r11.1 Internal and external vulnerability scans
Run internal and external vulnerability scans regularly and after significant changes, addressing findings by risk ranking. External ASV scans must be performed quarterly.
AWS services
Requirement 11
Test Security of Systems and Networks Regularly
PCI sub-requirements covered
- 11.3 External and internal vulnerabilities are regularly identified, prioritized, and addressed
How to implement on AWS
Cover continuous internal scanning with Amazon Inspector. For quarterly external scanning, engage an Approved Scanning Vendor (ASV). Rescan after significant changes. Track remediation until a passing result is achieved. Consolidate in Security Hub.
Practical implementation
How this control is implemented in each reference architecture:
Cover continuous internal scanning with Amazon Inspector in the account and engage an ASV for quarterly external scans of your public endpoints; track remediation to a passing result.
Single-account, 3-tier →Run Inspector org-wide for internal scanning across all CDE accounts (findings in the security tooling account), and coordinate quarterly ASV external scans for each internet-facing CDE endpoint.
Multi-account with a dedicated PCI OU →PCI validation
Testing procedures
- Examine internal scan reports from the last 12 months to verify scans occurred at least every 3 months and that all high-risk and critical vulnerabilities were resolved (11.3.1.a, 11.3.1.b).
- Examine ASV scan reports to verify external scans occurred at least every 3 months, met the ASV passing criteria, and were completed by a PCI SSC ASV (11.3.2.a, 11.3.2.b, 11.3.2.c).
Evidence in AWS
- Amazon Inspector internal scan reports with remediation evidence.
- Passing quarterly ASV reports (external vendor).
- Record of rescans after significant changes.
Customized approach
Requires a targeted risk analysis (Req 12.3.2).
Customized Approach Objective
- 11.3 — The security posture of all system components is verified periodically using automated tools designed to detect vulnerabilities, and detected vulnerabilities are addressed based on risk.
Learning resources
References
- PCI DSS v4.0.1 Requirement 11.3
PCI DSS Security Maturity Model