PCI-DSS 3.2 requirement 6.1 mandates that organizations establish a process for identifying security vulnerabilities on the servers that are within the scope of PCI. Yet as new vulnerabilities are discovered every day, this ‘laundry list’ of problems is very dynamic, and constantly being updated. It’s also extremely granular and detailed. So how can you assess and prioritize the remediation of these vulnerabilities that directly impact your compliance status?

The post Why and how to align vulnerabilities with business risk for PCI-DSS compliance appeared first on algosec.