docs(pci): document PCI DSS scan and ASV evidence - #16006
Merged
devGregA merged 1 commit intoSep 20, 2026
Merged
Conversation
Companion page to the PCI DSS scope docs, for the Requirement 11 evidence features: how a test gets a PCI role, the facts a scan report cannot carry (authenticated, ASV result, vendor and attestation reference), significant changes and unauthenticated system exceptions, what each cell of the quarterly grid means and the exact rule behind it, how the annual Requirement 11.4 checks are measured, the dashboard tile and the end-of-quarter reminders, and what the evidence workbook contains. States plainly that DefectDojo records the ASV results an entity reports, does not perform ASV scans, and does not validate an attestation, so a passing result is never inferred from an absence of findings. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
blakeaowens
approved these changes
Sep 20, 2026
Maffooch
approved these changes
Sep 20, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Documents the PCI DSS Requirement 11 scan and ASV evidence features, as a companion to the existing PCI DSS scope page.
The page covers:
It states plainly that DefectDojo records the ASV results an entity reports, does not perform ASV scans, is not an Approved Scanning Vendor, and does not validate an attestation, so a passing result is never inferred from an absence of findings.
English only. Per TRANSLATIONS.md the translations are regenerated from English.
The Pro side is DefectDojo-Inc/dojo-pro (private), on the same release line.
🤖 Generated with Claude Code