By: PCIGuru
In reply to B. Not sure exactly what you are implying here. But what I think you are asking is can a vulnerability scanning solution that is non-public be used to scan a public instance. As long as...
View ArticleBy: B
for external vulnerability scanning, can non-public facing instances be used or required to perform the vuln scan on public facing for PCI compliance?
View ArticleBy: PCIGuru
In reply to <a href="https://pciguru.wordpress.com/2009/03/08/vulnerability-scanning-and-penetration-testing/#comment-76578">Igor</a>. Category 2 or "Connected To" systems as the Council...
View ArticleBy: Igor
Hi, I have a question about Penetration Test. CHD are at AWS and we access them through IPSEC VPN by a Jumper Server. So, our workstations are category 2. Must we run a Penetration Test and...
View ArticleBy: PCIGuru
It all depends on your scope and how things are connected via your network. Read the Open PCI Scoping Toolkit (http://itrevolution.com/pci-scoping-toolkit/) to determine scope. If you still have...
View ArticleBy: Ayyan
Hi, I have a very basic question. Let me briefly introduce our setup than I will ask my question Our application is hosted at couple of servers at amazon AWS (one Web and one Database). Where we...
View ArticleBy: PCIGuru
Is your client an ASV or are they contracting with an ASV to scan your environment? As a service provider, I would only allow an Approved Scanning Vendor (ASV) to scan my network, not any client. That...
View ArticleBy: Mark
Hi we support an internal PCI estate. Our client tells us what services are PCI and what is not. They wish to conduct external Vulnerability scan, where they own the external IP, but are demanding the...
View ArticleBy: PCIGuru
See requirement 11.3, first column, fourth bullet which says, “Includes testing to validate any segmentation and scope-reduction controls”.
View ArticleBy: PCIGuru
This comes down to a couple of key questions. How “cookie cutter” are your retail locations for infrastructure and applications? Do you have all of the same configurations at a POS testing lab? If you...
View ArticleBy: JT
Pciguru, Quick question re: multiple sites. I am interested in your thoughts on internal scans for multiple sites / retail locations that do not have site to site VPN tunnels to a central office that...
View ArticleBy: PCIGuru
Internal vulnerability scanning and penetration testing is all about your internal network and internal IP address spaces. External vulnerability scanning and penetration testing is all about your...
View ArticleBy: PH
Hi – Thank you for your very helpful website! I have a question: Our public IP’s are usually scanned when we do the External Penetration Testing. Do they also have to be scanned when we do the Internal...
View ArticleBy: Hunter
Thanks for sharing your views PCIGuru. Appreciate your feedback and timely response.
View ArticleBy: Hunter
Thanks PCIGuru. In agreement with you on unsupported Oses. In the scenario that I’m referring to, due to legacy constraints, Windows XP is being used on ATM/POS systems and compensating controls for...
View ArticleBy: PCIGuru
If you have a consistent configuration and that can be proved, you can test one of each type of ATM or POS. XP is a generic OS. One version of XP, XP Embedded is still supported until January, 2016...
View ArticleBy: Hunter
Hi PCIGuru, I have a query with regards to performing vulnerability scans and penetration tests on ATM and POS systems. Does vulnerability scan (11.2) and penetration test (11.3) requirements apply to...
View ArticleBy: PCIGuru
You need to prove the segmentation in fact works and you need to run them inside the CDE.
View Article