PCI compliance requirement 11: Testing

PCI compliance requirement 11: Testing

PCI compliance requirement 11: Testing

Date: Jun 01, 2009
Diana Kelley and Ed Moyle of Security Curve review PCI compliance requirement 11: "Regularly test security systems and processes." To meet PCI compliance requirement 11, you must:

  • Conduct required quarterly tests, like wireless and external scans
  • Conduct required annual tests, including penetration tests

The compliance experts also review common questions that they hear when doing their QSA work, including what exactly is meant by a 'penetration test' and what role file integrity monitoring can play when addressing the requirement.

Watch the rest of the PCI compliance videos, as Ed and Diana review what each particular requirement calls for.

Editor's note: This video is based on PCI DSS version 1.1. For updated information on the changes in PCI DSS version 1.2, see the following:

More on PCI Data Security Standard