PCI DSS v4.0.1 and Penetration Testing
The security standard for entities that store, process, transmit, or can affect the security of payment card data.
Planning testing under PCI DSS v4.0.1
Start with the Cardholder Data Environment, or CDE, and systems that can affect its security rather than only the payment page.

- Create data flows and an asset inventory to identify the CDE, connected-to systems, and security-impacting systems before planning tests.
- Requirement 11.4 calls for internal and external testing at least every 12 months and after significant infrastructure or application changes.
- Cover both network and application layers, including relevant threats and vulnerabilities from the prior 12 months.
- Where network segmentation reduces scope, test its effectiveness under the standard's conditions, remediate exploitable findings, and retest before relying on the evidence.
PAYMENT CARD INDUSTRY DATA SECURITY STANDARD
The security standard for entities that store, process, transmit, or can affect the security of payment card data.
ข้อกำหนดที่เกี่ยวข้องกับ Penetration Testing
- PCI DSS ออกโดย PCI Security Standards Council และใช้กับ Merchant, Acquirer, Issuer, Processor และ Service Provider ที่อยู่ในขอบเขต Cardholder Data Environment (CDE)
- Requirement 11.4 กำหนดการทดสอบภายในและภายนอกอย่างน้อยทุก 12 เดือน และหลังการอัปเกรดหรือเปลี่ยนแปลงโครงสร้างพื้นฐานหรือแอปพลิเคชันที่มีนัยสำคัญ
- วิธีทดสอบต้องครอบคลุม Network และ Application layer รวมถึงช่องโหว่และภัยคุกคามที่เกิดขึ้นในช่วง 12 เดือนที่ผ่านมา พร้อมแก้ไขช่องโหว่ที่ใช้โจมตีได้และ Retest เพื่อยืนยันผล
- หากใช้ Network Segmentation เพื่อลดขอบเขต PCI DSS ต้องทดสอบประสิทธิผลของการแบ่งส่วนตามความถี่และเงื่อนไขที่มาตรฐานกำหนด
ขอบเขต ความถี่ ผู้ทดสอบ และหลักฐานขึ้นอยู่กับประเภทองค์กรและวิธีประเมิน เช่น SAQ หรือ ROC ควรยืนยัน PCI DSS v4.0.1 ฉบับปัจจุบันกับ QSA หรือ Compliance ขององค์กร
Requirements and Testing Scope Matrix
Summary of the referenced clauses, the testing scope they cover, and the expected evaluation cycle.
| Reference | Mandate Title | Scope Required | Testing Cycle |
|---|---|---|---|
| Requirement 11.4 | External and Internal Penetration Testing | Entire Cardholder Data Environment (CDE) | At least annually |
| Requirement 11.4.5 | CDE Segmentation Isolation Verification | Network Segmentation Controls (Service Providers) | Every 6 months |
Compliance Readiness Self-Assessment
Select items your organization has completed to evaluate your readiness score.
