11.5 Network intrusions and unexpected file changes are detected
How to meet it
Use IDS/IPS and file-integrity monitoring with response.
Defined requirements
The individual PCI DSS v4.0.1 requirements under 11.5, in plain English.
11.5.1Intrusion-detection/prevention techniques monitor traffic at the CDE perimeter and critical points and alert on suspected compromise.
11.5.1.1Service providers detect, alert on or prevent, and address covert malware communication channels.
11.5.2A change-detection mechanism (file integrity monitoring) alerts on unauthorized modification of critical files, comparing at least weekly.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.
Incident response policyUse for ISO 27001 A.5.24 to A.5.28, SOC 2 incident response, PCI DSS 12.10, and security event handling.Logging and monitoring policyUse for ISO 27001 A.8.15, A.8.16, A.8.17, SOC 2 Security, and PCI DSS requirements 10 and 11.Malware protection policyUse for ISO 27001 A.8.7, SOC 2 Security, and PCI DSS requirement 5 anti-malware controls.Network security policyUse for ISO 27001 A.8.20, A.8.21, A.8.22, A.8.23, SOC 2 Security, and PCI DSS requirements 1 and 4.
Open the control-to-policy map← 11.4 Penetration testing is regularly performed11.6 Unauthorised changes on payment pages are detected →
Back to Requirement 11, or see PCI DSS templates. To run PCI controls with automation, read how AI manages controls.