PCI DSS Security Maturity Model·AWS v1.0.0
Quick Wins Vulnerability Management 🤝 Shared

r6.1 Automated vulnerability scanning with Amazon Inspector

Enable continuous, automated vulnerability scanning of EC2, container images (ECR), and Lambda functions to identify and rank known security weaknesses.

Quick Wins
Foundational
Efficient
Optimized
Effort: Low Impact: High Applies to CDE: Yes

AWS services

Amazon Inspector Amazon ECR AWS Security Hub Amazon EventBridge

Requirement 6

Develop and Maintain Secure Systems and Software

PCI sub-requirements covered

  • 6.3 Security vulnerabilities are identified and addressed

How to implement on AWS

Enable Amazon Inspector across the entire organization. Prioritize by severity and exploitability. Send findings to Security Hub and alert with EventBridge. Align risk ranking with the vulnerability-ranking process required by PCI.

Practical implementation

How this control is implemented in each reference architecture:

Enable Amazon Inspector in the account to continuously scan EC2, ECR images, and Lambda; route findings to Security Hub and rank by severity to feed your vulnerability process.

Single-account, 3-tier →

Enable Inspector organization-wide from the delegated administrator so every CDE account is scanned automatically, and consolidate findings and risk ranking in the security tooling account.

Multi-account with a dedicated PCI OU →

PCI validation

Testing methods: examineobserve

Testing procedures

  • Examine policies and procedures to verify processes are defined to identify and manage security vulnerabilities, including risk ranking, per all elements of the requirement (6.3.1.a).
  • Interview personnel, examine documentation, and observe processes to verify vulnerabilities are identified from recognized sources and managed accordingly (6.3.1.b).
  • Verify an inventory of bespoke/custom and third-party software components is maintained and used to identify and address vulnerabilities (6.3.2.a).

Evidence in AWS

  • Amazon Inspector enabled on in-scope accounts and its scan coverage.
  • Inspector findings with severity/CVSS integrated in Security Hub.
  • Documented vulnerability ranking and remediation process.

Customized approach

Requires a targeted risk analysis (Req 12.3.2).

Customized Approach Objective

  • 6.3 — New system and software vulnerabilities that may impact the security of account data are monitored, cataloged, and risk-assessed, and applicable patches are installed within an appropriate time frame.

Learning resources

References

  • AWS Security Maturity Model: Infrastructure vulnerability management