What is the purpose of internal vulnerability scanning under PCI DSS?
- A.To test internet speed
- B.To identify security vulnerabilities within the internal network and CDE systems
- C.To test employee awareness, which Requirement 12.6.3 requires at least once every twelve months, with v4.0 adding content on phishing and social engineering under 12.6.3.1
- D.To validate encryption strength, which Requirement 4 mandates for PAN sent over open, public networks such as the internet and wireless links
Why B is correct
Internal vulnerability scanning identifies security weaknesses within the network that could be exploited by internal threats or attackers who have breached the perimeter.
Know someone studying for PCI DSS? Send them this one.