Thread: PCI Compliance
View Single Post
  #5 (permalink)  
Old 09-19-2007, 04:01 PM
wige's Avatar
wige wige is offline
Moderator
WebProWorld Moderator
 

Join Date: Jun 2006
Location: United States
Posts: 1,722
wige RepRank 4wige RepRank 4wige RepRank 4wige RepRank 4
Default Re: PCI Compliance

Chowell, I take it that it is your web server that is causing the failure, has your hosting company or the testing company given you any specifics on why you failed? Most of the PCI analysis that I tried (I did demo plans with a few companies before we selected ControlScan) involved quite similar steps - a "procedural audit" which consisted of a questionnaire about our current security practices, and a physical audit consisting of extensive daily or weekly vulnerability scans of our web server and the web-facing side of our company network. If you got through the procedural audit, the physical audit shouldn't give you any problems unless the hosting company is not adequately securing the servers, or a vulnerability exists in your web software.
__________________
The best way to learn anything, is to question everything.
Interestingly Average Security Blog
Reply With Quote