r6.1 Automated vulnerability scanning with Amazon Inspector
Enable continuous, automated vulnerability scanning of EC2, container images (ECR), and Lambda functions to identify and rank known security weaknesses.
AWS services
Requirement 6
Develop and Maintain Secure Systems and Software
PCI sub-requirements covered
- 6.3 Security vulnerabilities are identified and addressed
How to implement on AWS
Enable Amazon Inspector across the entire organization. Prioritize by severity and exploitability. Send findings to Security Hub and alert with EventBridge. Align risk ranking with the vulnerability-ranking process required by PCI.
Practical implementation
How this control is implemented in each reference architecture:
Enable Amazon Inspector in the account to continuously scan EC2, ECR images, and Lambda; route findings to Security Hub and rank by severity to feed your vulnerability process.
Single-account, 3-tier →Enable Inspector organization-wide from the delegated administrator so every CDE account is scanned automatically, and consolidate findings and risk ranking in the security tooling account.
Multi-account with a dedicated PCI OU →PCI validation
Testing procedures
- Examine policies and procedures to verify processes are defined to identify and manage security vulnerabilities, including risk ranking, per all elements of the requirement (6.3.1.a).
- Interview personnel, examine documentation, and observe processes to verify vulnerabilities are identified from recognized sources and managed accordingly (6.3.1.b).
- Verify an inventory of bespoke/custom and third-party software components is maintained and used to identify and address vulnerabilities (6.3.2.a).
Evidence in AWS
- Amazon Inspector enabled on in-scope accounts and its scan coverage.
- Inspector findings with severity/CVSS integrated in Security Hub.
- Documented vulnerability ranking and remediation process.
Customized approach
Requires a targeted risk analysis (Req 12.3.2).
Customized Approach Objective
- 6.3 — New system and software vulnerabilities that may impact the security of account data are monitored, cataloged, and risk-assessed, and applicable patches are installed within an appropriate time frame.
Learning resources
References
- AWS Security Maturity Model: Infrastructure vulnerability management
PCI DSS Security Maturity Model