Maintain a vulnerability management program

Requirement 6: Develop and maintain secure systems and software

Vulnerabilities in your own and third-party software must be found and fixed, and software developed securely.

SCOPEEVIDENCERISKEVIDENCETESTEVIDENCEREPORTEVIDENCEAUDIT TRAILPCI Req 6 EvidencePOLICY / CONTROL / EVIDENCE / REVIEW

Sub-requirements

Tips

  • Add SAST and dependency scanning to CI to cover 6.2 and 6.3 automatically.
  • A WAF is the simplest route to 6.4 for most teams.

Evidence to keep

  • Secure SDLC document
  • Scan results and patch records
  • Change-control tickets
  • WAF configuration

Example

Code is peer-reviewed, CI runs SAST and dependency scanning, criticals are patched within 30 days, and a WAF fronts public apps.

Policy templates for this control

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map