PCI SSC
What is PCI SSC?
The Payment Card Industry Security Standards Council, responsible for developing and managing PCI security standards including PCI DSS.
Frameworks that govern pci ssc
What the standards actually require on pci ssc
Requirements naming pci ssc across 3 standards, quoted from the control text.
External vulnerability scans are performed at least once every three months by a PCI SSC Approved Scanning Vendor (ASV) with passing scans achieved.
11.3.2 · External vulnerability scans quarterly by ASV →P2PE solutions must undergo annual reassessment by a P2PE QSA and any significant change to the solution must trigger reassessment of affected domains and updates to the listing on the PCI SSC website.
Domain-6.2 · Annual Reassessment and Change Management →The vendor must maintain effective communication with stakeholders including customers, partners, and PCI SSC regarding security-relevant matters, software releases, and vulnerability information.
SSLC-11.1 · Stakeholder Communication →Questions people ask about pci ssc
What is PCI SSC?
Why is PCI SSC important for compliance?
Which compliance frameworks address PCI SSC?
Where can I learn more about PCI SSC?
See how PCI SSC applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.