PCI DSS 6.5.2: Upon completion of a significant change, all applicable PCI DSS requirements are confirmed

PCI DSS v4.0.1 control 6.5.2: the requirement in full, the 1 testing procedure an assessor uses to verify it, and the related controls in section 6.5.

Requirement 6: Develop and Maintain Secure Systems and Software › Section 6.5

Upon completion of a significant change, all applicable PCI DSS requirements are confirmed to be in place on all new or changed systems and networks, and documentation is updated as applicable.

Summary

After a significant change, check that the PCI DSS controls still hold on what changed, and update the documentation.

What the assessor will examine

These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.

Procedure
6.5.2 Examine documentation for significant changes, interview personnel, and observe the affected systems/networks to verify that the entity confirmed applicable PCI DSS requirements were in place on all new or changed systems and networks and that documentation was updated as applicable.

The broadest control in Requirement 6, because it does not stay inside it: all applicable PCI DSS requirements are confirmed to be in place. A network change means verifying Requirement 1 controls; a new system means verifying logging, anti-malware, access control and configuration standards. It is the control that connects change management to the whole standard, and it exists because compliance is a state that a change can silently end. The second half is quieter and just as testable: documentation is updated as applicable, which reaches the network diagram in 1.2.3, the data-flow diagram in 1.2.4, the service list in 1.2.5 and the inventories elsewhere. The procedure examines change documentation, interviews personnel, and observes the affected systems.

What to prepare

  • The list of significant changes since the last assessment.
  • For each, the record of which requirements were confirmed and how.
  • The documentation updated as a result.
  • The systems themselves, since the procedure observes them.

How to implement it

1. Make it a checklist attached to the change, not a memory exercise. Which requirements apply depends on what changed, and a short list per change type is what makes this repeatable.

2. Cover the documentation half explicitly. Diagrams and inventories are where the drift shows up at the next assessment, and updating them is cheapest at the moment of the change.

3. Use the same "significant" definition as 11.3.1.3 and 11.4.2. One trigger serving several controls is easier to operate and to evidence.

4. Record the confirmation, not just the change. The procedure looks for evidence the entity confirmed, which a change ticket alone does not show.

Where this commonly fails

  • Changes made and controls assumed to be unaffected, with nothing recorded.
  • Documentation not updated, so the diagrams describe the environment before the change.
  • A definition of significant narrow enough that this control rarely triggers.
  • Confirmation done informally, leaving nothing for the procedure to examine.

Others in section 6.5:

Control What it requires
6.5.1 Changes to all system components in the production environment are made according…
6.5.3 Pre-production environments are separated from production environments and the separation…
6.5.4 Roles and functions are separated between production and pre-production environments to provide…
6.5.5 Live PANs are not used in pre-production environments…
6.5.6 Test data and test accounts are removed from system components before the system goes into…

6.5.1 · All controls · 6.5.3

Source

The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.

The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.