Requirement

PCI DSS 11.6.1

What the requirement asks for, how a change-detection mechanism is expected to behave, and the evidence an assessor asks to be shown.

What the requirement asks for

A mechanism that notices when the scripts or HTTP headers a payment page delivers are not the ones that were authorized, and alerts someone who can do something about it. A weekly screenshot is not that mechanism.

How a change-detection mechanism is expected to behave

Each authorized script is fingerprinted. A hash that no longer matches is a change, whether or not the file name stayed the same. Headers are recorded as the browser received them, not as the origin intended to send them — a CDN or a tag manager in the middle is still a change the page saw.

How often it has to run

Often enough that a change cannot sit unnoticed through a reporting period. At the end of that period a named person attests to what was observed and what they reviewed. The attestation is a human record; the detections are what it is attesting to.

What Tagnovo produces, and what it does not

Tagnovo is not a QSA and does not certify compliance. It produces a dated record of every change observed in the period and who reviewed it.Tagnovo Manifest is the product that does it.