Penetration Testing mailing list archives

Re: The goal of pentest by PCI DSS?


From: Mohamed Farid <m.farid.shawara () gmail com>
Date: Mon, 05 Oct 2009 09:16:04 +0200

Dear Taras :

The PCI DSS is only focusing on the Credit Card information - if you can
gain access to the card holder data scope but you can't get any data
from it - then you will pass the requirement.
The Main point is to not risk the information in the scope which
concentrate on the sensitive information of the card holder data ...

No - The Pen Test shouldn't contain social engineering - but of course
there is no problem to have it too ...

Thanks ,,,
Mohamed Farid ,,,

Taras wrote:
Hello, all!

There is requirement 11.3 in PCI DSS [0]: "...
Perform external and internal penetration testing at least once a year
and after any significant infrastructure or application upgrade or
modification (such as an operating system upgrade, a sub-
network added to the environment, or a web server added to the
environment).
...
"

From "Information Supplement: Payment Card Industry Data Security
Standard (PCI DSS) Requirement 11.3 Penetration Testing" [1]:

"
...
The scope of penetration testing is the cardholder data environment and
all systems and networks connected to it. 
...
The penetration tests should attempt to exploit vulnerabilities and
weaknesses throughout the cardholder data environment, attempting to
penetrate both at the network level and key applications. The
goal of penetration testing is to determine if unauthorized access to
key systems and files can be achieved. 
..
"
Does this mean that the main aim of pentester by PCI DSS is cardholder
data?  Or simply aim is to gain access (exploit vulnerabilities) to as
much systems in CDE as possible? I asked about this because we can gain
access to for example Oracle DB and do not try to search PANs in it. 
Or we can gain access to some users workstation and do not try to search
cardholder data in file system.

One more question. Do you use social engineering in pentests by PCI DSS?

Thanks for answers!

[0]
https://www.pcisecuritystandards.org/security_standards/download.html?id=pci_dss_v1-2.pdf
[1]
https://www.pcisecuritystandards.org/pdfs/infosupp_11_3_penetration_testing.pdf

  

------------------------------------------------------------------------
This list is sponsored by: Information Assurance Certification Review Board

Prove to peers and potential employers without a doubt that you can actually do a proper penetration test. IACRB CPT 
and CEPT certs require a full practical examination in order to become certified. 

http://www.iacertification.org
------------------------------------------------------------------------


Current thread: