Skip to main content

๐Ÿ’ผ 11.4 External and internal penetration testing is regularly performed, and exploitable vulnerabilities and security weaknesses are corrected.

  • Contextual name: ๐Ÿ’ผ 11.4 External and internal penetration testing is regularly performed, and exploitable vulnerabilities and security weaknesses are corrected.

  • ID: /frameworks/pci-dss-v4.0/11/04

  • Located in: ๐Ÿ’ผ 11 Test Security of Systems and Networks Regularly

Descriptionโ€‹

Empty...

Similarโ€‹

Sub Sectionsโ€‹

SectionSub SectionsInternal RulesPoliciesFlags
๐Ÿ’ผ 11.4.1 A penetration testing methodology is defined, documented, and implemented by the entity.
๐Ÿ’ผ 11.4.2 Internal penetration testing is performed.
๐Ÿ’ผ 11.4.3 External penetration testing is performed.
๐Ÿ’ผ 11.4.4 Exploitable vulnerabilities and security weaknesses found during penetration testing are corrected.
๐Ÿ’ผ 11.4.5 If segmentation is used to isolate the CDE from other networks, penetration tests are performed on segmentation controls.
๐Ÿ’ผ 11.4.6 If segmentation is used to isolate the CDE from other networks, penetration tests are performed on segmentation controls.
๐Ÿ’ผ 11.4.7 Multi-tenant service providers support their customers for external penetration testing per Requirement 11.4.3 and 11.4.4.