Discussion:
OT (sort of): pci scans
steve fox
2012-01-04 22:07:44 UTC
Permalink
Hi,

I've been asked to provide a pci scan report for several websites and
could use a recommendation for a pci scanning product, preferably at a
reasonable cost. I have found some "free" ones, but I thought I'd ask
the list what you use, if anything.

Also, feel free to share any opinions on PCI scans you may have.

Thanks,

Steve
Jason Heiser
2012-01-05 00:30:32 UTC
Permalink
My company used a service from Qualys called "QualysGuard PCI" and it did a good job of identifying vulnerabilities with our hosting environment. I don't think application vulnerability (penetration testing) was covered.

It wasn't cheap. The cost was $795/year, which allowed us to use their service to scan up to nine unique IP addresses concurrently. More concurrent IPs cost more money, but you are allowed to swap out IPs without too much hassle.

Like many application service providers, Qualys does not advertise prices on their website for their numerous and confusing product lines. You have to fill out a contact form and then talk to a salesperson. Fortunately, mine was helpful and not too pushy. Still, it's irritating (to me) when companies use price-hiding as a sales tactic.

In my opinion, PCI compliance has become something of a racket. Instead of solving security issues with technical innovation, the payment card industry formed a council and shifted the problem to their customers. Then a lucrative cottage industry of QSAs, PA-QSAs, ASVs, and ISAs (all PITAs) sprung up. It's expensive and burdensome, especially for smaller operations. I look forward to when transactions are authenticated better by the providers.

Anyhow. Good luck, Steve!

Jason
Hi,
I've been asked to provide a pci scan report for several websites and could use a recommendation for a pci scanning product, preferably at a reasonable cost. I have found some "free" ones, but I thought I'd ask the list what you use, if anything.
Also, feel free to share any opinions on PCI scans you may have.
Thanks,
Steve
---------------------------------------------------------------------
To unsubscribe, e-mail: talk-unsubscribe-4zcLI8jJc/***@public.gmane.org

Please read and follow the list guidelines:
http://www.tcphp.org/mailing_list/guidelines

The tcphp.org mailing list is sponsored by pajunas interactive, inc.
steve fox
2012-01-05 19:07:51 UTC
Permalink
Way to go Jason. It's great when someone says what most of us only think about. That is, " PCI compliance has become something of a racket."
Yeah, that's the sense I got as well. And expensive. One healthcare
conglomerate I work with pays dearly for quarterly scans. I'd actually
disregarded PCI testing to the extent of having forgotten about it, and
now that I revisit it, it sure feels like the whole ISO certification craze.

Thanks for the replies.

Steve
Carl Boudreau
2012-01-05 19:10:36 UTC
Permalink
Hi ALL, this is an interesting topic for me. What are the best free PCI
scanners and what is the risk of running them against a site?


-----Original Message-----
From: steve fox [mailto:foxsg-V0AihW0KB/***@public.gmane.org]
Sent: Thursday, January 05, 2012 1:08 PM
To: Frederick Hathaway
Cc: Jason Heiser; TC PHP List
Subject: Re: [tcphp] OT (sort of): pci scans
Way to go Jason. It's great when someone says what most of us only think
about. That is, " PCI compliance has become something of a racket."
Yeah, that's the sense I got as well. And expensive. One healthcare
conglomerate I work with pays dearly for quarterly scans. I'd actually
disregarded PCI testing to the extent of having forgotten about it, and now
that I revisit it, it sure feels like the whole ISO certification craze.

Thanks for the replies.

Steve


---------------------------------------------------------------------
To unsubscribe, e-mail: talk-unsubscribe-4zcLI8jJc/***@public.gmane.org

Please read and follow the list guidelines:
http://www.tcphp.org/mailing_list/guidelines

The tcphp.org mailing list is sponsored by pajunas interactive, inc.
Loading...