312-50V11 · Question #8
When does the Payment Card Industry Data Security Standard (PCI-DSS) require organizations to perform external and internal penetration testing?
The correct answer is B. At least once a year and after any significant upgrade or modification. PCI-DSS Requirement 11.3 mandates that organizations conduct penetration testing at least once per year and after any significant infrastructure upgrade or modification.
Question
When does the Payment Card Industry Data Security Standard (PCI-DSS) require organizations to perform external and internal penetration testing?
Options
- AAt least twice a year or after any significant upgrade or modification
- BAt least once a year and after any significant upgrade or modification
- CAt least once every two years and after any significant upgrade or modification
- DAt least once every three years or after any significant upgrade or modification
How the community answered
(21 responses)- A5% (1)
- B86% (18)
- D10% (2)
Why each option
PCI-DSS Requirement 11.3 mandates that organizations conduct penetration testing at least once per year and after any significant infrastructure upgrade or modification.
PCI-DSS does not require penetration testing twice a year as a baseline; the requirement is annually, not semi-annually.
PCI-DSS Requirement 11.3 explicitly states that penetration testing must be performed at least annually and after any significant changes to the network or applications, such as a new system component installation, network topology changes, or firewall rule modifications. The 'and' conjunction is critical - both conditions are required rather than either/or. This ensures ongoing validation of security controls over time and after change events.
A two-year cycle does not meet the PCI-DSS annual minimum penetration testing requirement defined in Requirement 11.3.
A three-year cycle significantly under-meets the PCI-DSS requirement and would place an organization out of compliance.
Concept tested: PCI-DSS penetration testing frequency requirements
Source: https://www.pcisecuritystandards.org/documents/Penetration_Testing_Guidance_March_2015.pdf
Topics
Community Discussion
No community discussion yet for this question.