Internal Vulnerability Scanning
PCIComplianceHubLast updated
Scanning performed from inside the network to identify vulnerabilities on system components in and connected to the cardholder data environment. PCI DSS requires it at least once every three months and after any significant change, with high-risk and critical findings resolved and rescans performed to confirm the fix. Unlike external scanning it does not require an Approved Scanning Vendor and may be run by qualified internal staff, provided they are organizationally independent of the systems being scanned. Under v4.x these scans must also be authenticated.