PCI DSS Security Maturity Model·AWS v1.0.0
Optimized Vulnerability Management 🤝 Shared

r6.5 Automated vulnerability detection and remediation at scale

Optimize the vulnerability management program with automated remediation, SLA metrics by severity, and full change traceability for continuous compliance.

Quick Wins
Foundational
Efficient
Optimized
Effort: High Impact: Medium Applies to CDE: Yes

AWS services

AWS Security Hub Amazon Inspector AWS Systems Manager Automation AWS CloudTrail

Requirement 6

Develop and Maintain Secure Systems and Software

PCI sub-requirements covered

  • 6.3 Security vulnerabilities are identified and addressed
  • 6.5 Changes to all system components are managed securely

How to implement on AWS

Orchestrate automatic remediation (SSM Automation) on Inspector/Security Hub findings by severity. Measure patching SLAs and generate reports. Rebuild immutable instances from patched AMIs (immutable infrastructure pattern). Correlate changes with CloudTrail for traceability.

Practical implementation

How this control is implemented in each reference architecture:

Wire SSM Automation runbooks to remediate Inspector/Security Hub findings by severity, track patching SLAs, and rebuild instances from patched AMIs (immutable infrastructure) in the account.

Single-account, 3-tier →

Operate remediation orchestration and SLA reporting centrally across the PCI OU, correlating findings in Security Hub and driving automated fixes per account, with change traceability aggregated in the log-archive account.

Multi-account with a dedicated PCI OU →

PCI validation

Testing methods: examineobserve

Testing procedures

  • Examine system components and installed patch information to verify vulnerabilities are addressed by risk ranking and critical/high patches applied within one month (6.3.3.b).
  • Examine change control documentation to verify managed-change requirements are met for all system component changes (6.5.1.b).

Evidence in AWS

  • SSM Automation runbooks for remediation by severity and their history.
  • Vulnerability-remediation SLA metrics/reports.
  • Change traceability in CloudTrail correlated with findings.

Customized approach

Requires a targeted risk analysis (Req 12.3.2).

Customized Approach Objective

  • 6.3 — New system and software vulnerabilities that may impact the security of account data are monitored, cataloged, and risk-assessed, and applicable patches are installed within an appropriate time frame.
  • 6.5 — All changes are tracked, authorized, and evaluated for impact and security, and are managed to avoid unintended effects to the security of system components.

Learning resources

References

  • AWS Security Maturity Model: Continuous improvement program