CyberTRIZPEDIA

Conduct Regular Security Testing of CDE

Control
PCI-TEST-001
Regulation
PCI DSS
Category
operational
Priority
high
Frequency
annually
Type
operational

What this control requires

Test security systems and processes: conduct quarterly internal/external network vulnerability scans, perform annual penetration testing (network and application layer), implement change-triggered penetration testing, deploy intrusion detection/prevention systems, and implement file integrity monitoring (FIM) for critical files. Remediate all critical and high findings within 30 days.

Other PCI DSS controls