Risk Ranking
PCIComplianceHubLast updated
The severity an organization assigns to a vulnerability in its own environment, which determines how quickly the vulnerability must be fixed. PCI DSS requires vulnerabilities to be ranked, with those ranked critical or high remediated on a defined and short timeline and the remainder addressed according to their ranking. A CVSS score is an input, not the answer: the ranking must account for what the affected system does, where it sits relative to the cardholder data environment, and what other protections are in place. The method must be documented and applied consistently.