Personal tools
You are here: Home wikidblog More on PCI Security: Random Pen Testing
« August 2008 »
Mo Tu We Th Fr Sa Su
        1 2 3
4 5 6 7 8 9 10
11 12 13 14 15 16 17
18 19 20 21 22 23 24
25 26 27 28 29 30 31
Recent comments
Re:Security and Oil admin Apr 25, 2008
Re:Security and Oil Paul feet Apr 24, 2008
Re:100% open source admin Apr 22, 2008
Re:100% open source Adam Apr 22, 2008
Re:Capital Gains Tax Rates and Entrepreneurs Lance Oct 23, 2007
 

More on PCI Security: Random Pen Testing

In thinking a bit more about PCI security since my post on PCI visibility. I think what Visa and Mastercard need to do is to hire independent 3rd party penetration testers to pen test merchants and processors.

The PCI Three are making a big switch in September, when they will start fining acquiring banks non-compliant merchants. However, there are two problems with the auditing procedures: Auditors are paid by the companies they are auditing and audits are static snapshots. I'm not insinuating anything here about the ethics of PCI auditors, just pointing out the agency conflict and that a company might get compliant for an audit, then lapse out of compliance.

Further, as I have mentioned before, I think that the PCI program may be too little too late to fend off regulatory action. I think that having auditors that are paid by Visa/Mastercard/Amex to pen test merchants and processors would keep merchants and processors on their toes. Obviously, the merchants and processors would have to give permission for random pen tests, but I think that issue can be forced. Doing this would eliminate the two problems noted above. The pen testers would not be paid by the target companies and the target companies would have no idea when they would be audited.

The URL to Trackback this entry is:
http://www.wikidsystems.com/WiKIDBlog/more-on-pci-security-random-pen-testing/tbping
Add comment

You can add a comment by filling out the form below. Plain text formatting. Comments and Trackbacks are moderated.

(Required)
(Required)
(Required)
(Required)
This helps us prevent automated spamming.