|
|||||||
New to SitePoint Forums? Register here for free!
|
![]() |
|
|
Thread Tools | Display Modes |
|
|
#1 |
|
SitePoint Addict
![]() ![]() ![]() Join Date: Apr 2007
Posts: 204
|
Client PCI Compliance
Hi,
I have been asked by a client to help them with becoming PCI compliant. We have everything sorted except one thing - wireless analysis. To become PCI compliant you need to use a 'wireless analyzer' to scan for vulnerabilities every quarter. The only trouble is, I haven't a clue what one of these things looks like, let alone where to get one or how to deploy one (and I have been Googling for hours)! If anyone who has any experience of dealing with PCI Compliance can explain what my client and I need to do for this I would be very grateful. Thanks, TM |
|
|
|
|
|
#2 |
|
SitePoint Member
Join Date: Jul 2009
Posts: 6
|
Are there any consultants that you can hire to do this for you? This sounds like it might be cheaper.
Also, this only applies if your client uses wireless LAN for transmitting cc info. I would take a look at regulations just to make sure you really need it. |
|
|
|
|
|
#3 |
|
SitePoint Zealot
![]() ![]() Join Date: Jun 2009
Posts: 114
|
Approved list of scanning vendors can be found here:
https://www.pcisecuritystandards.org...sv_report.html Personally, I'd check HackerGuardian as an option, this is a very reputable company. |
|
|
|
|
|
#4 | |
|
SitePoint Addict
![]() ![]() ![]() Join Date: Apr 2007
Posts: 204
|
My client is already with one of these approved scanning vendors - Security Metrics. All they do is perform an external scan - whereas we need an internal (on site) scan to comply with 11.1 which says that you must carry out a minimum quarterly wireless scan of all locations or the deployment of a wireless IDS/IPS.
We asked Security Metrics for help on how to comply with this and this was their response: Quote:
|
|
|
|
|
|
|
#5 |
|
SitePoint Zealot
![]() ![]() Join Date: Jun 2009
Posts: 114
|
I see, sorry for possible misunderstanding. Did you check with your hosting company regarding this question? They may have such a system if they host ecommerce sites.
|
|
|
|
|
|
#6 |
|
SitePoint Addict
![]() ![]() ![]() Join Date: Apr 2007
Posts: 204
|
No worries. I'm gradually picking up bits of this PCI Compliance as I go along. I guess it might be worth asking - the support people at my hosting company are usually quite helpful and knowledgeable. Thanks.
|
|
|
|
|
|
#7 |
|
SitePoint Zealot
![]() ![]() Join Date: Jun 2009
Posts: 114
|
It's good to hear this. Please, share your results with us, it would be interesting to know.
|
|
|
|
|
|
#8 |
|
SitePoint Addict
![]() ![]() ![]() Join Date: Apr 2007
Posts: 204
|
|
|
|
|
|
|
#9 | |
|
SitePoint Addict
![]() ![]() ![]() Join Date: Apr 2007
Posts: 204
|
Quote from my host:
Quote:
|
|
|
|
|
|
|
#10 |
|
SitePoint Zealot
![]() ![]() Join Date: Jun 2009
Posts: 114
|
Am I correct to assume that you use a dedicated server? If so, I'd suggest passing this question further to your server administrator.
|
|
|
|
|
|
#11 |
|
SitePoint Addict
![]() ![]() ![]() Join Date: Apr 2007
Posts: 204
|
That's irrelevant - the wireless access point is located at the client's home based office. I have now installed Norton for the client so we should be compliant now if my host is right.
|
|
|
|
![]() |
| Bookmarks |
| Tags |
| pci |
«
Previous Thread
|
Next Thread
»
| Thread Tools | |
| Display Modes | |
|
|
|
All times are GMT -7. The time now is 15:59.










Linear Mode
