What Requirement 11.4 actually says
- 11.4.1: You have a documented penetration testing methodology, covering the whole cardholder data environment and its boundaries, that includes application and network testing.
- 11.4.2: Internal penetration testing at least every 12 months and after any significant infrastructure or application change.
- 11.4.3: External penetration testing at least every 12 months and after any significant infrastructure or application change.
- 11.4.4: Exploitable vulnerabilities found by testing are corrected and the fix is verified by retesting.
- 11.4.5: If you use segmentation to isolate the cardholder data environment, segmentation controls are tested at least every 12 months and after any change to them.
- 11.4.6: Service providers test segmentation at least every six months and after any change.
- 11.4.7: Multi-tenant service providers support their customers' testing.
A penetration test is not the same as your quarterly ASV scan. Requirement 11.3 covers scanning; 11.4 covers testing. You need both.
Getting it done this week
Clone Systems sells both halves of 11.4 online. Automated external penetration testing, from $1,995 for one asset (30 days), covers 11.4.3. Automated internal penetration testing, from $2,995 for 25 hosts, covers 11.4.2. Retesting is included, which is 11.4.4. Both run on the same platform as your ASV scanning, so the systems in scope are already known. Segmentation testing and any test where your QSA requires a human tester are handled by managed penetration testing from Clone Systems engineers, scoped per environment.
Why Clone Systems
A PCI Approved Scanning Vendor since 2007. The same company that runs your quarterly ASV scans can run your annual penetration test, and your QSA gets one consistent set of reports.
Buy a pen test and start today · Request managed pen test scoping
Related
- A real penetration test used to cost $10,000
- Penetration testing for SOC 2
- Penetration testing for HIPAA
- Penetration testing for ISO 27001
Clone Systems is a PCI Security Standards Council Approved Scanning Vendor, listed since 2007. This page is general guidance, not legal or audit advice.
