Home page logo

basics logo Security Basics mailing list archives

From: "Craig Wright" <Craig.Wright () bdo com au>
Date: Fri, 24 Aug 2007 08:13:10 +1000

PCI-DSS is far from vague. This is a comment that implies that you have
not read the several hundred pages of standard, supporting documents and
testing requirements. The LAST thing that the standard is, is vague.

The comment - "Note, that for most of the time, you are only required to
have quarterly scans" is typical and demonstrates that you have not read
these documents. This is a typical IT problem, we like to get in without
reading the manual. Well this is one time you have to do the homework

You have commented "you may not ever need to have a pen test done". S
11.3 states:
"Perform penetration testing at least once a year and after any
significant infrastructure or application upgrade or modification (such
as an operating system upgrade, a sub-network added to the environment,
or a web server added to the  environment). These penetration tests must
include the following:
11.3.1 Network-layer penetration tests
11.3.2 Application-layer penetration tests.

This is AT LEAST once a year and also more when needed. This is not you
may not do it. IT IS ALWAYS. Every year come sun or rain or snow. There
is no excuse. You do AT LEAST  1 Pen Test per year or you fail. This is
not a ASV scan either.

On top of this, you have to test (AT LEAST once per year) an incident
response plan. All changes to the firewalls need to be tested. Testing a
firewall is not as some people believe a rules review - this means
testing - fire packets and validate it.

Microsoft Patch Tuesday means "Appropriate software patches are those
patches that have been evaluated and tested sufficiently to determine
that the patches do not conflict with existing security configurations"
(see S6 & S6.3.1) and this is to be completed in (S6.3.2) "Separate
development, test, and production environments"

S6.4.3 - all changes must have a process that includes "Testing of
operational functionality".

S11.1 "Test security controls, limitations, network connections, and
restrictions annually to assure the ability to adequately identify and
to stop any unauthorized access attempts. Use a wireless analyzer at
least quarterly to identify all wireless devices in use." If you look at
the associated test standards and other documents you will see what a
test is.

S11.2 "Run internal and external network vulnerability scans at least
quarterly" - this is more than a scan from an ASV. Please also note -
internal AND external. Plenty of people seem to grasp the external scan
from an ASV, but what happened to the INTERNAL component.

So take the time to read the standard BEFORE commenting on its

So what is not clear? Read the document first. Do not scan it, peruse it
of give it a once over. Read it. Before tying to make it seem as if you
know something - please read a little and gain the professed expertise.
The standards are free.


Craig Wright
Manager of Information Systems

Direct : +61 2 9286 5497
Craig.Wright () bdo com au
+61 417 683 914

BDO Kendalls (NSW)
Level 19, 2 Market Street Sydney NSW 2000
GPO BOX 2551 Sydney NSW 2001
Fax +61 2 9993 9497

Liability limited by a scheme approved under Professional Standards Legislation in respect of matters arising within 
those States and Territories of Australia where such legislation exists.

The information in this email and any attachments is confidential.  If you are not the named addressee you must not 
read, print, copy, distribute, or use in any way this transmission or any information it contains.  If you have 
received this message in error, please notify the sender by return email, destroy all copies and delete it from your 

Any views expressed in this message are those of the individual sender and not necessarily endorsed by BDO Kendalls.  
You may not rely on this message as advice unless subsequently confirmed by fax or letter signed by a Partner or 
Director of BDO Kendalls.  It is your responsibility to scan this communication and any files attached for computer 
viruses and other defects.  BDO Kendalls does not accept liability for any loss or damage however caused which may 
result from this communication or any files attached.  A full version of the BDO Kendalls disclaimer, and our Privacy 
statement, can be found on the BDO Kendalls website at http://www.bdo.com.au or by emailing administrator () bdo com au 

BDO Kendalls is a national association of separate partnerships and entities.

-----Original Message-----

From: listbounce () securityfocus com [mailto:listbounce () securityfocus com]
On Behalf Of evilwon12 () yahoo com
Sent: Friday, 24 August 2007 1:08 AM
To: security-basics () securityfocus com
Subject: Re: PCI DSS

PCI DSS is vague on certain things (at best).  However, you did not
state what level of a Merchant you are, which adds or subtracts plenty
of things that you must do.

My guess is that you are referring to Section 11.  Note, that for most
of the time, you are only required to have quarterly scans - which is
what you are probably being quoted on.  Only once a year does a pen test
need to be done (unless their are major changes) and even then I think
it depends on your level.  Even then, are you hosting the application
and data or outsourcing it?  If you are outsourcing everything, you may
not ever need to have a pen test done.

So, what is it that you are really asking?

  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]