← PCI DSS 4.0.1 · Req 11 — Test security regularly
11.5 — Intrusion detection and change detection
Requirement
Intrusion-detection and/or intrusion-prevention techniques detect or prevent intrusions into the network at the CDE perimeter and critical points, and a change-detection mechanism (such as file-integrity monitoring) alerts on unauthorised modification of critical files, with comparisons at least weekly.
What the engine looks for
Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.
Equivalent controls elsewhere
Matched on shared topics. Satisfying this control usually moves these too.
| Framework | Control | Title | Shared topics |
|---|---|---|---|
| GDPR | Art.5(1)(d) | Accuracy | integrity |
| GDPR | Art.16 | Right to rectification | integrity |
| CCPA/CPRA | 1798.106 | Right to correct | integrity |
| SOC 2 | CC4.1 | Ongoing and separate evaluations | monitoring |
| SOC 2 | PI1.1 | Quality information about processing objectives and specifications | integrity |
| ISO 27001 | A.5.7 | Threat intelligence | monitoring |
| ISO 27001 | A.7.4 | Physical security monitoring | monitoring |
| ISO 27001 | A.8.16 | Monitoring activities | monitoring |