Regularly monitor and test networks

Requirement 11: Test security of systems and networks regularly

Controls degrade over time; regular scanning and testing find new weaknesses before attackers do.

SCOPEEVIDENCERISKEVIDENCETESTEVIDENCEREPORTEVIDENCEAUDIT TRAILPCI Req 11 EvidencePOLICY / CONTROL / EVIDENCE / REVIEW

Sub-requirements

Tips

  • External scans must be by a PCI Approved Scanning Vendor (ASV), every quarter.
  • Requirement 11.6 targets Magecart-style attacks, use script and HTTP-header change detection on payment pages.

Evidence to keep

  • Quarterly ASV scan reports
  • Penetration test reports
  • IDS/FIM configuration
  • Payment-page monitoring records

Example

Quarterly ASV scans plus internal scans, annual pen tests, file-integrity monitoring on CDE servers, and payment-page script monitoring all feed the response process.

Policy templates for this control

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map