Skip to content

docs(pci): document PCI DSS scan and ASV evidence - #16006

Merged
devGregA merged 1 commit into
DefectDojo:bugfixfrom
devGregA:docs/pci-scan-and-asv-evidence
Sep 20, 2026
Merged

devGregA merged 1 commit into
DefectDojo:bugfixfrom
devGregA:docs/pci-scan-and-asv-evidence

Conversation

@devGregA

Copy link
Copy Markdown
Contributor

Documents the PCI DSS Requirement 11 scan and ASV evidence features, as a companion to the existing PCI DSS scope page.

The page covers:

  • How a test gets a PCI role, and that the defaults only fill a role nobody has set.
  • The facts a scan report cannot carry: whether the scan was authenticated, the ASV result with its vendor and attestation reference, the significant change a scan answers, and a note.
  • Significant changes and unauthenticated system exceptions, including that an exception reads as needing attention rather than as satisfied.
  • What each cell of the quarterly grid means, with the exact rule behind it in a table, and that quarters are counted from the assessment anchor date rather than from 1 January.
  • How the annual Requirement 11.4 checks are measured, including the six-month segmentation cadence for a service provider.
  • The dashboard tile and the end-of-quarter reminders.
  • What the evidence workbook contains.

It states plainly that DefectDojo records the ASV results an entity reports, does not perform ASV scans, is not an Approved Scanning Vendor, and does not validate an attestation, so a passing result is never inferred from an absence of findings.

English only. Per TRANSLATIONS.md the translations are regenerated from English.

The Pro side is DefectDojo-Inc/dojo-pro (private), on the same release line.

🤖 Generated with Claude Code

Companion page to the PCI DSS scope docs, for the Requirement 11 evidence
features: how a test gets a PCI role, the facts a scan report cannot carry
(authenticated, ASV result, vendor and attestation reference), significant
changes and unauthenticated system exceptions, what each cell of the quarterly
grid means and the exact rule behind it, how the annual Requirement 11.4 checks
are measured, the dashboard tile and the end-of-quarter reminders, and what the
evidence workbook contains.

States plainly that DefectDojo records the ASV results an entity reports, does
not perform ASV scans, and does not validate an attestation, so a passing result
is never inferred from an absence of findings.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@github-actions github-actions Bot added the docs label Sep 19, 2026
@devGregA devGregA added this to the 3.3.200 milestone Sep 19, 2026
@devGregA
devGregA added this pull request to the merge queue Sep 20, 2026
Merged via the queue into DefectDojo:bugfix with commit df9e389 Sep 20, 2026
30 checks passed
@devGregA
devGregA deleted the docs/pci-scan-and-asv-evidence branch September 20, 2026 23:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants