Host Vulnerability Management for PCI DSS
Setting up and managing a PCI DSS 4 compliant vulnerability management program for VMs and Kubernetes clusters.
Overview
Inherited a stale vulnerability scanning setup that I had to fix. Designed and implemented an end-to-end process for patch management on the cardholder data environment (CDE). Relied on automation scripts for accuracy and data integrity.
Key Practices
- Regular CDE scoping to determine scan targets- Virtual Machines and K8s Clusters
- Deployed a GCP Cloud Function for scheduled target verification and synchronisation
- Implemented secure authenticated internal scans for Linux hosts, with automated SSH key rotation mechanism.
- Established remediation SLAs