Penetration Testing mailing list archives
RE: nessus to PCI
From: "Dan Tesch" <dan.tesch () comcast net>
Date: Wed, 22 Jun 2005 17:00:22 -0500
Even if Nessus was certified, MC/Visa have a Qualified Security Assessors list that I believe you must choose from as of 12/20/04 it was at https://sdp.mastercardintl.com/vendors/vendor_list.shtml - you could use Nessus for preliminary scans though and I think that some of the "Qualified Assessors" may use Nessus as I have seen things that suggest it in logs. Unless you can get the Nessus Open Source Vulnerability Scanner project team to certify Nessus with the Visa & MasterCard PCI program, I would not advise using this tool for client engagements. Mr. Wizard. On 6/22/05, Vic N <vic778 () hotmail com> wrote:
Can you be more specific? Is this PCI 1.0? And are you talking about a specific section like section 1 or other sections?Has anyone had any luck mapping nessus results to the Payment Card Industry (PCI) Data Security standard?
-- I know because I must know...
Current thread:
- nessus to PCI ctodude (Jun 21)
- nessus to PCI Vic N (Jun 22)
- Re: nessus to PCI Mr Wizard (Jun 22)
- Re: nessus to PCI Renaud Deraison (Jun 22)
- Re: nessus to PCI Michael Hammer (Jun 22)
- RE: nessus to PCI Dan Tesch (Jun 22)
- Re: nessus to PCI David Rice (Jun 22)
- Re: nessus to PCI Mr Wizard (Jun 22)
- RE: nessus to PCI Vic N (Jun 23)
- <Possible follow-ups>
- RE: nessus to PCI Burnett, Robert (Jun 21)
- RE: nessus to PCI cdewitt (Jun 22)
- nessus to PCI Vic N (Jun 22)
