Vulnerability Scanning
PCIComplianceHubLast updated
The use of automated tools to check systems and networks against a database of known vulnerabilities and misconfigurations. PCI DSS requires two distinct kinds on different terms: external scanning, which must be performed by an Approved Scanning Vendor, and internal scanning, which may be performed by qualified staff and, under v4.x, must be authenticated. Both are required at least once every three months and after any significant change, and both require findings to be remediated and a rescan performed to confirm the fix. A scan that was run but never passed does not satisfy the requirement.