Test security of systems and networks regularly
Requirement 11 requires organizations to proactively identify and remediate security vulnerabilities through regular technical testing of the Cardholder Data Environment (CDE). This involves a combination of automated vulnerability scanning, manual penetration testing, and monitoring for unauthorized system changes.
What it means
The intent is to shift from a passive defense to an active one by simulating attacks and searching for weaknesses before they can be exploited. It ensures that security controls are not just implemented once, but remain effective as the network evolves and new threats emerge.
Scope includes all systems that store, process, or transmit cardholder data, as well as any system components that could impact the security of those systems. This encompasses both external-facing perimeters and internal network segments.
In practice, this requirement distinguishes between "scanning" (automated tools identifying known vulnerabilities) and "penetration testing" (manual efforts to exploit weaknesses). Organizations must perform both at defined intervals and after any significant change to the environment.
How to meet it
- Perform quarterly external vulnerability scans using a PCI Approved Scanning Vendor (ASV).
- Conduct internal vulnerability scans quarterly and after any significant change to the network.
- Execute annual internal and external penetration testing, ensuring tests cover the entire CDE scope.
- Implement File Integrity Monitoring (FIM) or similar change-detection software to alert personnel of unauthorized modifications to critical system files.
- Regularly scan for and identify rogue wireless access points that have been installed on the network without authorization.
- Establish a remediation process where "High" or "Critical" vulnerabilities found during scans are patched and then rescanned to verify the fix.
Evidence an auditor asks for
- Attestations of Scan Compliance (AoSC) provided by your ASV for the last four quarters.
- Internal vulnerability scan reports, including evidence that identified risks were remediated and verified via a follow-up scan.
- A formal penetration testing report from a qualified internal or external tester, detailing the scope, methodology, findings, and remediation steps taken.
- Configuration logs and alert history from your change-detection/FIM tools showing monitoring of critical files.
- Documentation of wireless scanning schedules and results proving no unauthorized access points were found (or that they were removed).
Common pitfalls
- Using a standard vulnerability scanner for external scans instead of one certified as an Approved Scanning Vendor (ASV).
- Performing penetration tests in a "sanitized" UAT environment rather than the actual production CDE, which fails to reflect real-world risk.
- Failing to trigger new scans or tests after a "significant change," relying solely on the annual or quarterly calendar.
- Documenting that vulnerabilities were "fixed" without providing the rescanning report that proves the vulnerability is actually gone.