Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: PCI DSS Compliance |
|---|---|
| Date: | Thu, 29 Dec 2005 11:25:54 +0100 |
Lyal, all,
Sorry for the delay-- I had vacation.
I don't think it's a question of the PCI document being right or wrong, but of compliance to a set of domumented requirements in order to either stay in business or minimise financial impact on a company if a security breach involving credit cards occurs.
PCI requires, among 190+ other things, vuln scanning of all internet facing systems, and those internal systems that process cardholder data, not the entire internal network. PCI also requires an annual pen-test, to attempt to exploit scanning-discovered vulnerabilities. Of course you may choose to scan the rest of the entire network as part of enterprise security management.
Sincerely, -pete.
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: Mambo, Coppermine and PHPBB Attacks, Yasuo Ohgaki |
|---|---|
| Next by Date: | Black Hat Federal and Europe Call for Papers, Jeff Moss |
| Previous by Thread: | RE: PCI DSS Compliance, Lyal Collins |
| Next by Thread: | RE: PCI DSS Compliance, Lyal Collins |
| Indexes: | [Date] [Thread] [Top] [All Lists] |