11.3 Vulnerabilities are regularly identified, prioritised and addressed
How to meet it
Run internal scans and quarterly external ASV scans; remediate and rescan.
Defined requirements
The individual PCI DSS v4.0.1 requirements under 11.3, in plain English.
11.3.1Internal vulnerability scans run at least every three months, with high-risk/critical issues fixed and rescans done.
11.3.1.1Lower-risk vulnerabilities are addressed based on the targeted risk analysis with rescans as needed.
11.3.1.2Internal scans use authenticated scanning with sufficient privileges.
11.3.1.3Internal scans are performed after every significant change by qualified, independent personnel.
11.3.2External scans run at least every three months by a PCI SSC Approved Scanning Vendor, meeting passing-scan requirements.
11.3.2.1External scans are performed after significant changes, fixing CVSS 4.0+ vulnerabilities, by qualified independent personnel.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.
Vulnerability and patch management policyUse for ISO 27001 A.8.8, A.8.19, A.8.32, SOC 2 Security, and PCI DSS requirements 6 and 11.Change management policyUse for ISO 27001 A.8.32, A.8.9, SOC 2 change management criteria, and PCI DSS requirement 6 change controls.Human resources security policyUse for ISO 27001 A.6.1 to A.6.6, A.6.8, SOC 2 Security, and personnel security controls.Secure development policyUse for ISO 27001 A.8.25 to A.8.32, source code controls, change management, and SOC 2 change controls.
Open the control-to-policy map← 11.2 Wireless access points are identified and monitored11.4 Penetration testing is regularly performed →
Back to Requirement 11, or see PCI DSS templates. To run PCI controls with automation, read how AI manages controls.