PCI DSS Security Maturity Model·AWS v1.0.0
Efficient Vulnerability Management 🤝 Shared

r11.5 Internal and external penetration testing

Perform internal and external penetration testing at least annually and after significant changes, including validation of the CDE segmentation controls.

Quick Wins
Foundational
Efficient
Optimized
Effort: High Impact: Medium Applies to CDE: Yes

AWS services

AWS (Customer Penetration Testing Policy)

Requirement 11

Test Security of Systems and Networks Regularly

PCI sub-requirements covered

  • 11.4 External and internal penetration testing is regularly performed

How to implement on AWS

Define a pentest methodology and engage qualified teams. AWS allows customer penetration testing on permitted services without prior approval (AWS pentesting policy). Validate segmentation (11.4.5) through targeted testing. Track remediation of exploitable findings.

Practical implementation

How this control is implemented in each reference architecture:

Engage a qualified team for annual internal/external penetration tests of the account, including a test of the subnet-based segmentation; track exploitable findings to closure.

Single-account, 3-tier →

Penetration testing validates the account/OU segmentation boundaries (Req 11.4.5) that this architecture relies on; test each internet-facing CDE account and the Transit Gateway isolation, tracking findings centrally.

Multi-account with a dedicated PCI OU →

PCI validation

Testing methods: examineinterview

Testing procedures

  • Examine documentation to verify the penetration-testing methodology covers all required elements (11.4.1).
  • Examine the scope and results of the most recent internal and external penetration tests (11.4.2.a, 11.4.3.a) and verify exploitable findings were corrected (11.4.4).
  • Examine segmentation controls and the most recent test results to verify all segmentation methods are tested (11.4.5.a, 11.4.5.b).

Evidence in AWS

  • Documented pentest methodology (aligned with 11.4.1).
  • Internal and external penetration test reports with remediation tracking.
  • CDE segmentation test results.

Customized approach

Requires a targeted risk analysis (Req 12.3.2).

Customized Approach Objective

  • 11.4 — Exploitable vulnerabilities and security weaknesses are identified through periodic penetration testing and corrected; segmentation controls, if used, are verified to be effective.

Learning resources

References

  • PCI DSS v4.0.1 Requirement 11.4