Skip to main content

💼 11.4.2 Internal penetration testing is performed.

Description​

Including:

  • Per the entity's defined methodology,
  • At least once every 12 months
  • After any significant infrastructure or application upgrade or change
  • By a qualified internal resource or qualified external third-party
  • Organizational independence of the tester exists (not required to be a QSA or ASV).

Similar​

  • Sections
    • /frameworks/pci-dss-v3.2.1/11/03/02
    • /frameworks/pci-dss-v4.0.1/11/04/02
  • Internal
    • ID: dec-c-6214a1d3

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
💼 PCI DSS v3.2.1 → 💼 11.3.2 Perform internal penetration testing at least annually and after any significant infrastructure or application upgrade or modification.
💼 PCI DSS v4.0.1 → 💼 11.4.2 Internal penetration testing is performed.

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
💼 PCI DSS v3.2.1 → 💼 11.3.2 Perform internal penetration testing at least annually and after any significant infrastructure or application upgrade or modification.
💼 PCI DSS v4.0.1 → 💼 11.4.2 Internal penetration testing is performed.

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags