What does PCI DSS require for patch management?
- A.Critical security patches must be installed within one month of release, and all applicable vendor-supplied security patches must be installed in a timely manner
- B.Only patch after testing for one year, which the v4.0 guidance for Requirement 6 accepts as permanent mitigation for any vulnerability class, closing findings without patching as long as the control is named in the entity's security policy
- C.Patch annually, since security patches from third-party libraries fall outside the patch management process for card-present merchants at each quarterly ASV scan
- D.Only patch when convenient, given that internal scanning may be replaced by patch management reporting for SAQ B-IP merchants until the next scheduled assessment
Why A is correct
Critical security patches must be installed within one month of release. All security patches should be applied in a timely manner based on risk.
Know someone studying for PCI DSS? Send them this one.