Skip to main content

πŸ’Ό 11.4.3 External penetration testing is performed.

Description​

Including:

  • Per the entity's defined methodology
  • At least once every 12 months
  • After any significant infrastructure or application upgrade or change
  • By a qualified internal resource or qualified external third party
  • Organizational independence of the tester exists (not required to be a QSA or ASV).

Similar​

  • Sections
    • /frameworks/pci-dss-v3.2.1/11/03/01
    • /frameworks/pci-dss-v4.0.1/11/04/03

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό PCI DSS v3.2.1 β†’ πŸ’Ό 11.3.1 Perform external penetration testing at least annually and after any significant infrastructure or application upgrade or modification.
πŸ’Ό PCI DSS v4.0.1 β†’ πŸ’Ό 11.4.3 External penetration testing is performed.

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό PCI DSS v3.2.1 β†’ πŸ’Ό 11.3.1 Perform external penetration testing at least annually and after any significant infrastructure or application upgrade or modification.
πŸ’Ό PCI DSS v4.0.1 β†’ πŸ’Ό 11.4.3 External penetration testing is performed.

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags