Penetration Testing mailing list archives
Re: The goal of pentest by PCI DSS?
From: "David M. Zendzian" <dmz () dmzs com>
Date: Mon, 05 Oct 2009 08:49:00 -0400
Yes to all of the above. First and foremost is can you gain access to cardholder data. Second (and just as important) is can any systems within the cardholder environment be compromised. And as for social engineering, it doesn't specifically state that, but if you can get a customer to work on that then they will be better rewarded knowing what risks they really have. David Taras wrote:
Hello, all! There is requirement 11.3 in PCI DSS [0]: "... Perform external and internal penetration testing at least once a year and after any significant infrastructure or application upgrade or modification (such as an operating system upgrade, a sub- network added to the environment, or a web server added to the environment). ... " From "Information Supplement: Payment Card Industry Data Security Standard (PCI DSS) Requirement 11.3 Penetration Testing" [1]: " ... The scope of penetration testing is the cardholder data environment and all systems and networks connected to it. ... The penetration tests should attempt to exploit vulnerabilities and weaknesses throughout the cardholder data environment, attempting to penetrate both at the network level and key applications. The goal of penetration testing is to determine if unauthorized access to key systems and files can be achieved. .. " Does this mean that the main aim of pentester by PCI DSS is cardholder data? Or simply aim is to gain access (exploit vulnerabilities) to as much systems in CDE as possible? I asked about this because we can gain access to for example Oracle DB and do not try to search PANs in it. Or we can gain access to some users workstation and do not try to search cardholder data in file system. One more question. Do you use social engineering in pentests by PCI DSS? Thanks for answers! [0] https://www.pcisecuritystandards.org/security_standards/download.html?id=pci_dss_v1-2.pdf [1] https://www.pcisecuritystandards.org/pdfs/infosupp_11_3_penetration_testing.pdf
------------------------------------------------------------------------ This list is sponsored by: Information Assurance Certification Review Board Prove to peers and potential employers without a doubt that you can actually do a proper penetration test. IACRB CPT and CEPT certs require a full practical examination in order to become certified. http://www.iacertification.org ------------------------------------------------------------------------
Current thread:
- The goal of pentest by PCI DSS? Taras (Oct 04)
- RE: The goal of pentest by PCI DSS? Victor Langåssve (Oct 05)
- Re: The goal of pentest by PCI DSS? Mohamed Farid (Oct 05)
- RE: The goal of pentest by PCI DSS? Victor Langåssve (Oct 06)
- RE: The goal of pentest by PCI DSS? Philip Cox (Oct 05)
- Re: The goal of pentest by PCI DSS? Jerome Athias (Oct 05)
- Re: The goal of pentest by PCI DSS? David M. Zendzian (Oct 05)
- RE: The goal of pentest by PCI DSS? Gary Everekyan (Oct 05)
- RE: The goal of pentest by PCI DSS? Taras (Oct 27)