PCI DSS 11.6.1 Requirements
Deployment & Scope
A mechanism must be deployed to detect changes and tampering of HTTP headers and payment page content as received by the consumer browser, ensuring security and integrity at the point of consumption.
Detection & Alerts
Personnel must be alerted to any unauthorized changes, including modifications, additions, or deletions to security-related HTTP headers, as well as any changes or additions to scripts on payment pages.
Frequency
Evaluations occur at least once every seven days OR at defined periodic intervals as established by the organization's targeted risk analysis (TRA).