CompTIA CySA+ (CS0-003)Reporting and CommunicationMedium
A security analyst is preparing a compliance report for the Payment Card Industry Data Security Standard (PCI DSS) Requirement 11.2, which mandates regular vulnerability scanning. The analyst needs to present evidence that all in-scope systems are scanned quarterly by an internal scanner and annually by an Approved Scanning Vendor (ASV). Which of the following metrics would BEST demonstrate compliance with this requirement?
- APercentage of in-scope systems scanned quarterly by internal tools and annually by ASV
- BNumber of vulnerabilities identified per scan
- CTotal number of security incidents related to cardholder data
- DTime taken to remediate critical vulnerabilities
Show answer & explanationAnswer & explanation
Correct answer: A. Percentage of in-scope systems scanned quarterly by internal tools and annually by ASV
PCI DSS Requirement 11.2 specifically mandates the frequency and type of scanning for all in-scope systems. The percentage of in-scope systems scanned quarterly by internal tools and annually by ASV directly demonstrates adherence to these explicit requirements.
Why the other options are wrong
- B. This metric measures findings, not the coverage or frequency of scanning as required by 11.2.
- C. This measures incident response, not compliance with vulnerability scanning requirements.
- D. This measures remediation efficiency, not compliance with scanning frequency and coverage mandates.
PCI DSS 11.2 Compliance Metric
A metric used to demonstrate adherence to PCI DSS Requirement 11.2, which specifies regular internal and external vulnerability scanning for all systems in the cardholder data environment.
- Mandates quarterly internal vulnerability scans.
- Requires annual external vulnerability scans conducted by an Approved Scanning Vendor (ASV).
- Focuses on coverage and frequency of scanning for in-scope systems.
Memory trick: PCI scans cover all cards every quarter and year.