Quantcast
Channel: Comments on: Vulnerability Scanning and Penetration Testing
Browsing index pages (45 articles)
↧

By: PCIGuru

In reply to B. Not sure exactly what you are implying here. But what I think you are asking is can a vulnerability scanning solution that is non-public be used to scan a public instance. As long as...

View Article


By: B

for external vulnerability scanning, can non-public facing instances be used or required to perform the vuln scan on public facing for PCI compliance?

View Article


By: PCIGuru

In reply to <a href="https://pciguru.wordpress.com/2009/03/08/vulnerability-scanning-and-penetration-testing/#comment-76578">Igor</a>. Category 2 or "Connected To" systems as the Council...

View Article

By: Igor

Hi, I have a question about Penetration Test. CHD are at AWS and we access them through IPSEC VPN by a Jumper Server. So, our workstations are category 2. Must we run a Penetration Test and...

View Article

By: PCIGuru

It all depends on your scope and how things are connected via your network. Read the Open PCI Scoping Toolkit (http://itrevolution.com/pci-scoping-toolkit/) to determine scope. If you still have...

View Article


By: Ayyan

Hi, I have a very basic question. Let me briefly introduce our setup than I will ask my question Our application is hosted at couple of servers at amazon AWS (one Web and one Database). Where we...

View Article

By: PCIGuru

Is your client an ASV or are they contracting with an ASV to scan your environment? As a service provider, I would only allow an Approved Scanning Vendor (ASV) to scan my network, not any client. That...

View Article

By: Mark

Hi we support an internal PCI estate. Our client tells us what services are PCI and what is not. They wish to conduct external Vulnerability scan, where they own the external IP, but are demanding the...

View Article


By: PCIGuru

See requirement 11.3, first column, fourth bullet which says, “Includes testing to validate any segmentation and scope-reduction controls”.

View Article


By: Bri

Where does it say this in the standard?

View Article

By: PCIGuru

This comes down to a couple of key questions. How “cookie cutter” are your retail locations for infrastructure and applications? Do you have all of the same configurations at a POS testing lab? If you...

View Article

By: JT

Pciguru, Quick question re: multiple sites. I am interested in your thoughts on internal scans for multiple sites / retail locations that do not have site to site VPN tunnels to a central office that...

View Article

By: PCIGuru

Internal vulnerability scanning and penetration testing is all about your internal network and internal IP address spaces. External vulnerability scanning and penetration testing is all about your...

View Article


By: PH

Hi – Thank you for your very helpful website! I have a question: Our public IP’s are usually scanned when we do the External Penetration Testing. Do they also have to be scanned when we do the Internal...

View Article

By: Hunter

Thanks for sharing your views PCIGuru. Appreciate your feedback and timely response.

View Article


By: PCIGuru

Your approach would have to be used for 11.2 and 11.3.

View Article

By: Hunter

Thanks PCIGuru. In agreement with you on unsupported Oses. In the scenario that I’m referring to, due to legacy constraints, Windows XP is being used on ATM/POS systems and compensating controls for...

View Article


By: PCIGuru

If you have a consistent configuration and that can be proved, you can test one of each type of ATM or POS. XP is a generic OS. One version of XP, XP Embedded is still supported until January, 2016...

View Article

By: Hunter

Hi PCIGuru, I have a query with regards to performing vulnerability scans and penetration tests on ATM and POS systems. Does vulnerability scan (11.2) and penetration test (11.3) requirements apply to...

View Article

By: PCIGuru

You need to prove the segmentation in fact works and you need to run them inside the CDE.

View Article
Browsing index pages (45 articles)


Latest Images