PCI DSS 11.4.6 (service providers): If segmentation is used to isolate the CDE from other networks
PCI DSS v4.0.1 control 11.4.6: the requirement in full, the 2 testing procedures an assessor uses to verify it, and the related controls in section 11.4.
Requirement 11: Test Security of Systems and Networks Regularly › Section 11.4
Additional requirement for service providers only: If segmentation is used to isolate the CDE from other networks, penetration tests are performed on segmentation controls as follows:
- At least once every six months and after any changes to segmentation controls/methods.
- Covering all segmentation controls/methods in use.
- According to the entity’s defined penetration testing methodology.
- Confirming that the segmentation controls/methods are operational and effective, and isolate the CDE from all out-of-scope systems.
- Confirming effectiveness of any use of isolation to separate systems with differing security levels (see Requirement 2.2.3).
- Performed by a qualified internal resource or qualified external third party.
- Organizational independence of the tester exists (not required to be a QSA or ASV).
Summary
Service providers only: the same segmentation testing as everyone else, but every six months.
What the assessor will examine
These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.
| Procedure | |
|---|---|
| 11.4.6.a | Additional testing procedure for service provider assessments only: Examine the results from the most recent penetration test to verify that the penetration covers and addressed all elements specified in this requirement. |
| 11.4.6.b | Additional testing procedure for service provider assessments only: Interview personnel to verify that the test was performed by a qualified internal resource or qualified external third party and that organizational independence of the tester exists (not required to be a QSA or ASV). |
Identical in substance to 11.4.5 with one difference that is the whole control: at least once every six months rather than every twelve. It is one of the semi-annual cadences entities schedule annually out of habit, alongside 1.2.7 and the scope confirmation in 12.5.2.1, and a test performed once in the year fails on frequency however good it is. The reason for the shorter cycle is worth stating: a service provider's segmentation is usually what separates one customer from another, so a failure exposes other people's data rather than only the provider's own.
What to prepare
- Everything 11.4.5 requires, plus dates showing the six-month interval.
- The last two tests, so the interval is visible rather than asserted.
- Change records for segmentation, with a test after each.
How to implement it
1. Schedule both tests at the start of the year with fixed dates. Two tests bunched into one half of the year meet the count and not the interval.
2. Read 11.4.5 for the substance. Every element there applies here, and this control adds only the cadence.
3. Include the customer boundary explicitly. For a multi-tenant provider, isolation between customers is the segmentation that matters most and is not always what a general test targets.
4. Check whether you are a service provider for this purpose. Entities that store, process or transmit account data on behalf of others often do not think of themselves that way until an assessor says so.
Where this commonly fails
- Annual testing carried over from a merchant-shaped programme.
- Both tests in the same half of the year, so the gap between them exceeds six months.
- Testing the perimeter and not the boundaries between customers.
- A merchant applying this to itself, which is effort spent on a service provider requirement.
Related controls
This control refers to 2.2.3.
Others in section 11.4:
| Control | What it requires |
|---|---|
| 11.4.1 | A penetration testing methodology is defined, documented, and implemented by the entity… |
| 11.4.2 | Internal penetration testing is performed… |
| 11.4.3 | External penetration testing is performed… |
| 11.4.4 | Exploitable vulnerabilities and security weaknesses found during penetration testing… |
| 11.4.5 | If segmentation is used to isolate the CDE from other networks… |
| 11.4.7 | Multi-tenant service providers support their customers for external penetration testing per… |
← 11.4.5 · All controls · 11.4.7 →
Source
The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.
The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.