|
The Threat: failing to comply with PCI Data Security Standards
Many organisations do not realise that PCI DSS Requirements 6.6 and 11.3 call for penetration testing - over and above the external and internal
vulnerability assessments required by PCI DSS Requirement 11.2.
The table below shows what PCI DSS Requirements 6.6 and 11.3 specify. If you are unsure about all this, then check out our PCI DSS information
page here.
| Test Type |
Frequency |
ASV/QSA Required? |
Location |
| Web Application Test |
Annual |
No |
Remote |
| External Penetration Test |
Annual |
No |
Remote |
| Internal Penetration Test |
Annual |
No |
On Site |
|
The Solution: First Base Technologies' PCI Services
Our web application tests comply with PCI DSS Requirement 6.6 "Reviewing public-facing web applications via manual or automated application
vulnerability security assessment tools or methods, at least annually and after any changes".
Our external and internal penetration tests comply with PCI DSS Requirement 11.3 "Penetration testing should include network and application
layer testing as well as controls and processes around the networks and applications, and should occur from both outside the network trying to come in (external testing)
and from inside the network.".
Our primary deliverable is a report - tailored to your requirements, it will inform you of the vulnerabilities and the solutions, so you can address these
before insiders or hackers do. Hover over the process diagram shown below for more information.
For more details click the image above
Download the pdf flyer here
You can read our FAQ on penetration testing here
And see what our clients say about our services here
or phone Andy on +44 (0)1273 45 45 25
|
|