PCI DSS 11.1.1: All security policies and operational procedures that are identified in Requirement 11

PCI DSS v4.0.1 control 11.1.1: the requirement in full, the 1 testing procedure an assessor uses to verify it, and the related controls in section 11.1.

Requirement 11: Test Security of Systems and Networks Regularly › Section 11.1

All security policies and operational procedures that are identified in Requirement 11 are:

  • Documented.
  • Kept up to date.
  • In use.
  • Known to all affected parties.

Summary

The policies and procedures behind Requirement 11 are written down, current, followed, and known to the people they apply to.

What the assessor will examine

These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.

Procedure
11.1.1 Examine documentation and interview personnel to verify that security policies and operational procedures are managed in accordance with all elements specified in this requirement.

Every requirement opens with this control and the same four bullets, so what matters is what Requirement 11 specifically does to it. Two things. First, one document inside the requirement has its own dedicated control: the penetration testing methodology that 11.4.1 mandates. That is the same shape Requirement 8 has with 8.3.8, and it leaves 11.1.1 covering everything else, which here is mostly operational procedure: how a scan is commissioned, how results are received and triaged, how rescans are tracked to closure. Second, "known to all affected parties" reads differently in a requirement this outsourced. Some affected parties are outside the organisation, and an ASV or a testing firm working to their own process rather than yours is the gap this bullet is asking about.

What to prepare

  • The Requirement 11 documents as a set: scanning procedures, the testing methodology, wireless detection, intrusion detection, change detection, payment page monitoring.
  • An owner and a review date on each.
  • Evidence they are in use, meaning the written process is the one being followed.
  • Who the affected parties are for each, including any external party performing the work.

How to implement it

1. List the documents before assessing them. Requirement 11 spreads across scanning, testing, monitoring and detection, often owned by different teams, and the set is usually assembled for the first time during the assessment.

2. Do not let 11.4.1 stand in for this. The testing methodology is one document with its own control; the scanning and monitoring procedures have no equivalent push and are the ones that go stale.

3. Include the external parties in "affected". Where an ASV or a testing firm performs the work, your procedure should describe the handoff, and they should know what you expect of it.

4. Check "in use" against practice. The usual divergence is remediation: the written triage timescales and the real ones.

Where this commonly fails

  • The penetration testing methodology maintained because 11.4.1 forces it, with the scanning procedures years out of date.
  • Procedures naming a scanning tool or vendor that has since been replaced.
  • External parties performing the work to their process with nothing recorded about yours.
  • A document set that exists only as an assessment artefact and is used at no other time.

Others in section 11.1:

Control What it requires
11.1.2 Roles and responsibilities for performing activities in Requirement 11 are documented…

10.7.3 · All controls · 11.1.2

Source

The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.

The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.