PCI DSS Requirement 11: Test System & Network Security Often
Blog post from Basis Theory
PCI DSS Requirement 11 establishes controls for regularly testing the security of systems and networks that handle cardholder data, aiming to identify and remediate weaknesses before attackers exploit them. It requires documented policies, assigned responsibilities, wireless access-point inventories and monitoring, quarterly internal and external vulnerability scans, authenticated scans where feasible, and additional scans after significant changes. Organizations must also conduct independent internal and external penetration tests at least annually, validate network segmentation controls, correct exploitable findings, and retain testing and remediation records. The requirement further calls for intrusion-detection or prevention capabilities, weekly critical-file change detection, and mechanisms to identify unauthorized modifications to payment-page content and HTTP headers that could indicate web-skimming attacks. The text also presents Basis Theory, a PCI Level 1 compliant service provider, as a platform intended to help organizations reduce the scope and operational burden of handling cardholder data by using its independently assessed cardholder data environment.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.