Organizational Independence
PCIComplianceHubLast updated
A reporting structure in which the person or team assessing an activity has no conflict of interest with the person or team performing it. The standard requires it of whoever runs internal vulnerability scans, post-change external scans and penetration tests, and it says explicitly that this does not require a QSA or an ASV.
Applies to. Any entity performing its own scanning or testing rather than engaging an outside firm.
Example. The engineer who configures the firewalls does not run the segmentation test that checks them; a colleague in a different reporting line does, or an external tester. The tester need hold no certification; the independence is what the control asks for.
Limits. Independence is organisational, not technical: the same tool run by the team being tested does not qualify, and a report signed off by the manager whose environment it covers does not either. The controls naming it are 11.3.1 and 11.3.1.3 (internal scans), 11.3.2.1 (external scans after significant change), 11.4.2, 11.4.3 and 11.4.5 (penetration tests). The quarterly external scan under 11.3.2 is the one that does require an ASV.