Home / Companies / Basis Theory / Blog / Post Details
Content Deep Dive

PCI DSS Requirement 11: Test System & Network Security Often

Blog post from Basis Theory

Post Details
Company
Date Published
Author
Basis Theory
Word Count
1,842
Company Posts That Month
7
Language
English
Hacker News Points
-
Post removed?
No
Summary

PCI DSS Requirement 11 establishes controls for regularly testing the security of systems and networks that handle cardholder data, aiming to identify and remediate weaknesses before attackers exploit them. It requires documented policies, assigned responsibilities, wireless access-point inventories and monitoring, quarterly internal and external vulnerability scans, authenticated scans where feasible, and additional scans after significant changes. Organizations must also conduct independent internal and external penetration tests at least annually, validate network segmentation controls, correct exploitable findings, and retain testing and remediation records. The requirement further calls for intrusion-detection or prevention capabilities, weekly critical-file change detection, and mechanisms to identify unauthorized modifications to payment-page content and HTTP headers that could indicate web-skimming attacks. The text also presents Basis Theory, a PCI Level 1 compliant service provider, as a platform intended to help organizations reduce the scope and operational burden of handling cardholder data by using its independently assessed cardholder data environment.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.