Regularly Monitor and Test Networks
11
Test Security of Systems and Networks Regularly
Regular testing of security systems, processes, and controls is essential to detect vulnerabilities before attackers do. This requirement covers vulnerability scanning, penetration testing, change detection, and wireless network analysis. PCI DSS 4.0.1 introduced authenticated internal scanning and expanded penetration testing scope.
Control Intent
Continuously verify the effectiveness of security controls through regular vulnerability scanning, penetration testing, change detection mechanisms, and wireless analysis to identify and remediate vulnerabilities before exploitation.
Common Failures
- Vulnerability scans not performed at the required quarterly cadence or after significant changes
- Internal vulnerability scans run without authentication, missing vulnerabilities only visible to authenticated scanners
- Penetration testing not covering both internal and external attack vectors, or not testing application-layer vulnerabilities
- File-integrity monitoring not deployed on all critical system files, binaries, and configuration files
- Wireless scanning gaps — rogue access point detection not covering all CDE locations