Requirement 11 · Test security of systems and networks regularly

11.2 Wireless access points are identified and monitored

SCOPEEVIDENCERISKEVIDENCETESTEVIDENCEREPORTEVIDENCEAUDIT TRAIL11.2 Audit PathPOLICY / CONTROL / EVIDENCE / REVIEW

How to meet it

Detect authorised and rogue wireless access points periodically.

Defined requirements

The individual PCI DSS v4.0.1 requirements under 11.2, in plain English.

11.2.1Authorized and unauthorized wireless access points are managed, detected at least every three months, with alerts where automated.
11.2.2An inventory of authorized wireless access points is kept with a business justification for each.

Policy templates for this control

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map
Back to Requirement 11, or see PCI DSS templates. To run PCI controls with automation, read how AI manages controls.