← PCI DSS 4.0.1 · Req 11 — Test security regularly
11.6.1 — Payment page change and tamper detection
Requirement
A change- and tamper-detection mechanism alerts personnel to unauthorised modification of the security-impacting HTTP headers and script contents of payment pages as received by the consumer's browser, evaluated at least once every seven days or at a frequency set by targeted risk analysis.
What the engine looks for
Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.
Equivalent controls elsewhere
Matched on shared topics. Satisfying this control usually moves these too.
| Framework | Control | Title | Shared topics |
|---|---|---|---|
| GDPR | Art.5(1)(d) | Accuracy | integrity |
| GDPR | Art.16 | Right to rectification | integrity |
| CCPA/CPRA | 1798.106 | Right to correct | integrity |
| SOC 2 | CC4.1 | Ongoing and separate evaluations | monitoring |
| SOC 2 | PI1.1 | Quality information about processing objectives and specifications | integrity |
| ISO 27001 | A.5.7 | Threat intelligence | monitoring |
| ISO 27001 | A.7.4 | Physical security monitoring | monitoring |
| ISO 27001 | A.8.16 | Monitoring activities | monitoring |