PCI DSS 4.0
Req 11: Test Security Regularly

PCI DSS 4.0 11.5.1: 11.5.1 IDS/IPS monitoring of CDE traffic

Network intrusions must be detected and/or prevented, using IDS and/or IPS techniques, in such a way that: all traffic at the CDE perimeter is monitored; all traffic at critical points inside the CDE is monitored; personnel receive alerts about suspected compromises; and every detection and prevention engine, baseline and signature is kept up to date. Guidance (definition): critical points can include network security controls between segments (for instance between a DMZ and the internal network, or between networks inside and outside scope) and points guarding connections from less trusted to more trusted components. Objective under the customized approach: mechanisms that detect suspicious or anomalous network traffic in real time, which may point to threat actor activity, are in place, and their alerts are acted on by staff or by automated responses that prevent system components being compromised by the detected activity.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 78 controls across 22 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

FedRAMP High · 13 controls

  • AC-17(1) Monitoring and Control
  • AU-6(3) Correlate Audit Record Repositories
  • CM-8(3) Automated Unauthorized Component Detection
  • IR-1 Policy and Procedures
  • IR-5 Incident Monitoring
  • IR-7(1) Incident Response Assistance | Automation Support for Availability of Information and Support (IR-7(1))
  • SC-5 Denial-of-Service Protection
  • SC-7(8) Route Traffic to Authenticated Proxy Servers
  • SI-4 System Monitoring
  • SI-4(1) System Monitoring | System-wide Intrusion Detection System (SI-4(1))
  • SI-4(16) System Monitoring | Correlate Monitoring Information (SI-4(16))
  • SI-4(4) Inbound and Outbound Communications Traffic
  • SI-4(5) System-Generated Alerts

FedRAMP Moderate · 13 controls

  • AC-17(1) Monitoring and Control
  • AU-6(3) Correlate Audit Record Repositories
  • CM-8(3) Automated Unauthorized Component Detection
  • IR-1 Policy and Procedures
  • IR-5 Incident Monitoring
  • IR-7(1) Incident Response Assistance | Automation Support for Availability of Information and Support (IR-7(1))
  • SC-5 Denial-of-Service Protection
  • SC-7(8) Route Traffic to Authenticated Proxy Servers
  • SI-4 System Monitoring
  • SI-4(1) System Monitoring | System-wide Intrusion Detection System (SI-4(1))
  • SI-4(16) System Monitoring | Correlate Monitoring Information (SI-4(16))
  • SI-4(4) Inbound and Outbound Communications Traffic
  • SI-4(5) System-Generated Alerts

NIST SP 800-53 Rev 5 · 8 controls

CIS Controls v8 · 7 controls

  • CIS-1.2 Address Unauthorized Assets
  • CIS-13.10 Perform Application Layer Filtering
  • CIS-13.2 Deploy a Host-Based Intrusion Detection Solution
  • CIS-13.3 Deploy a Network Intrusion Detection Solution
  • CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution
  • CIS-13.8 Deploy a Network Intrusion Prevention Solution
  • CIS-13.9 Deploy Port-Level Access Control

ISO 27001:2022 · 5 controls

  • 5.24 Information security incident management planning and preparation 
  • 5.7 Threat intelligence
  • 8.16 Monitoring activities
  • 8.20 Networks security
  • 8.7 Protection against malware

SOC 2 · 5 controls

  • SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11)
  • SOC2-CC6.6 CC6.6 Protection against threats from outside the system boundary
  • SOC2-CC6.8 CC6.8 Preventing and detecting unauthorised or malicious software
  • SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities
  • SOC2-CC7.2 CC7.2 Monitoring system components for anomalies

ISO 27002:2022 · 4 controls

  • 5.24 Information security incident management planning and preparation
  • 8.16 Monitoring activities
  • 8.20 Networks security
  • 8.7 Protection against malware

NIST SP 800-171 Rev 3 · 3 controls

  • ASBv3-LT-1 Enable threat detection capabilities
  • ASBv3-NS-4 Deploy intrusion detection/intrusion prevention systems (IDS/IPS)

C5 (Germany) · 2 controls

  • C5-COS-01 Technical safeguards
  • C5-COS-03 Monitoring of connections in the Cloud Service Provider's network

CMMC 2.0 · 2 controls

  • P1-2.2.1 P1-2.2.1 Detection or blocking of known and unknown network attacks
  • P1-2.2.2 P1-2.2.2 Suspicious traffic blocked or alerted and acted upon

APRA CPS 234 · 1 control

HIPAA Security Rule · 1 control

ISO 27701:2019 · 1 control

  • 6.9.4 Logging and monitoring
  • NIST-CSF-DE.CM-01 Networks and network services are monitored to find potentially adverse events

NIST SP 800-172 · 1 control

  • 3.14.2e Monitor Organizational Systems with Specialized Capabilities

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Req 11: Test Security Regularly

You are reading one control. How much of PCI DSS 4.0 have you already done?

PCI DSS 4.0 11.5.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of PCI DSS 4.0 your existing evidence covers. Hold ISO 27001:2022 and 139 of 280 PCI DSS 4.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 415 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 78 it maps to, and the evidence behind each claim, over MCP and REST.