|
|
|
|
|
by kasey_junk
2 days ago
|
|
PCI doesn’t mention cve by name but does require vulnerability accounting and requires action if they are found, the action required driven by severity. I could see a (poor) control being written around keeping counts down. |
|