Skip to content

Inconsistent ref_id in PCI-DSS 4 compliance #7335

Open
@ab-smith

Description

@ab-smith

Steps to Reproduce

Hello guys,

As discussed with Toni, when I was working on an integration between Prowler and CISO Assistant, I've noticed that the controls reference that the compliance part is sending is not consistent with the framework.
I've re-checked the official PDF and they don't exist.

Here is a sample of problematic ref_id:

see below on my OSCF export

Did I miss something? Maybe you have a specific split or definition?

Thank you

Expected behavior

Use conventional ref_id that can be used for compliance tracking.

Actual Result with Screenshots or Logs

Image

How did you install Prowler?

From brew (brew install prowler)

Environment Resource

M4 Mac

OS used

MacOS

Prowler version

5.4.0

Pip version

Context

No response

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions