WebApp Sec mailing list archives

Re: PCI DSS Compliance


From: Pete Herzog <lists () isecom org>
Date: Mon, 19 Dec 2005 16:03:03 +0100


Craig Wright wrote:
An automated, not verified process does not meet the scaning/testing
> requirements. It is thus entirely irrelivant to the discussion as it
> will not help you be compliant.

The question was about whether assuring all known vulns are patched by disabling all security controls is correct. That was the question which prompted my discussion about PCI. For me, vuln scanning an entire network is very wrong and a pointless task. And I think it's important we challenge notions we suspect to be wrong either to fix them or correct ourselves. I am proud of you for reading the whole PCI document and all associated pages but what good does it do you if it isn't correct?

-pete.


Current thread: