Siam Thanat Hack Co., Ltd.

PCI DSS v4.0.1 and Penetration Testing

The security standard for entities that store, process, transmit, or can affect the security of payment card data.

Planning testing under PCI DSS v4.0.1

Start with the Cardholder Data Environment, or CDE, and systems that can affect its security rather than only the payment page.

Thai infographic explaining: Planning testing under PCI DSS v4.0.1
Visual summary: Planning testing under PCI DSS v4.0.1
  • Create data flows and an asset inventory to identify the CDE, connected-to systems, and security-impacting systems before planning tests.
  • Requirement 11.4 calls for internal and external testing at least every 12 months and after significant infrastructure or application changes.
  • Cover both network and application layers, including relevant threats and vulnerabilities from the prior 12 months.
  • Where network segmentation reduces scope, test its effectiveness under the standard's conditions, remediate exploitable findings, and retest before relying on the evidence.

PAYMENT CARD INDUSTRY DATA SECURITY STANDARD

The security standard for entities that store, process, transmit, or can affect the security of payment card data.

ข้อกำหนดที่เกี่ยวข้องกับ Penetration Testing

  • PCI DSS ออกโดย PCI Security Standards Council และใช้กับ Merchant, Acquirer, Issuer, Processor และ Service Provider ที่อยู่ในขอบเขต Cardholder Data Environment (CDE)
  • Requirement 11.4 กำหนดการทดสอบภายในและภายนอกอย่างน้อยทุก 12 เดือน และหลังการอัปเกรดหรือเปลี่ยนแปลงโครงสร้างพื้นฐานหรือแอปพลิเคชันที่มีนัยสำคัญ
  • วิธีทดสอบต้องครอบคลุม Network และ Application layer รวมถึงช่องโหว่และภัยคุกคามที่เกิดขึ้นในช่วง 12 เดือนที่ผ่านมา พร้อมแก้ไขช่องโหว่ที่ใช้โจมตีได้และ Retest เพื่อยืนยันผล
  • หากใช้ Network Segmentation เพื่อลดขอบเขต PCI DSS ต้องทดสอบประสิทธิผลของการแบ่งส่วนตามความถี่และเงื่อนไขที่มาตรฐานกำหนด
ก่อนใช้ยื่น Compliance

ขอบเขต ความถี่ ผู้ทดสอบ และหลักฐานขึ้นอยู่กับประเภทองค์กรและวิธีประเมิน เช่น SAQ หรือ ROC ควรยืนยัน PCI DSS v4.0.1 ฉบับปัจจุบันกับ QSA หรือ Compliance ขององค์กร

Official source documents

Download the official PCI DSS document from the PCI SSC library.

Go to the official source