PCI Pentetration Testing
Stay Safe by Going Beyond “Check Box” Security
PCI Penetration Testing Has Specific Requierments
Segmentation testing
Re-test for vailidation
PCI approved reporting
PCI Compliance is a Big Part of What We Do to Keep Our Customers Safe
PCI-DSS V4 Penetration Test Requirements
Effective March 31, 2022
11.4.2 Perform internal penetration testing at least annually and after any significant infrastructure or application upgrade or modification (such as an operating system upgrade, a sub-network added to the environment, or a web server added to the environment).
11.4.3 Perform external penetration testing at least annually and after any significant infrastructure or application upgrade or modification (such as an operating system upgrade, a sub-network added to the environment, or a web server added to the environment).
11.4.4 Correct any findings from penetration testing activities as recommended and repeat penetration testing.
11.4.5 If segmentation is used to isolate the CDE from other networks, perform penetration tests at least annually and after any changes to segmentation controls/methods to verify that the segmentation methods are operational and effective and that they isolate all out of scope systems from systems in the CDE.