Siam Thanat Hack Co., Ltd.

PCI DSS v4.0.1 and Penetration Testing

The security standard for entities that store, process, transmit, or can affect the security of payment card data.

Executive Summary and Mandate Overview
Target Audience Merchants, Payment Processors, Gateways, and E-commerce handling card data (CDE)
Mandatory Frequency Annually (Req 11.4). Every 6 months for CDE Segmentation (Service Providers)
Required Scope Cardholder Data Environment (CDE), Payment APIs, External and Internal Network
Non-Compliance Risk Monthly card brand fines ($5,000 to $100,000 per month) and loss of card processing privileges

Planning testing under PCI DSS v4.0.1

Start with the Cardholder Data Environment, or CDE, and systems that can affect its security rather than only the payment page.

Thai infographic explaining: Planning testing under PCI DSS v4.0.1
Visual summary: Planning testing under PCI DSS v4.0.1
  • Create data flows and an asset inventory to identify the CDE, connected-to systems, and security-impacting systems before planning tests.
  • Requirement 11.4 calls for internal and external testing at least every 12 months and after significant infrastructure or application changes.
  • Cover both network and application layers, including relevant threats and vulnerabilities from the prior 12 months.
  • Where network segmentation reduces scope, test its effectiveness under the standard's conditions, remediate exploitable findings, and retest before relying on the evidence.

PAYMENT CARD INDUSTRY DATA SECURITY STANDARD

The security standard for entities that store, process, transmit, or can affect the security of payment card data.

ข้อกำหนดที่เกี่ยวข้องกับ Penetration Testing

  • PCI DSS ออกโดย PCI Security Standards Council และใช้กับ Merchant, Acquirer, Issuer, Processor และ Service Provider ที่อยู่ในขอบเขต Cardholder Data Environment (CDE)
  • Requirement 11.4 กำหนดการทดสอบภายในและภายนอกอย่างน้อยทุก 12 เดือน และหลังการอัปเกรดหรือเปลี่ยนแปลงโครงสร้างพื้นฐานหรือแอปพลิเคชันที่มีนัยสำคัญ
  • วิธีทดสอบต้องครอบคลุม Network และ Application layer รวมถึงช่องโหว่และภัยคุกคามที่เกิดขึ้นในช่วง 12 เดือนที่ผ่านมา พร้อมแก้ไขช่องโหว่ที่ใช้โจมตีได้และ Retest เพื่อยืนยันผล
  • หากใช้ Network Segmentation เพื่อลดขอบเขต PCI DSS ต้องทดสอบประสิทธิผลของการแบ่งส่วนตามความถี่และเงื่อนไขที่มาตรฐานกำหนด
ก่อนใช้ยื่น Compliance

ขอบเขต ความถี่ ผู้ทดสอบ และหลักฐานขึ้นอยู่กับประเภทองค์กรและวิธีประเมิน เช่น SAQ หรือ ROC ควรยืนยัน PCI DSS v4.0.1 ฉบับปัจจุบันกับ QSA หรือ Compliance ขององค์กร

Requirements and Testing Scope Matrix

Summary of the referenced clauses, the testing scope they cover, and the expected evaluation cycle.

Reference Mandate Title Scope Required Testing Cycle
Requirement 11.4 External and Internal Penetration Testing Entire Cardholder Data Environment (CDE) At least annually
Requirement 11.4.5 CDE Segmentation Isolation Verification Network Segmentation Controls (Service Providers) Every 6 months

Compliance Readiness Self-Assessment

Select items your organization has completed to evaluate your readiness score.

0%

Official source documents

Download the official PCI DSS document from the PCI SSC library.

Go to the official source