PCI_DSS_v4Requirement 11voice-validated
PCI_DSS_v4 R11: Requirement 11
PCI_DSS_v4
AL
Founder at SQUR · last verified 2026-10-06
Regulation text
Vulnerabilities are being discovered continually by malicious individuals and researchers, and being introduced by new software. System components, processes, and bespoke and custom software should be tested frequently to ensure security controls continue to reflect a changing environment. Includes internal vulnerability scans, external vulnerability scans by an Approved Scanning Vendor (ASV), and annual penetration testing.
ATT&CK techniques this article tests · 15
| Technique | Why it maps | Confidence |
|---|---|---|
| T1190 | 1. Vulnerability scans and penetration tests identify weaknesses in public-facing applications, preventing initial access by attackers. | 90% |
| T1046 | 1. Internal and external vulnerability scans actively perform network service scanning to discover open ports and services, a key discovery technique. | 90% |
| T1087 | 1. Penetration tests often include account enumeration and discovery to identify valid user accounts, a critical step for credential access. | 80% |
| T1083 | 1. Penetration testers perform file and directory discovery to locate sensitive information or misconfigurations, identifying potential data collection points. | 80% |
| T1068 | 1. Penetration testing explicitly attempts to exploit vulnerabilities for privilege escalation, assessing the effectiveness of existing controls. | 90% |
| T1562 | 1. Penetration tests evaluate if security controls can be impaired or bypassed, directly assessing defense evasion capabilities. | 70% |
| T1003 | 1. Penetration tests attempt OS credential dumping to assess the risk of credential access if a system is compromised. | 80% |
| T1552 | 1. Vulnerability assessments and penetration tests identify unsecured credentials stored in configuration files or code, preventing credential access. | 80% |
| T1021 | 1. Penetration tests simulate lateral movement by exploiting remote services, identifying pathways an attacker could use. | 80% |
| T1005 | 1. Penetration tests assess the ability to collect data from local systems once access is gained, evaluating data exposure risks. | 70% |
| T1071 | 1. Penetration tests can simulate command and control communication over application layer protocols, testing network egress controls. | 70% |
| T1041 | 1. Penetration tests may attempt exfiltration over C2 channels to demonstrate data theft capabilities, assessing data loss prevention. | 70% |
| T1490 | 1. Penetration tests can identify vulnerabilities that could lead to inhibiting system recovery, assessing potential impact on business continuity. | 60% |
| T1547 | 1. Penetration tests may attempt to establish persistence mechanisms like boot or logon autostart execution, identifying long-term compromise risks. | 70% |
| T1018 | 1. Vulnerability scans and penetration tests perform remote system discovery to map the network and identify potential targets. | 80% |
Defending mitigations · 6
| Mitigation | What it does | Confidence |
|---|---|---|
| M1050 | 1. Requirement 11 explicitly mandates vulnerability scanning, directly implementing this mitigation to identify system weaknesses. | 100% |
| M1035 | 1. Vulnerability assessments identify unnecessary open ports and services, leading to limiting access to resources over the network and reducing attack surface. | 90% |
| M1048 | 1. Penetration tests evaluate the effectiveness of network segmentation, ensuring that a compromise in one segment does not lead to widespread lateral movement. | 90% |
| M1028 | 1. Vulnerability scans identify misconfigurations and unpatched systems, driving improvements in operating system configuration and hardening. | 80% |
| M1016 | 1. Penetration tests often uncover weak or default credentials, reinforcing the need for robust account use policies to prevent credential access. | 80% |
| M1031 | 1. Penetration tests can assess if network intrusion prevention systems effectively detect and block exploitation attempts identified during testing. | 70% |
Underlying weaknesses · 7
| CWE | Why it persists | Confidence |
|---|---|---|
| CWE-89 | 1. Vulnerability scans and penetration tests frequently uncover SQL Injection flaws, a common web application weakness allowing data manipulation or exfiltration. | 90% |
| CWE-79 | 1. Cross-site Scripting vulnerabilities are often identified by web application scans and penetration tests, posing risks for session hijacking and client-side attacks. | 90% |
| CWE-200 | 1. Many vulnerabilities discovered by Requirement 11's testing lead to the exposure of sensitive information, a critical data breach risk. | 80% |
| CWE-287 | 1. Penetration tests often exploit improper authentication mechanisms, gaining unauthorized access to systems and data. | 80% |
| CWE-269 | 1. Improper privilege management is a common finding in penetration tests, allowing attackers to escalate privileges post-initial compromise. | 80% |
| CWE-78 | 1. OS Command Injection vulnerabilities are critical findings in application and system tests, enabling remote code execution. | 80% |
| CWE-502 | 1. Deserialization of untrusted data is a high-impact vulnerability often identified by thorough application security testing, leading to remote code execution. | 70% |
What SQUR Covers
Web application + API pentesting for OWASP Top 10, business logic flaws, authentication bypass, injection attacks, and other application-layer vulnerabilities. €1,995 per scan, 24-hour turnaround, EU-only data.
What SQUR Does Not Cover
Internal network pentesting, endpoint security testing, physical security assessments, social engineering, or ICT third-party concentration risk reviews. Engage a complementary provider for those scope items.
Provenance
Mapped Q2.2026 using gemini-2.5-flash · €0.0171 compute · voice-rubric self-validated · 1 hallucination(s) dropped at validation