Vulnerability Assessment

PCIComplianceHubLast updated

The broader process of identifying vulnerabilities, judging what each one actually means in the context of the environment, ranking them by risk and deciding what to do about them. A vulnerability scan is one input to this; the assessment is the analysis around it. The distinction matters under PCI DSS, which requires vulnerabilities to be given a risk ranking reflecting the environment they sit in rather than the raw score a scanner reports, and requires that ranking to be documented and justified.