Penetration Testing mailing list archives

Re: nessus to PCI


From: Renaud Deraison <deraison () nessus org>
Date: Wed, 22 Jun 2005 16:42:01 -0400


On Jun 22, 2005, at 13:54, Mr Wizard wrote:

Unless you can get the Nessus Open Source Vulnerability Scanner
project team to certify Nessus with the Visa & MasterCard PCI program,
I would not advise using this tool for client engagements.

VISA & Mastercard do not certify tools, they certify _services_. AFAIK, there's no PCI-certified tool out there. I know that several MSSPs using Nessus have been certified though.



                            -- Renaud


Current thread: