Skip to content

docs(pro): PCI DSS scope, patch clock, and scope inventory - #15966

Merged
Maffooch merged 4 commits into
DefectDojo:bugfixfrom
devGregA:docs/pci-dss-scope
Sep 17, 2026
Merged

Maffooch merged 4 commits into
DefectDojo:bugfixfrom
devGregA:docs/pci-dss-scope

Conversation

@devGregA

Copy link
Copy Markdown
Contributor

Adds a Pro documentation page for the PCI DSS v4.0.1 scope features.

The page covers, in plain prose and referencing requirements by number:

  • Per-Asset PCI DSS scope (Requirement 12.5.1) and component kind (6.3.2)
  • The public-facing web application determination (6.4.1 and 6.4.2), including how it is derived from the Asset and can be overridden
  • Scope confirmation with date and user (12.5.2)
  • The assessment anchor that sets the start of the Requirement 11 quarterly scan calendar
  • The instance PCI entity type (merchant, service provider, both) and why the six-month service-provider cadence reads it
  • The seeded PCI DSS 6.3.3 patch-clock SLA (critical and high within one month; medium and low per a targeted risk analysis under 12.3.1)
  • The scope inventory CSV export (12.5.1)
  • Filtering the Asset list by scope and component kind

The page notes that these features record the entity's own determinations and never decide compliance, and that the UI is released behind the pci_dss feature flag.

Accompanies the Pro implementation PR (DefectDojo-Inc/dojo-pro feat/pci-scope-and-patch-clocks). Same release line (bugfix).

🤖 Generated with Claude Code

Document the Pro PCI DSS v4.0.1 scope features: per-Asset scope and component
classification, the public-facing determination, scope confirmation, the
assessment anchor, the Requirement 6.3.3 patch-clock SLA, the instance entity
type, and the scope inventory export. Behind the pci_dss feature flag.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@devGregA devGregA added this to the 3.3.200 milestone Sep 16, 2026
@github-actions github-actions Bot added the docs label Sep 16, 2026
devGregA and others added 3 commits September 15, 2026 22:58
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
…s behavior

The API is behind the flag with the UI, hand-set SLA starts are authoritative
and the default policy changes nothing, the fix-available date has no import
date fallback, a never-assessed Asset counts as not assessed, and targeted
risk analyses have one scope, a one-way lifecycle, and owner-directed review
alerts.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@Maffooch
Maffooch added this pull request to the merge queue Sep 17, 2026
Merged via the queue into DefectDojo:bugfix with commit 6414f52 Sep 17, 2026
31 checks passed
@Maffooch
Maffooch deleted the docs/pci-dss-scope branch September 17, 2026 04:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants