How to define the CDE boundary, what segmentation testing must show, and the evidence your QSA will ask for.
PCI DSS v4.0.1 requirement 11.4 requires external and internal penetration testing at least annually and after significant changes, plus segmentation testing if you rely on segmentation to reduce scope. Most delays we see come from unclear scoping rather than from the testing itself.
List every system that stores, processes or transmits cardholder data, then every system that can connect to those systems. The second group, connected-to systems, is in scope for testing and is the one most often left out.
The test must demonstrate that out-of-scope networks cannot reach the CDE. In practice that means attempting connections from each out-of-scope segment to CDE hosts on all ports, not only the ones you expect to be open, and documenting the results.
Segmentation check: full TCP and UDP port sweep from an out-of-scope segment.
Record the source segment, destination range, date, tester and result for each run. A one-line table per segment pair is what assessors expect to see:
Segmentation evidence table (an open port from a connected-to system becomes a finding).
With a clear scope, a mid-size CDE takes two to three weeks from kickoff to final report, including one retest round. Book the test at least six weeks before your ROC or SAQ deadline.
Object-level access control failures accounted for the largest share of high-severity findings this year. Patterns and fixes.
ReadA stack overflow in the SNMP subsystem of Cisco IOS and IOS XE lets an attacker with SNMP access cause a device reload, and with additional administrative credentials, execute code as root. Actively exploited before the patch.
ReadAn unauthenticated ViewState deserialization in on-premises SharePoint Server allows remote code execution as the IIS worker. Mass exploitation began before the out-of-band patch.
ReadA missing authorization check on the SAP NetWeaver Visual Composer Metadata Uploader allows unauthenticated file upload leading to remote code execution as the SAP administrator.
Read