3.14 Requirement 11
Join over 3 million cybersecurity professionals advancing their career
Sign up with
Required fields are marked with an *
Already have an account? Sign In »
3 hours 37 minutes
Welcome to the cyber. Very de mystify ing P C I. D. S s complaints. Course,
Miss Module, focus on the goals of the P C. I. D. S s and the requirements associated with them.
This video introduces you to requirement 11.
We will talk about the requirements associated with testing the security controls of the CD.
The learning objective of this video is to discuss the requirements in all the ends and out of testing security controls within the CD
requirement 11 is designed around testing the effectiveness of your security controls.
You need testing to make sure your controls air doing what you think they're doing, as well as discover any blind spots you may not have seen during your vulnerability analysis.
It also helps to discover assets that may exist that you don't even know about.
Or you might find some vulnerabilities that aren't covered in the rest of the P. C. I. D. S s requirements.
A lot of the time, you'll end up finding some configurations that have unintended adverse security effects
11 1 and is about handling of access points.
First, you need to check for all the rogue access points every three months.
Next, you need to make sure that you have an inventory of all of your authorized access points.
Managing your devices is covered in several crime. It's but we stated again here to make sure you know all of your devices.
Next, in the event that an unauthorized access point is detected, you need to have an incident response process to handle them.
You need to have an incident response policy anyway, but we're just calling it out here again, especially for wireless.
Now here's a bit of a wordy slide.
I group them together because they all focused on the same thing.
To summarize the requirement, you need tohave an internal and external scans conducted quarterly
internally, it has to be run by someone qualified
PC. I stays that the internal scans must be run by someone that is a reasonably independent from the system component being scanned or by a firm that specializes in vulnerability Scanning.
The external scan must be done by PC. I certified Approve scanning vendor or a SP.
This scan is against service Is that our public facing and used by your customers,
the scans were re occurring until you're gonna passing score
11 to 3 states that scans must occur after any significant change.
The guidance is that a significant changes when an upgrade or modification could allow access to cardholder data
or affect the security of the cardholder data environment.
So there's a significant difference between scans and penetration testing.
PC I recognizes this and mandates of penetration test occur annually or after any significant change.
Penetration test is more in depth and cannot be conducted via automated tools.
Penetration testers are testing controls and applying logic to circumvent what you have in place.
Penetration tests must occur from from external to your network
and internal to your network.
As threats can exist from both the inside and outside, it's important to test both.
A penetration test can be conducted by an internal independent resource or an external firm.
The penetration test methodology must follow Industry accepted best practices and include testing of controls as mandated in previous requirements like that of requirement six, not five,
11 33 states that any vulnerabilities that air discovered during the penetration test, you must implement a fix and then have it retested.
11 34 is just saying that if you have a limited scope in your CD, evey of via segmentation.
Those controls must be tested to confirm that they are effective
for service providers. They need to be tested every six months instead of annually.
11 4 Simple enough.
Along with firewalls, you need tohave, an intrusion detection system or I. D. S at your perimeter.
A lot of times these air built into firewalls or they can be dedicated devices,
but you need to make sure any signatures are up to date, as well as follow all the auditing and logging rules for previous requirements.
11 5 requires you haven't placed a tool that monitors important files for changes.
Clearly, this isn't meant for files that are constantly changing due to regular operations.
This is meant for files that should very rarely change under North normal circumstances.
Miss Control is meant to protect against a malicious person, replacing files that others could
used to compromise. A sense system
changing executed bols and D L L's could lead to an attacker breaking into a system
a lot of the time. Regular patching contribute this monitoring, so having in place a process to deal with normal operations
will help deal with the expected noise,
but you need to have a process to respond to unexpected alerts
and out for 11 6 you need to make sure you're documenting all your policies and procedures.
It's important to make sure that you have a process in place that lets auditor know when you have your test scheduled and have your results ready to show that you address any vulnerabilities that have been discovered.
So in this video, we went over how to go about testing your security control to be a scanning and penetration testing.
We also touched on some monitoring to detect potential malicious intrusions
and not for quick quist.
How often should penetration tests be conducted?
A. Every quarter,
be every two years,
see every year
or D every six months.
Penetration test should occur annually. Make sure you have the results for your auditor review,
but also, a penetration test should occur after any significant change.
Where does your ideas need to be monitoring traffic?
A. Every sub net.
Be at every endpoint
See at the e commerce site
or D at the perimeter.
I. D. S is must be deployed at the perimeter of your network.
Vulnerability scans must be conducted. How often?
A annually Be quarterly, see every six months D every two years,
Vulnerability scans need to happen every quarter.