r11.5 Internal and external penetration testing
Perform internal and external penetration testing at least annually and after significant changes, including validation of the CDE segmentation controls.
AWS services
Requirement 11
Test Security of Systems and Networks Regularly
PCI sub-requirements covered
- 11.4 External and internal penetration testing is regularly performed
How to implement on AWS
Define a pentest methodology and engage qualified teams. AWS allows customer penetration testing on permitted services without prior approval (AWS pentesting policy). Validate segmentation (11.4.5) through targeted testing. Track remediation of exploitable findings.
Practical implementation
How this control is implemented in each reference architecture:
Engage a qualified team for annual internal/external penetration tests of the account, including a test of the subnet-based segmentation; track exploitable findings to closure.
Single-account, 3-tier →Penetration testing validates the account/OU segmentation boundaries (Req 11.4.5) that this architecture relies on; test each internet-facing CDE account and the Transit Gateway isolation, tracking findings centrally.
Multi-account with a dedicated PCI OU →PCI validation
Testing procedures
- Examine documentation to verify the penetration-testing methodology covers all required elements (11.4.1).
- Examine the scope and results of the most recent internal and external penetration tests (11.4.2.a, 11.4.3.a) and verify exploitable findings were corrected (11.4.4).
- Examine segmentation controls and the most recent test results to verify all segmentation methods are tested (11.4.5.a, 11.4.5.b).
Evidence in AWS
- Documented pentest methodology (aligned with 11.4.1).
- Internal and external penetration test reports with remediation tracking.
- CDE segmentation test results.
Customized approach
Requires a targeted risk analysis (Req 12.3.2).
Customized Approach Objective
- 11.4 — Exploitable vulnerabilities and security weaknesses are identified through periodic penetration testing and corrected; segmentation controls, if used, are verified to be effective.
Learning resources
- AWS Penetration Testing (doc)
References
- PCI DSS v4.0.1 Requirement 11.4
PCI DSS Security Maturity Model