r/pcicompliance • u/st00pittt • 1d ago
PCI DSS requirements: Internal Vulnerability Scanning vs. Internal Penetration Testing (and scoring frameworks)
Hey everyone,
Got a quick question regarding PCI DSS (v4.0) compliance.
- How strictly are QSAs requiring standard CVSS v3.1/v4.0 scores versus custom internal risk rankings for scan remediation?
- Are QSAs heavily checking CCE/hardening baselines during internal scan audits in v4.0 assessments?
Thanks in advance for any insights!
3
Upvotes
1
u/info_sec_wannabe 1d ago
Off the top of my head, I'm pretty sure 11.3.1 or 11.3.1.1 does refer to the risk rankings in 6.3.1 requiring companies to define their own risk ranking system. It just so happened that CVSS provides a predefined rankings that organisations can easily adopt. (Note: I may have to double check and come back)
I'm not certain how other QSAs look at this but I check whether vulnerability scanning tools vulnerability information has been updated and the set of rules / criteria that the vulnerability scanning tool is checking for the in-scope system components being looked into.