PCI DSS 4.0 11.5.1: 11.5.1 IDS/IPS monitoring of CDE traffic
Network intrusions must be detected and/or prevented, using IDS and/or IPS techniques, in such a way that: all traffic at the CDE perimeter is monitored; all traffic at critical points inside the CDE is monitored; personnel receive alerts about suspected compromises; and every detection and prevention engine, baseline and signature is kept up to date. Guidance (definition): critical points can include network security controls between segments (for instance between a DMZ and the internal network, or between networks inside and outside scope) and points guarding connections from less trusted to more trusted components. Objective under the customized approach: mechanisms that detect suspicious or anomalous network traffic in real time, which may point to threat actor activity, are in place, and their alerts are acted on by staff or by automated responses that prevent system components being compromised by the detected activity.
This control maps to 78 controls across 22 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
You are reading one control. How much of PCI DSS 4.0 have you already done?
PCI DSS 4.0 11.5.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of PCI DSS 4.0 your existing evidence covers. Hold ISO 27001:2022 and 139 of 280 PCI DSS 4.0 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 415 were rejected on the ISO 27001:2022 pair alone.