Security Basics mailing list archives
FW: PCI DSS
From: "Craig Wright" <Craig.Wright () bdo com au>
Date: Fri, 24 Aug 2007 08:13:10 +1000
"EvilWon12" PCI-DSS is far from vague. This is a comment that implies that you have not read the several hundred pages of standard, supporting documents and testing requirements. The LAST thing that the standard is, is vague. The comment - "Note, that for most of the time, you are only required to have quarterly scans" is typical and demonstrates that you have not read these documents. This is a typical IT problem, we like to get in without reading the manual. Well this is one time you have to do the homework first. You have commented "you may not ever need to have a pen test done". S 11.3 states: "Perform penetration testing at least once a year and after any significant infrastructure or application upgrade or modification (such as an operating system upgrade, a sub-network added to the environment, or a web server added to the environment). These penetration tests must include the following: 11.3.1 Network-layer penetration tests 11.3.2 Application-layer penetration tests. This is AT LEAST once a year and also more when needed. This is not you may not do it. IT IS ALWAYS. Every year come sun or rain or snow. There is no excuse. You do AT LEAST 1 Pen Test per year or you fail. This is not a ASV scan either. On top of this, you have to test (AT LEAST once per year) an incident response plan. All changes to the firewalls need to be tested. Testing a firewall is not as some people believe a rules review - this means testing - fire packets and validate it. Microsoft Patch Tuesday means "Appropriate software patches are those patches that have been evaluated and tested sufficiently to determine that the patches do not conflict with existing security configurations" (see S6 & S6.3.1) and this is to be completed in (S6.3.2) "Separate development, test, and production environments" S6.4.3 - all changes must have a process that includes "Testing of operational functionality". S11.1 "Test security controls, limitations, network connections, and restrictions annually to assure the ability to adequately identify and to stop any unauthorized access attempts. Use a wireless analyzer at least quarterly to identify all wireless devices in use." If you look at the associated test standards and other documents you will see what a test is. S11.2 "Run internal and external network vulnerability scans at least quarterly" - this is more than a scan from an ASV. Please also note - internal AND external. Plenty of people seem to grasp the external scan from an ASV, but what happened to the INTERNAL component. So take the time to read the standard BEFORE commenting on its effectiveness. So what is not clear? Read the document first. Do not scan it, peruse it of give it a once over. Read it. Before tying to make it seem as if you know something - please read a little and gain the professed expertise. The standards are free. Regards, Craig Craig Wright Manager of Information Systems Direct : +61 2 9286 5497 Craig.Wright () bdo com au +61 417 683 914 BDO Kendalls (NSW) Level 19, 2 Market Street Sydney NSW 2000 GPO BOX 2551 Sydney NSW 2001 Fax +61 2 9993 9497 www.bdo.com.au Liability limited by a scheme approved under Professional Standards Legislation in respect of matters arising within those States and Territories of Australia where such legislation exists. The information in this email and any attachments is confidential. If you are not the named addressee you must not read, print, copy, distribute, or use in any way this transmission or any information it contains. If you have received this message in error, please notify the sender by return email, destroy all copies and delete it from your system. Any views expressed in this message are those of the individual sender and not necessarily endorsed by BDO Kendalls. You may not rely on this message as advice unless subsequently confirmed by fax or letter signed by a Partner or Director of BDO Kendalls. It is your responsibility to scan this communication and any files attached for computer viruses and other defects. BDO Kendalls does not accept liability for any loss or damage however caused which may result from this communication or any files attached. A full version of the BDO Kendalls disclaimer, and our Privacy statement, can be found on the BDO Kendalls website at http://www.bdo.com.au or by emailing administrator () bdo com au. BDO Kendalls is a national association of separate partnerships and entities. -----Original Message----- From: listbounce () securityfocus com [mailto:listbounce () securityfocus com] On Behalf Of evilwon12 () yahoo com Sent: Friday, 24 August 2007 1:08 AM To: security-basics () securityfocus com Subject: Re: PCI DSS PCI DSS is vague on certain things (at best). However, you did not state what level of a Merchant you are, which adds or subtracts plenty of things that you must do. My guess is that you are referring to Section 11. Note, that for most of the time, you are only required to have quarterly scans - which is what you are probably being quoted on. Only once a year does a pen test need to be done (unless their are major changes) and even then I think it depends on your level. Even then, are you hosting the application and data or outsourcing it? If you are outsourcing everything, you may not ever need to have a pen test done. So, what is it that you are really asking?
Current thread:
- PCI DSS security guy (Aug 22)
- RE: PCI DSS Craig Wright (Aug 23)
- <Possible follow-ups>
- Re: PCI DSS alistair . fletcher (Aug 23)
- Re: PCI DSS evilwon12 (Aug 23)
- FW: PCI DSS Craig Wright (Aug 23)