← work

Host Vulnerability Management for PCI DSS

Setting up and managing a PCI DSS 4 compliant vulnerability management program for VMs and Kubernetes clusters.

Streamlined patch management
Simplified audit evidence collection
Ensured accurate scanning and reduced false positives
Massively reduced attack surface and security posture over the course of several years.

Overview

Inherited a stale vulnerability scanning setup that I had to fix. Designed and implemented an end-to-end process for patch management on the cardholder data environment (CDE). Relied on automation scripts for accuracy and data integrity.

Key Practices

  • Regular CDE scoping to determine scan targets- Virtual Machines and K8s Clusters
  • Deployed a GCP Cloud Function for scheduled target verification and synchronisation
  • Implemented secure authenticated internal scans for Linux hosts, with automated SSH key rotation mechanism.
  • Established remediation SLAs