| Home > Strategies for success -- PCI DSS Requirement 11: Regularly test security systems and processes | |
| Learning Guide: |
|
||
How to pass PCI requirement 11:
A substantial number of successful attacks are carried out against systems that do not get patched with the latest security updates. In addition to a systematic patching process, the greatest protection against network and application security threats is the consistent use of vulnerability scanners that can see all of the applications and devices on a network, identify vulnerabilities and supply remediation information. Nevertheless, scanning the corporate network for vulnerabilities will not reveal everything and may only uncover issues that have already been confronted or at least discovered. Scanning, though helpful, may not necessarily offer what a real, attack-like penetration testing program provides. In order to be aware of its readiness, it is imperative (and required by the PCI DSS) that an organization perform an annual penetration test on its information systems, measuring how well the systems can endure an attack. This type of test actually exploits vulnerabilities to better quantify the true risk of any particular finding. According to a report found in The Retail Data Security 2005 Benchmark Study, only 51% of retailers perform network penetration testing. A frightening 14% of the survey respondents indicated that they had suffered a customer data security breach. Vulnerability scanning provides a look into known weaknesses, but does not address the elements of a successful intrusion. Your testing should include a deeper dive that will bring to light the real threats to your organization's assets. Furthermore, when it comes to testing processes, all changes that could affect ingress and egress filter rules should go through a formal process before adjustments are made to firewalls, routers, VPNs and WLAN devices. These changes should be reviewed carefully for proper justification, and management must be made aware of any newly discovered security risks. Information systems environments will always have to change in order to help the business obtain its objectives; therefore, all changes must continually be reviewed and fully documented.
'); // -->
|
||||||||||||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||
|
||||||||||