PCI DSS Security Maturity Model·AWS v1.0.0
Quick Wins Vulnerability Management 🤝 Shared

r11.1 Internal and external vulnerability scans

Run internal and external vulnerability scans regularly and after significant changes, addressing findings by risk ranking. External ASV scans must be performed quarterly.

Quick Wins
Foundational
Efficient
Optimized
Effort: Low Impact: High Applies to CDE: Yes

AWS services

Amazon Inspector AWS Security Hub

Requirement 11

Test Security of Systems and Networks Regularly

PCI sub-requirements covered

  • 11.3 External and internal vulnerabilities are regularly identified, prioritized, and addressed

How to implement on AWS

Cover continuous internal scanning with Amazon Inspector. For quarterly external scanning, engage an Approved Scanning Vendor (ASV). Rescan after significant changes. Track remediation until a passing result is achieved. Consolidate in Security Hub.

Practical implementation

How this control is implemented in each reference architecture:

Cover continuous internal scanning with Amazon Inspector in the account and engage an ASV for quarterly external scans of your public endpoints; track remediation to a passing result.

Single-account, 3-tier →

Run Inspector org-wide for internal scanning across all CDE accounts (findings in the security tooling account), and coordinate quarterly ASV external scans for each internet-facing CDE endpoint.

Multi-account with a dedicated PCI OU →

PCI validation

Testing methods: examine

Testing procedures

  • Examine internal scan reports from the last 12 months to verify scans occurred at least every 3 months and that all high-risk and critical vulnerabilities were resolved (11.3.1.a, 11.3.1.b).
  • Examine ASV scan reports to verify external scans occurred at least every 3 months, met the ASV passing criteria, and were completed by a PCI SSC ASV (11.3.2.a, 11.3.2.b, 11.3.2.c).

Evidence in AWS

  • Amazon Inspector internal scan reports with remediation evidence.
  • Passing quarterly ASV reports (external vendor).
  • Record of rescans after significant changes.

Customized approach

Requires a targeted risk analysis (Req 12.3.2).

Customized Approach Objective

  • 11.3 — The security posture of all system components is verified periodically using automated tools designed to detect vulnerabilities, and detected vulnerabilities are addressed based on risk.

Learning resources

References

  • PCI DSS v4.0.1 Requirement 11.3