PCI 11:
Jump to navigation
Jump to search
Requirement 11: Regularly test security systems and processes.
- Vulnerabilities are continually being discovered by hackers/researchers and introduced by new software. Systems, processes, and custom software should be tested frequently to ensure security is maintained over time and through changes.
- Note that external vulnerability scans must be performed by a scan vendor qualified by the payment card industry.
- Note that external vulnerability scans must be performed by a scan vendor qualified by the payment card industry.
- Critical files are not necessarily those containing cardholder data. For file integrity monitoring purposes, critical files are usually those that do not regularly change, but the modification of which could indicate a system compromise or risk of compromise. File integrity monitoring products usually come pre-configured with critical files for the related operating system. Other critical files, such as those for custom applications, must be evaluated and defined by the merchant or service provider.
- Critical files are not necessarily those containing cardholder data. For file integrity monitoring purposes, critical files are usually those that do not regularly change, but the modification of which could indicate a system compromise or risk of compromise. File integrity monitoring products usually come pre-configured with critical files for the related operating system. Other critical files, such as those for custom applications, must be evaluated and defined by the merchant or service provider.
- Maintain an Information Security Policy.
--Mdpeters 11:27, 7 July 2006 (EDT)