Earlier in this chapter, I mentioned that the PCI DSS comprises 6 goals and 12 requirements. The official PCI DSS v3.2.1 Quick Reference Guide provides a summary of all 12 requirements to be satisfied, and can be downloaded at https://www.pcisecuritystandards.org/documents/PCI_DSS-QRG-v3_2_1.pdf?agreement=true&time=1535479943356. In this section, we focus on the penetration testing elements of the PCI DSS assessment under Requirement 11: Regularly test security systems and processes, which falls under Goal 5: Regularly Monitoring and Testing Networks.
Requirement 11.3 is based on implementing a penetration testing methodology such as the suggested NIST SP800-115 Technical Guide to Information Security Testing and Assessment. Although published in 2008, NIST SP800-115 provides tried-and-trusted techniques and best practices for scoping and executing...