CyberTRIZPEDIA

Regular Security Testing Programme

Control
PCI-R11-001
Regulation
PCI DSS
Category
technical
Priority
critical
Frequency
quarterly
Type
technical

What this control requires

Conduct quarterly internal/external network vulnerability scans, annual penetration testing (network and application), and change-triggered testing. Use approved scanning vendor (ASV) for external scans. Deploy IDS/IPS on CDE network boundaries. Implement file integrity monitoring (FIM) for critical CDE files.

Other PCI DSS controls