Penetration testing for PCI DSS Requirement 11.4

Of all the compliance frameworks, PCI DSS is the one that spells penetration testing out. Requirement 11.4 says what to test, how often, and what to do with the results. This page explains each part in plain language and how to meet it from the same platform you use for your ASV scans.

Penetration testing for PCI DSS Requirement 11.4

What Requirement 11.4 actually says

  • 11.4.1: You have a documented penetration testing methodology, covering the whole cardholder data environment and its boundaries, that includes application and network testing.
  • 11.4.2: Internal penetration testing at least every 12 months and after any significant infrastructure or application change.
  • 11.4.3: External penetration testing at least every 12 months and after any significant infrastructure or application change.
  • 11.4.4: Exploitable vulnerabilities found by testing are corrected and the fix is verified by retesting.
  • 11.4.5: If you use segmentation to isolate the cardholder data environment, segmentation controls are tested at least every 12 months and after any change to them.
  • 11.4.6: Service providers test segmentation at least every six months and after any change.
  • 11.4.7: Multi-tenant service providers support their customers' testing.

A penetration test is not the same as your quarterly ASV scan. Requirement 11.3 covers scanning; 11.4 covers testing. You need both.

Getting it done this week

Clone Systems sells both halves of 11.4 online. Automated external penetration testing, from $1,995 for one asset (30 days), covers 11.4.3. Automated internal penetration testing, from $2,995 for 25 hosts, covers 11.4.2. Retesting is included, which is 11.4.4. Both run on the same platform as your ASV scanning, so the systems in scope are already known. Segmentation testing and any test where your QSA requires a human tester are handled by managed penetration testing from Clone Systems engineers, scoped per environment.

Why Clone Systems

A PCI Approved Scanning Vendor since 2007. The same company that runs your quarterly ASV scans can run your annual penetration test, and your QSA gets one consistent set of reports.

Buy a pen test and start today · Request managed pen test scoping

Related

Clone Systems is a PCI Security Standards Council Approved Scanning Vendor, listed since 2007. This page is general guidance, not legal or audit advice.

Ready when you are

Ready to get your pen test done this week?

Automated penetration testing from Clone Systems starts at $1,995 for an external test and $2,995 for an internal test. Buy it online, start in minutes, and retest for free within your 30-day window.