Requirement 11: Test security of systems and networks regularly
Controls degrade over time; regular scanning and testing find new weaknesses before attackers do.
Sub-requirements
Processes and mechanisms are defined and understood
2 defined requirementsDocument security-testing policy.
View defined requirements →Wireless access points are identified and monitored
2 defined requirementsDetect authorised and rogue wireless access points periodically.
View defined requirements →Vulnerabilities are regularly identified, prioritised and addressed
6 defined requirementsRun internal scans and quarterly external ASV scans; remediate and rescan.
View defined requirements →Penetration testing is regularly performed
7 defined requirementsPerform internal and external penetration tests at least annually and after significant changes.
View defined requirements →Network intrusions and unexpected file changes are detected
3 defined requirementsUse IDS/IPS and file-integrity monitoring with response.
View defined requirements →Unauthorised changes on payment pages are detected
1 defined requirementMonitor payment-page scripts/headers for tampering (a v4.0 focus on e-skimming).
View defined requirements →Tips
- ›External scans must be by a PCI Approved Scanning Vendor (ASV), every quarter.
- ›Requirement 11.6 targets Magecart-style attacks, use script and HTTP-header change detection on payment pages.
Evidence to keep
- ✓Quarterly ASV scan reports
- ✓Penetration test reports
- ✓IDS/FIM configuration
- ✓Payment-page monitoring records
Example
Quarterly ASV scans plus internal scans, annual pen tests, file-integrity monitoring on CDE servers, and payment-page script monitoring all feed the response process.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.