PCI DSS 11.1.2: Roles and responsibilities for performing activities in Requirement 11 are documented

PCI DSS v4.0.1 control 11.1.2: the requirement in full, the 2 testing procedures an assessor uses to verify it, and the related controls in section 11.1.

Requirement 11: Test Security of Systems and Networks Regularly › Section 11.1

Roles and responsibilities for performing activities in Requirement 11 are documented, assigned, and understood.

Summary

Someone internal is named for each Requirement 11 activity, including the ones a third party performs.

What the assessor will examine

These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.

Procedure
11.1.2.a Examine documentation to verify that descriptions of roles and responsibilities for performing activities in Requirement 11 are documented and assigned.
11.1.2.b Interview personnel with responsibility for performing activities in Requirement 11 to verify that roles and responsibilities are assigned as documented and are understood.

Requirement 11 is the most outsourced requirement in the standard, and that is what makes this control specific rather than generic. The quarterly external scan in 11.3.2 must be performed by an Approved Scanning Vendor; penetration testing under 11.4.2 and 11.4.3 usually is too. Outsourcing the activity does not outsource the responsibility, and "the ASV does it" is not an answer to who is responsible. Someone has to commission the work, receive the results, decide what gets remediated and by when, confirm the rescan, and notice when a quarter has gone by without a scan. Procedure 11.1.2.b interviews the people named, so those roles have to be held by someone who knows they hold them.

What to prepare

  • A responsibility matrix by role for each Requirement 11 activity, distinguishing who performs it from who owns it.
  • The internal owner for each outsourced activity: commissioning, receiving, remediating, confirming.
  • Evidence the assignment reached its holder.
  • Named cover, since several of these are periodic and easy to miss when one person is away.

How to implement it

1. Separate performs from owns for every outsourced activity. The vendor performs; someone here owns. Writing both columns is what makes this control answerable.

2. Name who notices a missed cycle. Quarterly scans and annual tests fail quietly by not happening, and that is a responsibility in its own right.

3. Assign remediation separately from testing. The party that finds a vulnerability is rarely the party that fixes it, and 11.4.4 makes the fix a requirement.

4. Assign by role and keep a role-to-person mapping current. A rota survives a departure; a name does not.

Where this commonly fails

  • Outsourced activities left unassigned internally, so nobody owns the scan the vendor runs.
  • No named owner for the calendar, so a missed quarter is discovered at the assessment.
  • Everything assigned to security, including remediation that only the system owners can perform.
  • A matrix naming a team that a reorganisation has dissolved.

Others in section 11.1:

Control What it requires
11.1.1 All security policies and operational procedures that are identified in Requirement 11…

11.1.1 · All controls · 11.2.1

Source

The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.

The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.