programme for all CDE system components: deploy antivirus software, apply security patches within defined timeframes (critical within 30 days, high within 60 days, others within 90 days), conduct monthly internal vulnerability scans and quarterly external scans. Perform penetration testing at least annually and after significant changes.

Other PCI DSS controls