The Intent of assigning a risk ranking to vulnerabilities Is to?
Intent of Risk Ranking
PCI DSS Requirement 6.3.2 requires that entities assign a risk ranking to vulnerabilities to prioritize remediation efforts.
This ensures that the most critical vulnerabilities are addressed in a timely manner, reducing the risk to the CDE.
Practical Implementation
Vulnerabilities are assessed based on potential impact and likelihood of exploitation, typically using industry-standard frameworks like CVSS.
High-risk vulnerabilities may require immediate attention, while lower-priority issues are remediated per schedule.
Incorrect Options
Option A: PCI DSS does not mandate a 30-day remediation window for all vulnerabilities; remediation timelines depend on risk.
Option B: Quarterly ASV scans are still required even with risk ranking.
Option D: Installing patches quarterly does not align with the dynamic prioritization of risks.
Amber
3 months agoGlenn
2 months agoShenika
2 months agoKerry
2 months agoShasta
2 months agoPete
3 months agoDiane
3 months agoEveline
2 months agoLisbeth
2 months agoOnita
3 months agoLou
4 months agoBrett
4 months agoMitsue
4 months agoMiesha
4 months agoFranchesca
3 months agoRoselle
4 months ago